Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data.
While a GE spokesperson said the company is aware of the claim and is "working to assess the potential issue," a Philips spokesperson confirmed its systems were breached but said the incident has been contained and didn't affect customers.
"Philips has identified and contained an attempted cybersecurity compromise of a specific enterprise server related to internal data," Philips said in a statement shared with Reuters. "This has no impact on customer environments."
GE and Philips spokespersons have yet to reply after BleepingComputer also reached out to them for more details and to confirm the Clop ransomware gang's claims.
This comes after oil giant Shell also said on Friday that it is investigating a potential security incident after the Clop hacking group claimed it stole 89GB of data.
"We are aware of a potential incident," a Shell spokesperson told BleepingComputer when asked to confirm the gang's data theft claims. "We are working with our security teams and relevant experts to investigate.
While the three companies have yet to share more information, the Clop gang has listed them on its leak site as part of a batch of 43 new victims likely targeted in data theft attacks exploiting a critical improper input validation vulnerability (tracked as CVE-2026-12569) against Internet-exposed PTC Windchill and PTC FlexPLM instances.
PTC says the two enterprise software platforms are widely used by high-profile companies across the aerospace, defense, automotive, heavy machinery, retail, and medtech sectors. The company says more than 30,000 customers globally use its products, including over 1,500 brand and retail customers using FlexPLM.
In these attacks, Clop claims it stole a wide range of sensitive data from the companies' compromised systems, including backups, project plans, photos of facilities, drawings, diagrams, blueprints, and more, belonging to Shell, GE, and Philips.
Clop data theft claims (BleepingComputer)
... continue reading