Philips and General Electric are investigating claims from the Clop ransomware group that the attackers breached their systems and stole company data. Clop has listed both companies on its data leak site as part of a wider campaign targeting dozens of organizations. The group claims that it obtained sensitive information from the affected companies, but the full extent of the alleged theft has not been independently confirmed. Reuters also reported that the companies became aware of the claims and started investigations into the incident.

Philips has confirmed that an attempted cybersecurity compromise took place on a specific enterprise server connected to internal data. The company said the incident was identified and contained, and stressed that customer environments were not affected. This means there is currently no indication from Philips that its customer-facing systems were compromised in the incident. The company has not confirmed the amount or type of data that Clop claims to have taken.
GE has also acknowledged the claims and is working to understand whether there was an actual security issue and what impact it may have had. The company has started assessing the potential incident as part of its cybersecurity response. At this stage, GE has not confirmed Clop’s claim that data was stolen from its systems. The investigation is still ongoing, so the actual scope of any compromise remains unclear.

The claims are linked to a broader Clop campaign involving internet-exposed PTC Windchill and PTC FlexPLM systems. These platforms are used by organizations to manage product information, engineering designs and other important business data. PTC says its software is used by more than 30,000 customers worldwide across industries including aerospace, defense, automotive, heavy machinery, retail and medical technology. Because these systems can contain valuable internal information, successful attacks could expose highly sensitive company data.
Security researchers have linked the campaign to a critical vulnerability tracked as CVE-2026-12569. The flaw affects PTC Windchill PDMLink and PTC FlexPLM and can allow remote code execution through the deserialization of untrusted data. The National Vulnerability Database rates the vulnerability as critical with a CVSS score of 9.8 and confirms that it has been added to the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog.

Clop claims that the stolen information from the affected organizations included backups, project information, drawings, diagrams, blueprints and other internal files. Reports say the group listed 43 new victims on its leak site in this campaign, with Shell also among the companies investigating a potential incident. However, the data theft claims made by Clop have not been independently verified, and the companies involved have not publicly confirmed the full list of information allegedly taken.
The incident shows how attackers can use a vulnerability in widely deployed enterprise software to target many organizations at once. Instead of necessarily relying on traditional ransomware encryption, Clop has increasingly used data theft and the threat of public disclosure as a way to pressure victims. This approach can be especially damaging when the targeted systems contain engineering documents, product designs, project files or other confidential business information.

For now, Philips and GE are still investigating what happened and whether Clop’s claims accurately describe the data accessed during the campaign. Philips has confirmed a contained compromise involving an internal enterprise server, while GE is continuing its assessment of the potential issue. No evidence has been publicly provided that customer environments at Philips were affected. Until the investigations are completed, the exact amount of data accessed and the wider impact of the campaign remain unknown.
Stay alert, and keep your security measures updated!
Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news