General Electric and Philips have confirmed they are investigating claims from the Clop extortion gang that it stole data from their systems joining oil giant Shell as the second and third multinationals drawn into the campaign this month.
A Philips spokesperson told Reuters the company had identified and contained an attempted compromise of “a specific enterprise server related to internal data,” adding that the incident had no impact on customer environments. A GE spokesperson gave a thinner answer saying only that the company is “working to assess the potential issue.”
That gap matters. Philips has effectively confirmed an intrusion while stopping short of confirming what, if anything, left its network. GE has confirmed nothing beyond awareness of the claim. Clop listing both companies on its dark web leak site is an allegation, not proof of what was taken.
Shell was drawn into the story first, on 13 August, when a spokesperson said the company was “aware of a potential incident” and working with security teams to investigate after Clop claimed to have stolen 89GB of data from its systems.
43 Victims, One Recycled Vulnerability
Clop listed Shell, GE and Philips among 43 new victims added to its leak site all likely compromised through the same flaw, CVE-2026-12569, a critical improper input validation vulnerability in PTC Windchill and FlexPLM. Both are product lifecycle management platforms used by engineering, manufacturing and supply chain teams to track products from design to production. PTC says more than 30,000 customers run its software globally including over 1,500 brand and retail companies using FlexPLM across aerospace, defence, automotive, heavy machinery, retail and medtech.
Clop claims it took backups, project plans, facility photographs, drawings, diagrams and blueprints from the compromised Windchill and FlexPLM instances at Shell, GE and Philips.
Confirmed Exploitation, Not Just a Claim
PTC released patches for CVE-2026-12569 on 17 June and issued a private advisory urging customers to check for indicators of compromise, though it did not confirm active exploitation at the time. That changed within weeks. ReliaQuest said it observed threat actors actively exploiting the flaw, rated 9.3 on the CVSS scale, deploying JSP webshells for remote command execution and data exfiltration. The Ransomware Information Sharing and Analysis Centre corroborated the activity a day later.
Ransom-ISAC’s Brandon Parsons of Ascent Solutions asserts that Clop is sending extortion emails from previously compromised accounts to hundreds of employees at each target, the same approach the gang used during its Oracle E-Business Suite campaign last year.
CISA added CVE-2026-12569 to its Known Exploited Vulnerabilities catalogue after PTC warned of “heightened threat activity” on 26 June, giving US federal agencies three days to secure their instances. Germany’s Federal Office for Information Security went further, phoning and emailing PTC customers overnight to urge immediate patching.
A Familiar Playbook
Clop has run this playbook against enterprise platforms for five years including Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U, Cleo and MOVEit Transfer, the last of which affected more than 2,770 organisations. Its Oracle EBS campaign, running since August 2025, has already claimed Harvard University, The Washington Post, Logitech, Estée Lauder and Korean Air among its victims. The Windchill and FlexPLM campaign follows the same shape, find one widely deployed enterprise platform, exploit it at scale, then extort victims individually once the data is out.
PTC customers running internet-facing Windchill or FlexPLM instances should apply the 17 June patch immediately, place the platform behind a VPN or trusted access gateway, and treat any unpatched instance as compromised until an IOC review says otherwise. The US State Department’s $10 million reward for information tying Clop to a foreign government remains unclaimed.
References
- Philips and GE Investigating Clop Ransomware Data Theft Claims (BleepingComputer)
- Clop Ransomware Targets Windchill, FlexPLM in Data Theft Attacks (BleepingComputer)
- Shell Investigates ‘Potential Incident’ After Clop Data Theft Claims (BleepingComputer)
- Known Exploited Vulnerabilities Catalog (CISA)
- Windchill/FlexPLM RCE Vulnerability Advisory (PTC)
This post is also available in:


