Shell
Incident posture
Timeline
Summary
The Clop ransomware group exploited a zero‑day vulnerability in PTC’s Windchill and FlexPLM platforms, gaining unauthenticated remote code execution and deploying a custom web shell to steal credentials and exfiltrate data from dozens of organizations. Among the alleged victims Shell acknowledged a possible incident and said it was investigating, while Philips, Fiserv and GE reported they were reviewing the claims and had found no evidence of compromise to customer or operational systems. The attackers claimed to have taken between one gigabyte and several terabytes of files per company, including databases, engineering documents, backups and images. PTC released a patch and indicators of compromise after the flaw was added to CISA’s known exploited vulnerabilities catalog, but intrusions had already occurred before the fix was available.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
PTC disclosed the vulnerability CVE-2026-12569 on June 17, 2026 and issued a patch and initial indicators of compromise the following day. The Cybersecurity and Infrastructure Security Agency added the defect to its known exploited vulnerabilities catalog on June 25, 2026. The vulnerability permits unauthenticated attackers to execute code remotely via specially crafted requests. Clop began sending threatening emails to its alleged victims in mid‑July 2026. Ransom‑ISAC issued a notice on July 22, 2026 warning that the hacking group was exploiting vulnerabilities in PTC Windchill and FlexPLM. Some companies reported receiving notices from Cl0p on July 19 or July 20, 2026. On August 12, 2026 the Cl0p ransomware group started publishing the full names of alleged victims, including Shell. Shell stated it was aware of a recent "possible incident," confirming an earlier report by Dutch media outlet BNR. A Shell spokesperson said the company was working with its security teams and relevant experts to investigate the situation. Shell did not respond to earlier requests for comment but later provided the above statement.
According to the hackers' claims, the type of data exfiltrated from compromised organizations includes databases, project files, backups, photographs and other image files, engineering documents, blueprints, diagrams, logs, and other corporate documents. The amount of stolen information per organization is said to range between 1 GB and several terabytes. Shell, like Philips, Fiserv and GE, said it is aware of the claims and is investigating. Shell has not confirmed a significant data breach resulting from the alleged incident. Philips reported that it identified and contained an attempted cybersecurity compromise of a specific enterprise server related to internal data and said the incident does not impact customer environments. Fiserv stated that, based on its review to date, it found no evidence that customer, banking, transaction, or personal data had been compromised or that its operating environment had been affected. GE said it had initiated its cyber response protocols and was working to assess the potential issue. The Cl0p website initially listed GE as a victim but later removed the name; the reason for the removal was not disclosed by the group. The hackers did not respond to requests for comment on their claims. Reuters could not independently verify the hacking group’s assertions about the kind or volume of data taken.
Researchers described the tool used by Clop as a custom web shell that maps sensitive vault data, decrypts every credential in the Windchill keystore, and includes a custom Java class loader. The web shell allows Clop to execute additional code inside the application process, creating an unlimited backdoor for follow‑on activity such as lateral movement, ransomware, or persistence. The vulnerability exploited is an improper input validation issue in PTC’s Windchill and FlexPLM software, tracked as CVE-2026-12569. It is the first ever Windchill vulnerability to be exploited in the wild. Clop affiliates used the security hole to deliver the web shell, thereby gaining access to data of organizations that rely on Windchill for supply chain and product lifecycle management. PTC consistently added new indicators of compromise as they were discovered by researchers after the patch was released. The Cybersecurity and Infrastructure Security Agency’s addition of the flaw to its KEV catalog highlighted its active exploitation. The attack followed a pattern seen in prior Clop campaigns targeting zero‑day flaws in Oracle E‑Business Suite, MOVEit, Cleo and GoAnywhere. Those earlier campaigns resulted in data theft from thousands of organizations over extended periods. As of the dates covered in the sources, Shell’s investigation remained ongoing with no public confirmation of breach impact.
Sources
Sources available to members: 3 sources.