- September Edition
- Reading time~ 2mins
THE BIG DEAL Shell said on 14 August it was investigating after the Clop extortion group claimed 89 gigabytes of engineering drawings, facility test reports and project plans; GE and Philips followed, with Clop claiming 391 and 13.5 gigabytes respectively. The three are among 43 organisations Clop has listed after a campaign against internet-exposed PTC Windchill and FlexPLM lifecycle platforms, which exploited CVE-2026-12569 with a purpose-built web shell. PTC has more than 30,000 customers across aerospace, defence, automotive and medtech. The stolen material is not personal data. It is the design record of industrial companies, held in plain form inside the platform built to manage it, and it holds its value for decades.
TAKEAWAY Intellectual property deserves the encryption reserved for customer data, because a blueprint does not expire. Classify engineering repositories as crown jewels, protect the files inside the PLM platform rather than only the platform itself, and treat any internet-facing instance as compromised until proven otherwise.
You cannot monitor what you haven’t mapped. You cannot protect what you haven’t found. DISCOVER is step one of the GuardWare data-first security sequence. INSIGHT monitors everything including AI. PROTECT encrypts every sensitive file, so data that leaves your environment is worthless to anyone without your keys.
Related Blogs
Eight Agents, Four Days: AI Runs a Government Intrusion in Taiwan
Closer to Home: Origin Energy’s Breach Traced to a Manila Call Centre
284 Million Rows in Four Days: McKesson’s Cloud Warehouses Emptied
How an SME Built a Security Posture That Enterprise Clients Trust
What If Your Data Could Protect Itself? A Data-First Security Playbook
Payment Security Summit & Gala – Australia 2026
Do you know where your sensitive data is?
Stop your IP and Design files from being stolen?


