Clop Ransomware Group Targets GE, Philips, and Shell in Latest Data Theft Campaign
The notorious **Clop** ransomware gang has claimed responsibility for breaching the systems of industrial giants **General Electric (GE)** and **Philips**, alongside oil major **Shell**. This latest wave of attacks exploits a critical vulnerability in **PTC Windchill** and **PTC FlexPLM** enterprise software, leading to the alleged theft of substantial sensitive data.
Cybersecurity professionals and privacy-conscious users are once again on high alert as the **Clop** ransomware group expands its reach, adding **General Electric (GE)**, **Philips**, and **Shell** to its growing list of high-profile victims.
### Industrial Giants Confirm Investigations
Both **GE** and **Philips** have confirmed they are investigating claims by **Clop** regarding system breaches and data exfiltration. A **GE** spokesperson stated the company is "working to assess the potential issue." **Philips**, in a statement shared with Reuters, confirmed an attempted cybersecurity compromise of a "specific enterprise server related to internal data," adding that the incident has been contained and had "no impact on customer environments."

**Shell** also announced its investigation into a potential security incident last Friday, following **Clop's** claims of stealing 89GB of data.
### Exploiting PTC Windchill and FlexPLM Vulnerability
The **Clop** gang has listed these companies on its leak site as part of a batch of 43 new victims. These attacks are believed to leverage a critical improper input validation vulnerability, tracked as **CVE-2026-12569**, affecting internet-exposed instances of **PTC Windchill** and **PTC FlexPLM**.
**PTC**, a software company, states that its **Windchill** and **FlexPLM** platforms are widely adopted by over 30,000 customers globally across various critical sectors, including aerospace, defense, automotive, and medtech.
**Clop** asserts that it has stolen a wide array of sensitive information from the compromised systems, including backups, project plans, facility photos, drawings, diagrams, and blueprints belonging to **Shell**, **GE**, and **Philips**.

### Urgent Calls for Patching and Mitigation
**PTC** initiated the release of security patches for **CVE-2026-12569** on June 17, urging customers to review their environments for indicators of compromise (IOCs). The **Ransomware Information Sharing and Analysis Centre (Ransom-ISAC)** has since corroborated **Clop's Windchill** and **FlexPLM** attacks, noting the deployment of JSP webshells for data exfiltration.
The **U.S. Cybersecurity and Infrastructure Security Agency (CISA)** confirmed active exploitation of the flaw, adding it to its catalog of known exploited vulnerabilities. This prompted **CISA** to mandate federal agencies to secure their **PTC Windchill** and **FlexPLM** instances within three days of the alert. German authorities, specifically the **Federal Office for Information Security (BSI)**, also issued urgent warnings to **PTC** customers, emphasizing immediate patching.
### Clop's History of Exploiting Enterprise Platforms
**Clop** has a well-documented history of exploiting vulnerabilities in enterprise file-sharing and data transfer platforms for data theft. Previous campaigns have targeted **Accellion FTA**, **GoAnywhere MFT**, **SolarWinds Serv-U FTP**, **Cleo**, and **MOVEit Transfer**, with the **MOVEit** breach alone impacting over 2,770 organizations worldwide.
More recently, starting in early August 2025, **Clop** began exploiting an **Oracle EBS** zero-day flaw, compromising organizations such as **The Washington Post**, **GlobalLogic**, **Harvard University**, and **Logitech**.
In response to **Clop's** persistent and impactful activities, the **U.S. Department of State** is offering a $10 million reward for information linking the cybercrime group's attacks to a foreign government.