Shell said it is investigating a possible data breach after the Cl0p ransomware and extortion group listed the energy giant on its dark web leak site, claiming to have stolen roughly 89 gigabytes of engineering drawings, facility photographs, project plans and testing reports, according to CyberSecurityNews. Shell is one of nearly 50 companies Cl0p has now named in a mass extortion campaign that Reuters reports also lists Philips, GE and financial technology firm Fiserv, tied to a single critical flaw in engineering software used across manufacturing and industrial firms.
What is Cl0p claiming happened at Shell?
Cl0p’s post to its leak site alleges it exfiltrated about 89 gigabytes of Shell data, including technical drawings, facility photographs, project roadmaps and testing report scans, according to CyberSecurityNews. A Shell spokesperson said the company is “working with our security teams and relevant experts to investigate the situation,” per Reuters. Shell has not confirmed that any data was actually taken, and has not reported disruption to its refineries, drilling operations or core IT systems.
Which other companies has Cl0p named?
Reuters, citing the group’s own leak site posting, reports that Cl0p has named close to 50 organizations worldwide as of August 13, 2026. Alongside Shell, the list includes:
- Philips, which Cl0p claims lost about 13.5 gigabytes of PDF drawings, diagrams and blueprints. Philips said it “identified and contained an attempted cybersecurity compromise of a specific enterprise server related to internal data,” per Reuters.
- GE, which said it “initiated our cyber response protocols and are working to assess the potential issue.”
- Fiserv, a financial technology firm, which said that “based on our comprehensive review to date” it has found no evidence that customer or transaction data was compromised.
None of the four companies has confirmed that data was actually stolen, and Reuters said it could not independently verify Cl0p’s claims. Cl0p has not published sample files to substantiate the alleged haul, a pattern consistent with the group’s history of claims that outpace proof.
| What happened | Cl0p listed Shell and nearly 50 other companies on its extortion leak site, claiming to have stolen internal data |
|---|---|
| When | Claims surfaced around August 13 to 14, 2026, tied to a vulnerability patched June 18, 2026 |
| Who is affected | Shell, Philips, GE and Fiserv are named and investigating; nearly 50 companies total claimed |
| Scale | Cl0p claims 89GB from Shell and 13.5GB from Philips; no volumes disclosed for GE or Fiserv |
| Fix or deadline | PTC patched the underlying Windchill and FlexPLM flaw, CVE-2026-12569, on June 18, 2026; unpatched instances remain exposed |
How did Cl0p reportedly break in?
Security researchers tie the campaign to CVE-2026-12569, a critical unauthenticated remote code execution flaw, rated 9.3 on the CVSS scale, in PTC’s Windchill and FlexPLM product lifecycle management software, according to The Hacker News. Attackers reportedly chain a pre-authentication information disclosure bug in FlexPLM’s WSDL endpoint with a separate flaw in the Windchill login servlet to achieve remote code execution without ever needing a password, then drop web shells to exfiltrate data. PTC patched the flaw on June 18, 2026, according to Reuters, and researchers say exploitation followed quickly; Cl0p sent extortion notices to affected companies on July 19 and 20, with a public warning about the campaign following on July 22.
Windchill and FlexPLM manage exactly the kind of files Cl0p claims to have stolen: engineering drawings, product roadmaps and manufacturing test data. That makes this campaign a close cousin of Gunra’s exploitation of Fortinet and Schneider Electric flaws and the D1R group’s extortion claim against Synopsys and Bosch: attackers are increasingly going after the engineering and design software that industrial companies depend on, rather than customer databases. Ascent Solutions security lead Brandon Parsons told Reuters the pattern is opportunistic rather than targeted, saying, “They don’t really target a specific company, they target a specific zero day vulnerability.”
Why does this matter for energy and industrial CISOs?
Shell’s inclusion puts an energy major squarely inside a campaign that, so far, reads like a repeat of Cl0p’s 2023 MOVEit breach, in which a single unpatched file transfer flaw led to data theft at hundreds of organizations. The group, also tracked as affiliated with TA505 and FIN11, has built a business model around finding one widely deployed enterprise application, exploiting it at scale before defenders patch, then extorting dozens of victims at once rather than encrypting their networks. That approach lines up with what our analysis of how AI is rewriting data breach economics for BFSI and energy firms found: attackers are industrializing reconnaissance and exploitation faster than asset owners can inventory their exposed software. It also echoes the disclosure pattern seen at Levi Strauss, where a company confirmed an intrusion into employee systems well before the scope of any data loss was clear.
What should security leaders do now?
For any organization running PTC Windchill or FlexPLM, the first move is to confirm the June 18 patch for CVE-2026-12569 is applied and to check logs for the hex named web shells associated with the campaign. More broadly, this incident is a reminder that engineering and product lifecycle systems deserve the same exposure management rigor as customer facing applications. CISOs should:
- Inventory every internet facing PLM, file transfer and document management system, not just the ones holding regulated customer data
- Treat vendor patch notices for engineering software as high priority, given Cl0p’s track record of weaponizing fixes within weeks of release
- Prepare a holding statement and forensic escalation path now, since Shell, Philips, GE and Fiserv all had to respond publicly before they had full clarity on impact
- Watch Cl0p’s leak site for proof, since claims alone are not evidence of compromise, but treat repeat naming as a signal to prioritize the underlying vulnerability regardless
As our 2026 CISO perspective on what security leaders need to know has argued, boards increasingly expect a fast, factual public response to exactly this kind of claim, whether or not it is ultimately verified. None of the four named companies has confirmed data was taken, and Reuters could not independently verify Cl0p’s numbers. But the underlying vulnerability is real, the patch has existed since June, and the exploitation window is not.
Frequently asked questions
What is Cl0p claiming about the Shell data breach?
Cl0p, a ransomware and extortion group, listed Shell on its dark web leak site claiming to have stolen roughly 89 gigabytes of data including engineering drawings, facility photographs, project plans and testing reports. Shell says it is investigating the claim with its security teams and outside experts, but has not confirmed any data loss.
Which other companies did Cl0p name alongside Shell?
Cl0p listed nearly 50 companies on its leak site, including Philips, which it claims lost 13.5 gigabytes of engineering diagrams, as well as GE and financial technology firm Fiserv. Philips confirmed and contained an attempted compromise of one server, and Fiserv said it found no evidence that customer data was affected.
How did Cl0p reportedly gain access to these companies’ systems?
Security researchers link the campaign to CVE-2026-12569, a critical unauthenticated remote code execution flaw in PTC Windchill and FlexPLM, software companies use to manage engineering and product data. PTC patched the flaw on June 18, 2026, and researchers say Cl0p affiliates began exploiting unpatched systems within weeks of the fix.

Leave a Reply