decrypted · 14 august 2026 · ransomware and cybercrime · vulnerabilities and patching
Clop names Shell on its leak site, over a flaw PTC patched in June
Clop's leak site named Shell this week as one of 43 new victims in a data-theft campaign against PTC's Windchill and FlexPLM software, alongside Philips, GE and Fiserv. The gang claims to have taken 89GB of engineering drawings, facility testing reports and project plans. Shell says only that it is "aware of a potential incident" and is investigating; none of the four companies has confirmed data was actually taken, and Clop has published no samples, so treat the theft claim as exactly that, a claim. What is not in doubt is the vulnerability behind it: a remote code execution flaw that PTC patched in mid-June and confirmed was already being exploited within a day, and that attackers were still finding unpatched, internet-facing copies of two months later.
The flaw, in plain English
Windchill and FlexPLM are product lifecycle management systems: the electronic filing cabinet that holds a manufacturer's CAD files, supplier specifications, test reports and design history, the kind of software that engineering, automotive, aerospace and retail firms run to keep every version of every part under control. Because engineers need to reach it from client sites and factory floors, it often sits with a login page exposed directly to the internet.
CVE-2026-12569, CVSS 9.3, let an attacker skip that login page entirely. By chaining a data leak in Windchill's FlexPLM WSDL endpoint, a machine interface that answered questions it should have demanded credentials for first, with a flaw in the login servlet itself, an attacker could plant a web shell without ever authenticating. It's the equivalent of a reception desk that hands over an access badge to anyone who asks the right question, no ID check required. From there, Clop's affiliates catalogued the filesystem, staged the interesting files and moved to extortion.
What UK organisations should take from the timeline
The instructive part isn't the bug, it's the gap. PTC published its advisory and remediation steps on 17 June and confirmed exploitation within a day. CISA had the flaw in its known-exploited catalogue by 25 June and gave US federal agencies three days to fix it. The campaign nonetheless widened through July, and by August, Clop was still finding new, unpatched, internet-facing instances to add to its leak site, Shell reportedly among them.
That's a Secure by Design failure on two levels. First, software this sensitive should never need to be reachable from the open internet at all: a VPN or zero-trust gateway in front of it removes an entire class of pre-authentication bugs, whatever the CVE count turns out to be. Second, a vendor confirming active exploitation on day one is not a routine patch cycle, it's a same-week fire drill, and two months later is too late regardless of how good the eventual fix was. UK manufacturers, and the aerospace and automotive supply chains that depend on them, are exactly the sort of Windchill users this campaign is targeting. Anyone running it, or any PLM system, facing the internet should be checking exposure now, not waiting for their own name to turn up on a leak site.
Also this week
ShinyHunters, the extortion group behind this year's wave of Salesforce and Snowflake-linked data thefts, published a 280GB archive of RingCentral customer data in mid-August after the cloud communications provider refused to pay. RingCentral disclosed the breach on 28 July, blaming a "sophisticated social engineering campaign", and says around 1.6 million accounts had names, emails, phone numbers and addresses exposed, with no impact on its core calling and messaging platform. RingCentral serves hundreds of thousands of businesses, plenty of them in the UK, who use it for phone systems; the lesson is the increasingly familiar one, that the weak point in a well-defended platform is usually a person with legitimate access, not the software itself.
A report this week from London-based Intruder, a GCHQ Cyber Accelerator alumnus, found weak identity and access controls in 87 to 98 percent of the cloud accounts it scanned, worsening with company size, and internet-exposed services on 76 percent of AWS accounts against 8 percent of Google Cloud ones. Its founder, Chris Wallis, put it plainly: moving to the cloud doesn't make an organisation secure by default, each provider fails in its own particular way, and average remediation still takes over a month at larger firms. For any UK board treating a cloud migration as a security upgrade in itself, that gap between provider and comfortable assumption is worth closing.
Sources
- Shell investigates 'potential incident' after Clop data theft claims
- PTC Windchill Vulnerability Exploited in Ransomware Campaign
- JSP webshells being dropped on unpatched PTC Windchill instances
- RingCentral data breach exposed info of 1.6 million accounts
- Weak IAM affects up to 98% of cloud environments
If your organisation runs internet-facing PLM, ERP or other enterprise software and you're not sure what's exposed, get in touch.
More like this
- The phone call that gets past your passkey 12 september 2026
- The SSO flaw that let one attacker log in as 138 companies 11 september 2026
- MikroTik routers are being hijacked exactly as NCSC warned they would be 8 september 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.
Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.