GE and Philips Investigate Alleged Clop Ransomware Data Theft
General Electric (GE) and Philips have confirmed that they are investigating claims by the Clop ransomware group that it breached their systems and stole sensitive data.
A GE spokesperson said the company was aware of the allegations and was “working to assess the potential issue.” A Philips spokesperson also acknowledged that certain corporate systems had been compromised but said the incident had been contained and that customers were not affected.
“Philips has identified and thwarted an attempted cybersecurity breach of certain corporate servers involving internal data,” Philips said in a statement shared with Reuters. “This does not affect your environment.”
GE and Philips had not responded to BleepingComputer’s requests for additional details or confirmation of the Clop ransomware group’s claims at the time of publication.
The disclosures follow a similar announcement from oil giant Shell, which said it was investigating a possible cybersecurity incident after Clop claimed to have stolen 89GB of company data.
“We are aware of the possibility of an incident,” a Shell spokesperson told BleepingComputer when asked about the alleged data theft. “We are working with our security team and relevant experts to investigate.”
Although GE, Philips, and Shell have not provided detailed information about the alleged breaches, Clop has listed the companies on its leak site among 43 new victims allegedly targeted through attacks exploiting a critical improper input validation vulnerability, tracked as CVE-2026-12569.
The vulnerability affects Internet-exposed instances of PTC Windchill and PTC FlexPLM, enterprise product lifecycle management platforms used by organizations across the aerospace, defense, automotive, heavy equipment, retail, and medical technology industries.
According to PTC, more than 30,000 customers worldwide use its products, including over 1,500 brand and retail companies that rely on FlexPLM.
Clop claims that attackers stole a broad range of sensitive information from compromised organizations, including backups, project plans, facility photographs, drawings, diagrams, blueprints, and other business data belonging to Shell, GE, and Philips.

PTC released a security patch for CVE-2026-12569 on June 17 and urged customers to review their environments for indicators of compromise (IOCs), even though exploitation in the wild had not initially been confirmed. PTC also published additional security guidance for affected customers.
Since then, ReliaQuest and the Ransomware Information Sharing and Analysis Center (Ransom-ISAC) have reported observing Clop attacks targeting Windchill and FlexPLM deployments. In these incidents, attackers reportedly installed a JSP web shell on compromised product lifecycle management platforms to maintain access and steal sensitive data.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) later confirmed that CVE-2026-12569 was being actively exploited and added the flaw to its Known Exploited Vulnerabilities catalog. PTC had previously warned of “increased threat activity” and advised federal agencies to secure affected Windchill and FlexPLM instances within three days.
The vulnerability also prompted urgent action from German authorities. The German Federal Office for Information Security (BSI) urged PTC customers to patch their systems as soon as possible.
The Clop extortion group has a long history of targeting enterprise software and file-transfer platforms in data theft campaigns. Previous attacks affected Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer. The MOVEit campaign impacted more than 2,770 organizations worldwide.
Beginning in early August 2025, Clop also exploited a zero-day vulnerability in Oracle E-Business Suite to steal sensitive files from numerous organizations. Reported victims included the Washington Post, GlobalLogic, Harvard University, the University of Pennsylvania, Logitech, Estée Lauder, Korean Air, and Envoy Air, a subsidiary of American Airlines.
The U.S. State Department is currently offering a $10 million reward for information linking cybercrime groups responsible for attacks to foreign governments.
The overall prevention score can hide what happens after initial access. If an attacker uses valid credentials, your defenses can drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




