GE And Philips Investigate Clop Ransomware Claims As PTC Flaw Bites

General Electric and Philips are investigating claims by the Clop ransomware gang that it stole data via a zero-day in PTC's Windchill and FlexPLM platforms, joining Shell and 40 others.

GE And Philips Investigate Clop Ransomware Claims As PTC Flaw Bites

General Electric and Philips have confirmed they are investigating claims by the Clop ransomware gang that it breached their systems and stole data, becoming the latest names on a growing list of alleged victims tied to a mass exploitation of PTC's Windchill and FlexPLM enterprise software.

What The Two Companies Said

A GE spokesperson said the company is aware of the claim and is "working to assess the potential issue." Philips confirmed the compromise but stressed the fallout was limited: "Philips has identified and contained an attempted cybersecurity compromise of a specific enterprise server related to internal data," a spokesperson told Reuters. "This has no impact on customer environments." Both companies join oil major Shell, which said last Friday it is investigating a potential incident after Clop claimed to have exfiltrated 89GB of its data.

Clop ransomware leak site listings showing GE, Philips and Shell

The PTC Windchill Zero-Day

Clop has listed GE, Philips and Shell alongside 40 other alleged victims from data-theft attacks abusing CVE-2026-12569, a critical improper-input-validation flaw in Internet-exposed PTC Windchill and FlexPLM instances. PTC — whose two enterprise PLM platforms are used by more than 30,000 customers across aerospace, defense, automotive, heavy machinery, retail and medtech — began releasing patches on June 17 and warned customers of "heightened threat activity" on June 26. Clop is said to have deployed JSP webshells to siphon backups, project plans, facility photos, drawings and blueprints from victim systems.

Latest Chapter In Clop's Enterprise-Software Playbook

The Windchill/FlexPLM campaign fits Clop's long-running enterprise-software playbook, following mass exploitations of Accellion FTA, GoAnywhere MFT, MOVEit Transfer, Cleo and, most recently, an Oracle E-Business Suite zero-day that snared Estée Lauder among many others. It arrives on the same day France's DGFiP tax authority confirmed a 2 million-record breach, cementing August 2026 as another brutal month for enterprise defenders. CISA has added CVE-2026-12569 to its Known Exploited Vulnerabilities catalog and Germany's BSI urged customers to patch overnight. The State Department currently offers a $10 million reward for information linking Clop to a foreign government.

Reporting based on coverage from BleepingComputer, Reuters, Industry Week, CISA and PTC advisories dated August 13-17, 2026.

Category: Cyber Security

Tags: Automation Cybersecurity Industrial Deployment ransomware Data Breach

Related Articles