INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Philips and GE investigating Clop ransomware data theft claims

| 2026-08-17 11:25 CRITICAL LOW RANSOMWARE & EXTORTION DATA BREACH
Executive Summary
AI-generated
On August 17, 2026, high-profile companies across the aerospace, defense, automotive, heavy machinery, retail, and medtech sectors were targeted by a Clop ransomware gang in attacks exploiting a critical improper input validation vulnerability (CVE-2026-12569) against Internet-exposed PTC Windchill and PTC FlexPLM instances. More than 30,000 customers globally use these platforms, including over 1,500 brand and retail customers using FlexPLM. The U.S. Department of State now offers a $10 million reward for any information linking the cybercrime gang's attacks to a foreign government. Philips and GE are investigating claims that their systems were breached by Clop, with Philips containing an attempted cybersecurity compromise but stating it had no impact on customer environments; Shell is also investigating after claiming it stole 89GB of data from its compromised system.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-12569 and treat internet-facing systems that were not patched in time as potentially compromised until verified. • Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-12569CVE-2026-12569
Target & Sectors
DACH DACH defensedefense governmentgovernment automotiveautomotive retailretail aerospaceaerospace
Incident Timeline
‎August 2025
The U.S. Department of State now offers a $10 million reward for any information linking the Clop ransomware gang's attacks to a foreign government, announced in August 2025.
financial $10 reward
‎2026/08/17
The Clop ransomware gang has claimed to have stolen 89GB of data from Shell, prompting the oil giant and other companies including Philips and GE to investigate potential security incidents.
victims 30,000 customers
victims 1,500 customers
victims 2,770 organizations
victims 43 new victims
data_breach 89 GB
Tactical Metrics
Metrics
victims
30,000
Customers
Metrics
victims
1,500
Customers
Metrics
financial
10,000,000
Reward
Metrics
victims
2,770
Organizations
Metrics
victims
43
New Victims
Metrics
data_breach
89
Gb
Intelligence Sources
BleepingComputer 2026-08-17