Shell said it is investigating a potential security incident after the Clop extortion group claimed it stole 89 GB of company data, including engineering drawings, facility photos, project plans, and scans of facility testing reports. Separate victim-listing reports also named GE and Philips as compromised organizations, indicating a broader campaign affecting major firms in the energy, technology, and healthcare sectors.
The activity has been tied to Clop’s exploitation of Internet-exposed PTC Windchill and FlexPLM systems through CVE-2026-12569, an actively exploited vulnerability for which PTC began issuing patches on June 17. Security reporting said the attackers deployed JSP webshells to steal data from compromised product lifecycle management platforms, while CISA and Germany’s BSI warned organizations to urgently secure exposed instances as confirmed exploitation spread beyond Shell to other high-profile enterprises.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Clop was reported as targeting SHELL.COM and exfiltrating 89 GB of data, including engineering drawings, facility photos, scans of testing reports, and project plans. The breach was listed at 15:25 UTC and discovery at 15:26 UTC.
Clop was reported as breaching PHILIPS.COM in a data-breach incident affecting Philips. The breach and discovery were both listed at 15:28 UTC.
Clop was reported as breaching GE.COM in a data-theft incident affecting General Electric. The breach time was listed as 15:26 UTC, with discovery one minute later at 15:27 UTC.
PTC warned customers about heightened threat activity involving CVE-2026-12569 affecting Internet-exposed Windchill and FlexPLM instances.
PTC started releasing security patches for the critical PTC Windchill and FlexPLM vulnerability CVE-2026-12569. The company also issued a private advisory urging customers to review their environments for indicators of compromise.
Shell said it was aware of a potential security incident after Clop listed the company on its leak site and claimed to have stolen 89 GB of data. A spokesperson said the company was working with security teams and relevant experts to investigate.
CISA confirmed that CVE-2026-12569 was being actively exploited in attacks, added it to the Known Exploited Vulnerabilities catalog, and ordered U.S. federal agencies to secure vulnerable PTC instances within three days. Germany's BSI also warned customers to patch affected systems quickly.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourcehookphish.com
Open sourcehookphish.com
Open sourcehookphish.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.