2026 Shell — investigating potential incident after Clop claims ~89GB (Windchill/FlexPLM wave)
Data compromised
Clop claims ~89GB including engineering drawings, facility test-report scans, facility photos, project plans. No company-attested individual census — recordsAffected 0.
Technical writeup
Company-confirmed investigation after Clop claim — August 14, 2026. BleepingComputer reported Shell acknowledging a potential security incident and investigating with security teams after Clop listed Shell among victims of data-theft attacks against Internet-exposed PTC Windchill and FlexPLM instances (CVE-2026-12569 improper input validation; CISA KEV). Clop claimed ~89GB including engineering drawings, facility testing-report scans, facility photos, and project plans. Shell had not published an attested individual-records census at indexing — recordsAffected 0. Same campaign listings include General Electric and Philips claims.
Root cause
Clop ransomware/extortion listing claiming theft via PTC Windchill / FlexPLM (CVE-2026-12569 wave); Shell confirms investigating a potential incident