Cl0p’s breach of Shell 89 GB's of Data Leaked



Cl0p’s breach of Shell refers to a large-scale data‑theft campaign in mid‑2026 in which the Russia‑linked extortion group Cl0p claimed to have stolen ~89 GB of internal engineering and operational data from Shell. This incident was part of a broader wave of attacks affecting nearly 50 companies worldwide, including Philips, GE, and Fiserv.

What happened

  • Cl0p listed Shell as a victim on its leak site, claiming theft of:

    • Engineering drawings

    • Facility photographs

    • Technical inspection reports

    • Project plans

  • Shell publicly acknowledged a “potential incident” and launched an internal investigation with security teams and external experts.

  • As of the latest reporting, Shell had not confirmed whether data was actually exfiltrated, but Cl0p’s claims were consistent across multiple outlets.

How Cl0p got in

Evidence strongly suggests the breach was part of a mass exploitation campaign targeting a critical vulnerability in PTC Windchill and FlexPLM—enterprise engineering and manufacturing software used by tens of thousands of organizations.

Key points:

  • Vulnerability: CVE‑2026‑12569, a high‑severity deserialization flaw allowing unauthenticated remote code execution.

  • Attack chain: Combined with a pre‑auth information‑disclosure flaw in FlexPLM’s WSDL endpoint to map environments before exploitation.

  • Ransom‑ISAC and CISA confirmed active exploitation and issued urgent patching directives.

This was not a targeted attack on Shell specifically—Cl0p used a single software flaw to breach dozens of companies simultaneously.

Why this breach matters

  • Scale: Nearly 50 companies impacted globally.

  • Type of data: Highly sensitive engineering and infrastructure documentation, not typical customer PII.

  • Extortion model: Cl0p specializes in quiet data theft followed by ransom demands—no encryption, just leverage.

  • Precedent: Similar to Cl0p’s MOVEit mass breach in 2023, showing the group’s preference for exploiting shared enterprise software.

Shell’s response

Shell stated:

  • It is aware of a potential incident.

  • It is working with internal and external experts.

  • It has not confirmed data theft publicly.

Comments

Popular posts from this blog

Entire List Leaked for Canvas Ransomware Attack

WSUS CVE-2025-59287 Mitigation

Cloud Infrastructures are Having a Bad Week

CVE-2025-58034 Fortinet Warnings and Mitigation

Broadcom is dismantling of VMware Cloud Service Providers (VCSPs)

FBI Seizes RAMP Cybercrime Forum

Instagram Data Leak Update

CodeRED emergency alert system is currently down across many regions!

Notepad++ update service was compromised

SitusAMC Breached!