Philips and GE investigating Clop ransomware data theft claims

Two Tech Giants and an Oil Giant Investigate Claims of Clop Ransomware Data Theft

A trio of high-profile companies is facing a potentially serious cybersecurity breach after the notorious Clop ransomware gang claimed to have stolen sensitive data from their systems. General Electric (GE), Philips, and Shell are all investigating claims that the attackers exploited a critical vulnerability in enterprise software platforms to gain access to their networks.

According to reports, the Clop gang has listed the three companies on its leak site as part of a batch of 43 new victims likely targeted in data theft attacks. The attack is believed to have involved exploiting an improper input validation vulnerability (CVE-2026-12569) against Internet-exposed PTC Windchill and PTC FlexPLM instances. These platforms are widely used by high-profile companies across various sectors, including aerospace, defense, automotive, and healthcare.

Philips has confirmed that its systems were breached but stated that the incident has been contained and did not affect customers. GE and Shell have acknowledged the claims but declined to provide further details. The Clop gang has claimed to have stolen a wide range of sensitive data from the compromised systems, including backups, project plans, photos of facilities, drawings, diagrams, blueprints, and more.

The attacks follow a pattern of behavior by the Clop ransomware gang, which has a long history of targeting enterprise platforms in data theft attacks. The gang has previously breached Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer file-sharing servers, with the latter affecting over 2,770 organizations worldwide.

The incident highlights the importance of timely patching and vulnerability management. PTC began releasing security patches for CVE-2026-12569 on June 17 but warned customers that there was no confirmation of in-the-wild exploitation at the time. However, cybersecurity companies and government agencies have since confirmed that the flaw is actively being exploited in attacks.

For organizations using PTC Windchill or FlexPLM instances, it’s essential to review their environments for indicators of compromise (IOCs) and apply available security patches as soon as possible. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has also warned federal agencies to secure their PTC Windchill and FlexPLM instances within three days after adding the vulnerability to its catalog of known exploited vulnerabilities.

As the investigation into the claims continues, one thing is clear: timely patching and effective vulnerability management are crucial in preventing such attacks. Organizations should prioritize regular security updates and be vigilant in monitoring their systems for any signs of compromise.


Source: Bleeping Computer — 2026-08-17