bleeping-computer · Crawled Aug 17, 2026

Philips and GE investigating Clop ransomware data theft claims

Read original article ↗

AI Summary

The Clop ransomware gang is conducting data theft attacks against organizations using PTC Windchill and PTC FlexPLM platforms, exploiting a critical vulnerability, CVE-2026-12569, that allows improper input validation. Companies including Philips, General Electric (GE), and Shell have confirmed they are investigating or have confirmed breaches. The attackers deploy JSP webshells to exfiltrate sensitive data such as project plans, blueprints, and internal backups. The U.S. CISA and Germany's BSI have issued urgent warnings, mandating immediate patching due to active exploitation in the wild.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.