The Shell Breach Blueprint: Why Vendor Visibility Is Your Biggest Security Gap
Shell is investigating a breach that never should have happened. 89 GB of engineering data stolen through a vendor connection they probably didn't know existed. And their $1B+ security infrastructure couldn't see it coming.
This isn't a story about sophisticated attackers. It's about an invisible gap in every organization's security posture, and how it keeps closing the same way.
What Shell's Security Team Could See (And Couldn't)
Shell's security team monitors firewalls, logs thousands of alerts, tracks employee behavior, and controls network perimeter. They have visibility into their own infrastructure.
What they can't see:
- Who has external access to their systems. Which vendors. Which integrations. Which accounts.
- What those connections are doing. Pattern-of-life for vendor identities. Whether a PTC account pulling files at 3 AM is normal or abnormal.
- Whether access is acting normally. Unusual geographies. Abnormal rates. Accessing data they've never touched.
This isn't because Shell's team is bad. It's because external vendor access is still treated as an IT checkbox, not a security crisis.
The Real Breach Mechanics
Cl0p exploited CVE-2026-12569 in PTC Windchill. Nearly 50 organizations got hit the same way. Shell was one of them.
But here's what matters: The breach wasn't sophisticated. No zero-day. No social engineering. No credential theft in the traditional sense. Attackers logged in using valid, active vendor credentials and pulled data while Shell's security team watched their employee logins and firewall rules.
They had no visibility into whether the PTC account was:
- Logging in from an unusual location
- Downloading at 10x normal rates
- Accessing files it never touched before
- Acting like a legitimate vendor or like an attacker
They couldn't know. And by the time they realized what happened, the data was gone.
This Keeps Happening. Different Vendors. Same Blindness.
- Bol and De Bijenkorf: Attackers logged in through compromised third-party access
- Amgen: Vendor account exploitation
- EY: External credential abuse
- Deutsche Bank: Third-party breach cascade
- Polymarket, Lidl, Shell: Same story
The pattern is unmistakable. Attackers stopped breaking in years ago. They log in. They use valid credentials nobody has visibility into. And security teams don't know until the investigation starts.
The Visibility Gap That Closes Nothing
Most organizations can tell you:
- Every employee who logged in yesterday
- What files they accessed, from which devices, from where
- Every anomaly on your network perimeter
Ask them these questions:
- How many vendor accounts have access to your infrastructure right now?
- Which one of those accounts acted unusual in the last month?
- Which ones have MFA enabled?
Most CISOs can't answer. That's not a gap. That's a blind spot. And blind spots are where breaches live now.
Pattern-of-Life Visibility: The Solution Shell Needed
Shell's team probably wanted to:
- See every external connection touching their infrastructure
- Understand what's normal for each vendor identity
- Detect when behavior deviates from baseline
- Catch the anomaly before data leaves the network
They couldn't do it. Because visibility tools for external access don't exist in most organizations.
But they should. Here's what pattern-of-life security does:
Five things you need to see:
- Who each external identity is (vendor name, relationship, purpose)
- Where they typically log in from (geographic baseline)
- What devices they use (normal endpoints vs anomalies)
- What files they access (data access patterns)
- When they deviate (unusual times, locations, rates, permissions)
When the PTC account logs in from a new geography at an unusual time, accessing files it's never touched, downloading at 10x the normal rate—you see it immediately. Not during incident response. During the attack.
That's the difference between a breach story and a breach prevented.
Your Move
Shell had expertise. They had budget. They had a world-class security team. What they didn't have was visibility into their external access layer. One gap. One breach.
Your organization has the same gap right now.
The question isn't whether you'll face vendor-related risk. You will. The question is whether you'll see it before attackers exploit it.