Philips and General Electric (GE) are investigating incidents after the Clop ransomware group claimed to have stolen data from both companies.
The companies are among 43 organizations recently listed on Clop’s data leak site.
These incidents may be connected to attacks targeting internet-exposed PTC Windchill and PTC FlexPLM systems through CVE-2026-12569.
“Cl0p’s playbook hasn’t been a mystery for years. They’ve repeatedly targeted widely used enterprise software, exploited known weaknesses, and used stolen data as leverage,” said Pete Luban, Field CISO at AttackIQ, in an email to eSecurityPlanet.
He explained, “The challenge is turning that knowledge into action. CTEM gives organizations a way to continuously identify the exposures that are most likely to matter, rather than treating every vulnerability as equally urgent.”
Key takeaways of the Philips and GE incidents
- Philips and GE are investigating incidents after Clop claimed to have stolen data from both companies.
- Clop has listed 43 organizations as potential victims in a campaign that may involve internet-exposed PTC Windchill and FlexPLM systems.
- CVE-2026-12569 may be connected to the attacks, but the initial access vector and extent of exploitation across the claimed victims remain under investigation.
- Philips confirmed a compromise involving an internal enterprise server but said customer environments were not affected, while GE is still assessing Clop’s claim.
- Organizations using Windchill or FlexPLM should prioritize patching exposed instances and investigate for evidence of compromise or data exfiltration.
Philips confirms enterprise server compromise
Philips confirmed that it detected and contained unauthorized activity involving a specific enterprise server containing internal information.
The company has not publicly disclosed what internal information may have been accessed or whether data was successfully exfiltrated.
GE has provided fewer details. A company spokesperson said GE was aware of the threat actor’s claim and was “working to assess the potential issue,” according to BleepingComputer.
Neither company has publicly confirmed the extent of Clop’s claimed data theft.
Clop lists 43 potential victims
Clop’s latest victim list extends beyond Philips and GE and includes oil and gas company Shell.
Shell recently confirmed it was investigating a potential security incident after the ransomware group claimed to have stolen approximately 89GB of company data.
The companies may be part of a broader campaign targeting PTC Windchill and PTC FlexPLM, enterprise platforms used for product lifecycle management (PLM).
These systems can contain sensitive corporate information, including product and engineering data, making compromised deployments potentially valuable targets for data-focused extortion groups.
How organizations can reduce risk
Organizations using PTC Windchill or FlexPLM should take the following steps to reduce the risk of exploitation and identify potential compromise.
- Identify and patch affected PTC Windchill and FlexPLM instances, prioritizing systems exposed to the internet.
- Review application, authentication, network, and firewall logs for suspicious access, unusual data transfers, or other indicators of compromise.
- Rotate potentially exposed credentials, API keys, service account passwords, authentication tokens, and other secrets accessible from affected systems.
- Isolate suspected systems and hunt for persistence mechanisms, including unauthorized accounts, web shells, modified files, and unusual processes.
- Strengthen network segmentation and restrict unnecessary inbound and outbound connectivity to limit lateral movement and data exfiltration.
- Enforce least-privilege access and review privileged and service accounts to ensure compromised applications cannot unnecessarily access sensitive systems or data.
- Test incident response plans and use attack simulation tools with scenarios around PLM platform compromise and data exfiltration.
Bottom line
As investigations continue, security teams should watch for confirmation of how Clop gained access and whether CVE-2026-12569 was exploited across the 43 claimed victims.
If confirmed, teams should review historical exposure and telemetry to determine whether vulnerable systems were accessible or compromised before remediation.
Zero trust solutions can help further reduce exposure by enforcing continuous verification and limiting access between critical systems and sensitive data.





