Philips and General Electric are investigating claims that the Clop ransomware group stole data from their systems. Philips says it contained an attempted compromise involving an internal server, while GE is still assessing the potential issue.
Clop has listed both companies alongside Shell on its leak site, claiming the organisations were affected in attacks targeting PTC Windchill and FlexPLM systems.
Philips says the incident did not affect customers
Philips confirmed that it identified and contained an attempted cybersecurity compromise involving a specific enterprise server used for internal data.
The company said the incident did not affect customer environments. However, Philips has not publicly confirmed what data, if any, attackers accessed or removed.
GE has also acknowledged the claim. A spokesperson said the company is aware of the alleged incident and is working to assess it.
Shell is investigating a separate potential security incident after Clop claimed it stole 89GB of company data. None of the three companies has confirmed the full scope of the alleged theft.
Clop links the attacks to PTC software flaw
The Clop data theft claims appear connected to a campaign exploiting CVE-2026-12569, a critical vulnerability affecting internet-exposed PTC Windchill and PTC FlexPLM instances.
Windchill and FlexPLM are product lifecycle management platforms used across sectors including aerospace, defence, automotive, retail, heavy machinery and medical technology.
PTC released security updates for the flaw on 17 June and advised customers to check their systems for signs of compromise. Security researchers later confirmed that Clop had used the vulnerability in attacks.
The group reportedly deployed JSP webshells on compromised systems, allowing it to access and exfiltrate sensitive files.
Attackers claim to hold project and engineering files
Clop claims it obtained a broad range of information from affected organisations. The alleged stolen data includes backups, project plans, facility photographs, technical drawings, diagrams and blueprints.
These claims remain unverified. Leak-site listings and ransomware group statements do not independently prove that attackers accessed the data they describe.
Still, the Clop data theft claims have drawn attention because the targeted software is widely used by large organisations worldwide. CISA has confirmed active exploitation of the vulnerability and ordered US federal agencies to secure vulnerable systems within three days of adding it to its Known Exploited Vulnerabilities Catalog.
Germany’s Federal Office for Information Security also issued an urgent warning, telling PTC customers to apply patches as quickly as possible.
Clop continues to target enterprise platforms
Clop has repeatedly targeted vulnerabilities in widely used enterprise software to steal data and pressure victims into paying extortion demands.
Previous campaigns have targeted Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U, Cleo and MOVEit Transfer. Its MOVEit campaign affected thousands of organisations around the world.
The group also exploited an Oracle E-Business Suite zero-day vulnerability in 2025, with alleged victims including major media groups, universities, airlines and technology companies.
US authorities offer a reward of up to $10 million for information that links Clop’s activity to a foreign government.


0 responses to “Philips and GE Investigate Clop Data Theft Claims”