Philips and GE investigating Clop ransomware data theft claims
August 17, 2026 · BleepingComputer · Severity: CRITICAL
This article reports that the Clop ransomware gang has claimed data theft attacks against General Electric (GE), Philips, and Shell, exploiting a critical improper input validation vulnerability (CVE-2026-12569) in internet-exposed PTC Windchill and FlexPLM enterprise platforms. GE confirmed it is investigating the claim, while Philips acknowledged a breach of an internal enterprise server but stated the incident was contained and did not affect customers. Shell also confirmed it is investigating a potential incident after Clop claimed to have stolen 89GB of data. The Clop gang listed these three companies among 43 new victims on its leak site, claiming to have stolen backups, project plans, facility photos, drawings, diagrams, and blueprints. PTC released security patches on June 17 and urged customers to check for indicators of compromise. Cybersecurity firm ReliaQuest and the Ransomware Information Sharing and Analysis Centre (Ransom-ISAC) confirmed that Clop deployed JSP webshells to exfiltrate data from compromised PLM platforms. CISA added the vulnerability to its known exploited vulnerabilities catalog, mandating federal agencies to patch within three days, and German authorities (BSI) issued emergency warnings for PTC customers to patch immediately. The article also notes Clop’s history of targeting enterprise platforms, including previous campaigns against file-sharing servers (affecting over 2,770 organizations) and exploiting an Oracle EBS zero-day flaw. The U.S. Department of State is now offering rewards for information linking Clop’s attacks to a foreign government. Finally, the article highlights a broader security insight: once attackers obtain valid credentials, only 37% of their subsequent actions are blocked, underscoring the need for better post-authentication defense monitoring.
Key Takeaways
- Immediately patch CVE-2026-12569 in all internet-exposed PTC Windchill and FlexPLM instances, as Clop is actively exploiting this improper input validation vulnerability to deploy JSP webshells and steal sensitive data.
- Audit and restrict access to enterprise PLM servers — especially those containing backups, project plans, blueprints, and diagrams — since Clop specifically targets these platforms for high-value intellectual property theft.
- Implement credential-based threat detection beyond initial access prevention, as the article notes that once attackers have valid credentials, only 37% of their actions are blocked, indicating a critical gap in post-authentication monitoring.