Vulnerabilities

Clop Ransomware Data Theft Claims Investigated by Philips and GE

August 18, 2026 08:13 · 12 min read
Clop Ransomware Data Theft Claims Investigated by Philips and GE

Clop Ransomware Gang Claims Data Theft from Philips and GE

Philips and General Electric (GE) have confirmed that they are investigating claims that the Clop ransomware gang breached their systems and stole sensitive data. The claims were made by the Clop gang, which has listed the two companies on its leak site as part of a batch of 43 new victims likely targeted in data theft attacks.

Investigations Underway

A GE spokesperson said that the company is aware of the claim and is "working to assess the potential issue." A Philips spokesperson confirmed that the company's systems were breached, but stated that the incident has been contained and did not affect customers. "Philips has identified and contained an attempted cybersecurity compromise of a specific enterprise server related to internal data," Philips said in a statement. "This has no impact on customer environments."

Both GE and Philips have yet to provide more details on the alleged breaches, despite being reached out to by BleepingComputer for confirmation. This comes after oil giant Shell also announced that it is investigating a potential security incident after the Clop hacking group claimed it stole 89GB of data.

CVE-2026-12569 Vulnerability Exploited

The Clop gang's attacks are believed to have exploited a critical improper input validation vulnerability (tracked as CVE-2026-12569) against Internet-exposed PTC Windchill and PTC FlexPLM instances. PTC says that the two enterprise software platforms are widely used by high-profile companies across the aerospace, defense, automotive, heavy machinery, retail, and medtech sectors.

More than 30,000 customers globally use PTC's products, including over 1,500 brand and retail customers using FlexPLM. The company began releasing security patches for the vulnerability on June 17 and urged customers to review their environments for indicators of compromise (IOCs) in a private advisory.

Stolen Data Includes Sensitive Information

The Clop gang claims to have stolen a wide range of sensitive data from the companies' compromised systems, including backups, project plans, photos of facilities, drawings, diagrams, blueprints, and more. The stolen data belongs to Shell, GE, and Philips.

Cybersecurity company ReliaQuest and the Ransomware Information Sharing and Analysis Centre (Ransom-ISAC) have confirmed Clop's Windchill and FlexPLM attacks, in which the threat actors have been deploying JSP webshells to steal sensitive data from victims' compromised PLM platforms.

Emergency Action Taken by Authorities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that the flaw is actively exploited in attacks and has added it to its catalog of known exploited vulnerabilities. German authorities have also taken emergency action, with the Federal Office for Information Security (BSI) warning PTC customers to patch their systems as quickly as possible.

The Clop extortion gang has a long history of targeting enterprise platforms in data theft attacks, breaching Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer file-sharing servers in previous campaigns. The gang has also exploited an Oracle EBS zero-day flaw to steal sensitive files from many organizations.

The list of victims includes many high-profile organizations worldwide, including The Washington Post, GlobalLogic, Harvard University, the University of Pennsylvania, Logitech, Estée Lauder, Korean Air, and American Airlines subsidiary Envoy Air. The U.S. Department of State is offering a $10 million reward for any information linking the cybercrime gang's attacks to a foreign government.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free