
General Electric and Philips have confirmed they are investigating claims that the Clop ransomware gang breached their systems and stole corporate data. A GE spokesperson said the company is “working to assess the potential issue,” while Philips confirmed the breach itself but said the incident has been contained and has no impact on customer environments. Clop added both companies to its data-leak site as part of a wave of 43 newly listed victims.
Both companies are named alongside oil giant Shell — which separately disclosed a breach last Friday — in attacks exploiting CVE-2026-12569, a critical improper input validation flaw in PTC’s Windchill and FlexPLM product lifecycle management platforms. Clop claims to have stolen extensive data from each company, including backups, project plans, facility photos, engineering drawings, and blueprints. CISA added CVE-2026-12569 to its Known Exploited Vulnerabilities catalog, and Germany’s BSI issued an emergency overnight advisory urging PTC customers to patch immediately. The U.S. Department of State is now offering a $10 million reward for information linking Clop’s attacks to a foreign government.
