BusinessCybersecurityNewswireTechnology

Philips, GE probe Clop ransomware data theft claims

Originally published on: August 18, 2026
▼ Summary

– GE and Philips are investigating Clop ransomware claims, with Philips confirming a contained breach of an internal server that did not affect customers.
– Shell is also probing a potential incident after Clop claimed theft of 89GB of data, following a pattern of similar responses from the three companies.
– Clop listed 43 new victims, exploiting CVE-2026-12569, a critical flaw in PTC Windchill and FlexPLM platforms used by over 30,000 global customers.
– PTC released patches on June 17, with CISA confirming active exploitation and mandating federal agencies to secure systems within three days, while German authorities issued urgent patch warnings.
– Clop has a history of data theft campaigns against platforms like MOVEit and Oracle EBS, and the U.S. State Department offers a $10 million reward for ties to foreign governments.

General Electric and Philips have joined the growing list of corporations responding to allegations from the Clop ransomware group, which claims to have breached their networks and exfiltrated sensitive information. Both companies have confirmed they are actively looking into the situation, though their initial statements differ in severity.

A GE representative acknowledged awareness of the claim, stating the company is “working to assess the potential issue.” Philips, on the other hand, confirmed that a breach did occur but emphasized that the incident was contained and posed no risk to its customer base. In a statement shared with Reuters, Philips said it “identified and contained an attempted cybersecurity compromise of a specific enterprise server related to internal data,” adding that “this has no impact on customer environments.” Neither firm has provided additional details to BleepingComputer following further requests for comment.

This development follows a similar disclosure from oil giant Shell, which said on Friday that it is investigating a potential security event after Clop claimed to have stolen 89GB of data. A Shell spokesperson told BleepingComputer that the company is “aware of a potential incident” and is “working with our security teams and relevant experts to investigate.”

The three firms were listed on Clop’s leak site as part of a batch of 43 new victims, all believed to have been targeted through a critical vulnerability tracked as CVE-2026-12569. This flaw, an improper input validation issue, has been exploited against internet-facing instances of PTC Windchill and PTC FlexPLM, enterprise software platforms widely used in aerospace, defense, automotive, heavy machinery, retail, and medtech sectors. PTC notes that over 30,000 customers globally rely on its products, including more than 1,500 brand and retail clients using FlexPLM.

According to the ransomware gang, the stolen data from these compromised systems includes backups, project plans, facility photos, drawings, diagrams, and blueprints belonging to Shell, GE, and Philips.

PTC began rolling out security patches for CVE-2026-12569 on June 17, urging customers to inspect their environments for indicators of compromise, even before any active exploitation had been confirmed. Since then, cybersecurity firm ReliaQuest and the Ransomware Information Sharing and Analysis Centre have verified that Clop has been deploying JSP webshells to siphon data from compromised PLM platforms. The U. S. Cybersecurity and Infrastructure Security Agency has also flagged the vulnerability as actively exploited, adding it to its catalog of known exploited vulnerabilities and mandating federal agencies to secure their PTC instances within three days. German authorities have taken similar emergency measures, with the Federal Office for Information Security warning customers to patch systems immediately.

Clop has a well-documented history of exploiting enterprise platforms for data theft, with previous campaigns targeting Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer, the latter impacting over 2,770 organizations worldwide. More recently, the group began exploiting an Oracle EBS zero-day flaw in early August 2025, hitting high-profile victims such as The Washington Post, Harvard University, Logitech, Korean Air, and American Airlines subsidiary Envoy Air.

In response to the ongoing threat, the U. S. Department of State has offered a $10 million reward for information linking Clop’s activities to a foreign government.

(Source: BleepingComputer)

Topics

ransomware attacks 98% corporate data breaches 96% cve-2026-12569 vulnerability 94% clop hacking group 92% supply chain security 89% enterprise software exploitation 87% data theft claims 85% government cybersecurity alerts 83% ptc windchill and flexplm 82% incident response 80%