Clop Ransomware Hits Philips, GE, And Shell
Industrial and energy giants Philips, General Electric (GE), and Shell have all confirmed they are investigating claims made by the Clop ransomware gang that it stole data from their systems. The disclosures follow a wider extortion campaign in which the cybercrime group exploited a critical vulnerability in PTC's Windchill and FlexPLM software to break into corporate networks and exfiltrate sensitive files.

Philips acknowledged that attackers targeted one of its systems but said the incident was limited in scope. The company stated that it identified and contained an attempted compromise of a specific enterprise server linked to internal data, and stressed that the intrusion did not reach customer-facing environments. A GE spokesperson said the company is aware of the claim and is working to assess the potential issue, while a Shell spokesperson confirmed the oil giant is investigating a potential incident after Clop claimed to have stolen 89GB of data from its systems.
None of the three companies has published a detailed account of what data may have been taken or confirmed the extent of the intrusion, and representatives for GE and Philips did not immediately respond to further requests for comment.
Clop listed Philips, GE, and Shell on its dark web leak site as part of a batch of 43 newly named victims, which the gang says were compromised through internet-exposed instances of PTC Windchill and PTC FlexPLM, two enterprise Product Lifecycle Management (PLM) platforms used by manufacturers to manage products from design through production.
The attacks exploited a critical flaw tracked as CVE-2026-12569, an improper input validation and unsafe deserialization vulnerability that allows unauthenticated attackers to execute code remotely on vulnerable systems. The National Vulnerability Database lists the flaw with a CVSS 3.1 base score of 9.8, and PTC's own CVSS 4.0 rating places it at 9.3, both in the critical range. The bug affects Windchill PDMLink and FlexPLM releases prior to version 11.0 M030, as well as numerous later builds up to 13.1.3.0.
Once inside a vulnerable environment, Clop's operators have been observed deploying JSP web shells to maintain remote access and exfiltrate data from compromised PLM platforms. According to the attackers' own claims, the stolen material spans backups, project plans, internal photos of manufacturing facilities, engineering drawings, diagrams, and blueprints belonging to the affected organizations.
"Philips has identified and contained an attempted cybersecurity compromise of a specific enterprise server related to internal data," a Philips spokesperson said. "This has no impact on customer environments."
A Shell spokesperson offered a similarly guarded statement, saying only that the company is aware of a potential incident and is working with its security teams and outside experts to investigate.
Because PTC Windchill and FlexPLM are deployed by more than 30,000 customers worldwide, including over 1,500 brand and retail companies that rely specifically on FlexPLM, the exposure extends well beyond the three companies named so far. Both platforms are widely used across aerospace, defense, automotive, heavy machinery, retail, and medical technology sectors, industries where the loss of proprietary product data, engineering schematics, or manufacturing details could carry significant competitive and security consequences.
How the Windchill and FlexPLM attacks unfolded
- PTC began releasing patches for CVE-2026-12569 on June 17, 2026, and issued private guidance urging customers to check their environments for indicators of compromise, though it did not confirm active exploitation at the time.
- PTC warned of "heightened threat activity" on June 26, prompting the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add the flaw to its Known Exploited Vulnerabilities catalog and order federal agencies to secure their instances within three days.
- Cybersecurity firm ReliaQuest and the nonprofit Ransomware Information Sharing and Analysis Center (Ransom-ISAC) both confirmed active exploitation in July, tying the intrusion tradecraft to patterns consistent with previous Clop campaigns.
- Germany's Federal Office for Information Security (BSI) took the unusual step of contacting PTC customers overnight to urge immediate patching, mirroring emergency action it took in March over a related Windchill and FlexPLM flaw tracked as CVE-2026-4681.
- Ransom-ISAC investigators observed Clop sending extortion emails from previously compromised third-party accounts to hundreds of employees at targeted organizations, a tactic the group also used during its Oracle E-Business Suite campaign the previous year.
Security researchers have advised organizations that are still running exposed Windchill or FlexPLM instances to apply PTC's patches immediately, place the systems behind a VPN or another trusted access gateway, and treat any suspected compromise as an active incident by isolating affected servers, preserving forensic evidence, and rotating credentials before restoring service.
Clop has built a long track record of breaching widely used enterprise software to steal data at scale rather than deploying traditional file-encrypting ransomware. Previous campaigns exploited flaws in Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo file-transfer software, and MOVEit Transfer, the last of which affected more than 2,770 organizations globally.
Since August 2025, the gang has also been exploiting a separate Oracle E-Business Suite zero-day to steal files from a long list of organizations, including Harvard University, The Washington Post, GlobalLogic, the University of Pennsylvania, Logitech, Estée Lauder, Korean Air, and American Airlines subsidiary Envoy Air.
In each case, the group's pattern has been consistent: quietly harvest data from vulnerable systems over weeks or months, then use the stolen files as leverage in a mass extortion push once the exploitation window closes. Companies that decline to pay are typically named on Clop's leak site, with stolen data eventually made available for bulk download.
Clop presents a unique and possibly devastating threat to organizations for two distinct reasons:
- Clop's exploitation of file-transfer and enterprise-data platforms has consistently preceded large, multi-victim extortion waves rather than isolated incidents, meaning more organizations using Windchill or FlexPLM could still be identified as victims in the weeks ahead.
- The vulnerability allows unauthenticated remote code execution, so any internet-facing instance that has not been patched or isolated remains at risk regardless of whether an organization has already seen evidence of compromise.
The U.S. Department of State continues to offer a $10 million reward for information linking Clop's operations to a foreign government, reflecting the scale and persistence of the group's activity. For now, Philips, GE, and Shell have not disclosed whether they have received direct extortion demands from Clop, and the gang has not set a public deadline for the companies to respond before further data is potentially leaked.
Organizations running PTC Windchill or FlexPLM that have not yet applied the June patches for CVE-2026-12569 are strongly encouraged to do so immediately, review logs for signs of unauthorized JSP web shell activity, and treat any internet-exposed instance as a priority for remediation.
Share:
Karolis Liucveikis
Experienced software engineer, passionate about behavioral analysis of malicious apps
Author and general operator of PCrisk's News and Removal Guides section. Co-researcher working alongside Tomas to discover the latest threats and global trends in the cyber security world. Karolis has experience of over 8 years working in this branch. He attended Kaunas University of Technology and graduated with a degree in Software Development in 2017. Extremely passionate about technical aspects and behavior of various malicious applications.
PCrisk security portal is brought by a company RCS LT.
Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.
Our malware removal guides are free. However, if you want to support us you can send us a donation.
DonatePCrisk security portal is brought by a company RCS LT.
Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.
Our malware removal guides are free. However, if you want to support us you can send us a donation.
Donate
▼ Show Discussion