Breaking
Cyber CrimeConfirmed

Clop Claims Hit GE, Philips as Fallout Widens

GE and Philips confirm probing Clop breach claims as the gang's PTC Windchill attacks ripple through enterprise giants.

··1 hour ago·3 min read
red padlock on black computer keyboard
Photo by FlyD on Unsplash

The Clop ransomware gang has added two more industrial heavyweights to its list of claimed victims. General Electric and Philips have both confirmed they are looking into the group's allegations of data theft, following a similar disclosure from energy giant Shell just days earlier. The moves signal that the fallout from Clop's latest campaign is extending well beyond its initial targets.

GE and Philips Respond to Breach Claims

When reached for comment, a GE spokesperson acknowledged the company is aware of the claim and is "working to assess the potential issue." Philips, meanwhile, went further, confirming that its systems had been breached but stating the incident has been contained and did not affect customers.

"Philips has identified ​and contained an attempted cybersecurity compromise of a specific enterprise server related to ⁠internal data. This has no impact on customer environments."

— Philips statement shared with Reuters

Both companies have yet to respond to additional inquiries from BleepingComputer seeking confirmation of the Clop gang's specific claims. A spokesperson for Shell, which disclosed its investigation on Friday, told the publication, "We are aware of a potential incident. We are working with our security teams and relevant experts to investigate."

Clop's Leak Site Grows by 43

Clop has listed GE, Philips, and Shell on its leak site as part of a batch of 43 new victims, all allegedly targeted through a critical vulnerability in PTC enterprise software. The flaw, tracked as CVE-2026-12569, is an improper input validation issue affecting Internet-exposed PTC Windchill and PTC FlexPLM instances. PTC says these platforms are widely used by high-profile companies in aerospace, defense, automotive, heavy machinery, retail, and medtech sectors.

Data Theft Claims Include Blueprints and Plans

According to Clop's claims, the stolen data includes backups, project plans, photos of facilities, drawings, diagrams, blueprints, and more, belonging to the three companies. The gang has a history of leveraging such data in double-extortion schemes, threatening to release sensitive information if ransoms are not paid.

PTC Patches and Heightened Threat Activity

PTC began releasing security patches for CVE-2026-12569 on June 17, urging customers to review their environments for indicators of compromise (IOCs) in a private advisory, even though there was no confirmation of in-the-wild exploitation at that time. The company later warned of "heightened threat activity" on June 26, after cybersecurity firm ReliaQuest and the Ransomware Information Sharing and Analysis Centre (Ransom-ISAC) confirmed Clop's attacks, which involved deploying JSP webshells to steal data from victims' compromised PLM platforms.

CISA and BSI Respond with Urgency

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its catalog of known exploited vulnerabilities, mandating federal agencies to secure their PTC Windchill and FlexPLM instances within three days. German authorities also took emergency action, with the Federal Office for Information Security (BSI) warning PTC customers in the middle of the night to patch systems as quickly as possible.

Clop's Pattern of Enterprise Attacks

Clop has a long history of targeting enterprise platforms in data theft attacks, having previously breached Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer file-sharing servers. The MOVEit campaign alone affected over 2,770 organizations worldwide. Starting in early August 2025, Clop also began exploiting an Oracle EBS zero-day flaw, adding victims such as The Washington Post, GlobalLogic, Harvard University, the University of Pennsylvania, Logitech, Estée Lauder, Korean Air, and American Airlines subsidiary Envoy Air. The U.S. Department of State now offers a $10 million reward for information linking the cybercrime gang's attacks to a foreign government.

What This Means for Affected Organizations

The confirmed investigations by GE, Philips, and Shell underscore the broad reach of Clop's latest campaign. For any organization running PTC Windchill or FlexPLM, the urgency to patch and hunt for IOCs is clear. The fact that Clop has already listed dozens of victims suggests that many more companies may be unknowingly compromised. The inclusion of blueprints and facility photos in the alleged thefts raises concerns about intellectual property loss, and the pattern of attacks across multiple platforms indicates that Clop is relentless in adapting its methods to exploit new vulnerabilities. While the full impact on GE, Philips, and Shell is not yet known, the potential for significant data exposure is real, and the coming weeks may reveal more details about the scale of the breach.

#clop#ransomware#ptc-windchill#data-breach#cve-2026-12569#ge

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories