Shell investigates 'potential incident' after Clop data theft claims
Reported exploitedPTC WindchillClopPTC FlexPLMOur summary
Major energy firm Shell has begun investigating a potential security incident following claims by the Clop ransomware group that they exfiltrated 89GB of sensitive data, including engineering drawings and facility reports. The theft is attributed to active exploitation of CVE-2026-12569, a critical input validation flaw in internet-facing instances of PTC Windchill and FlexPLM. CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog, urging organizations to apply patches released by PTC and check for indicators of compromise.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.