General Electric (GE) and Philips have begun investigating claims by the Clop ransomware gang that it breached their systems and stole data from them, in a development that comes as part of a broader campaign targeting organizations that use the PTC Windchill and PTC FlexPLM platforms for product lifecycle management.
A GE spokesperson said the company was aware of the claim and was working to assess the potential issue. Philips, meanwhile, confirmed that its systems had been breached, explaining that the incident was limited to an attempted breach of a specific corporate server associated with internal data, and that it had been contained without affecting customer environments. As of the report's publication on August 17, 2026, neither company had provided additional details or responded to BleepingComputer's inquiries to confirm Clop's claims.
Claims Part of a Campaign Targeting Product Management Platforms
Clop listed all three companies—GE, Philips, and oil company Shell—among 43 new victims on its leak site. Reports believe that these attacks were carried out by exploiting a critical input-validation vulnerability, tracked as CVE-2026-12569, in internet-exposed versions of Windchill and FlexPLM.
Clop said it stole a wide range of data from the companies' systems, including backups, project plans, facility images, drawings, diagrams, and engineering specifications. The gang also claimed that Shell lost 89 gigabytes of data, but the companies have not yet published enough information to verify the size or nature of the data.
Shell had previously confirmed that it was aware of a potential incident and was working with security teams and relevant experts to investigate it.
Why Does This Development Matter to PTC Customers?
The importance of the incident lies in the platforms' broad user base; PTC says its products are used by more than 30,000 customers worldwide, including more than 1,500 brand and retail companies through FlexPLM. Potentially affected sectors include aerospace and defense, automotive, heavy machinery, retail, and medical technology, making the data stored in these systems highly valuable operationally and from an engineering perspective.
PTC began releasing patches for the vulnerability on June 17 and urged customers to review their environments for indicators of compromise in dedicated guidance, despite there being no confirmation at the time that it was being actively exploited. However, ReliaQuest and the Ransom-ISAC ransomware information-sharing center later confirmed Clop attacks against Windchill and FlexPLM that involved deploying JSP webshell control tools to steal sensitive data.
Security Agencies' Response
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed that the vulnerability was being actively exploited. After PTC warned of increased threat activity on June 26, CISA added it to its Known Exploited Vulnerabilities Catalog and required federal agencies to secure Windchill and FlexPLM instances within three days. Germany's Federal Office for Information Security (BSI) also warned customers about the risk and urged them to install the patches as soon as possible.
The campaign follows a recurring pattern by Clop of targeting enterprise platforms and stealing data, after previous campaigns affected Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer, with the MOVEit campaign affecting more than 2,770 organizations worldwide. Since early August 2025, the gang has also exploited an undisclosed zero-day vulnerability in Oracle EBS, while the U.S. Department of State is offering a reward of $10 million for information linking the gang's attacks to a foreign government.