started · updated
Clop ransomware gang targets Shell, GE, and Philips via PTC software flaws
The Clop ransomware gang has reportedly targeted approximately 43 companies by exploiting vulnerabilities in product lifecycle management (PLM) software provided by PTC. Major corporations, including Shell, GE, and Philips, have been identified as victims of these cyberattacks.
The attackers exploited a critical improper input validation vulnerability, tracked as CVE-2026-12569, affecting internet-connected PTC Windchill and FlexPLM software. Clop claimed to have stolen sensitive data, such as blueprints, diagrams, and project plans. While PTC began releasing security patches in mid-June, cybersecurity experts noted that attackers appeared to be exploiting these environments before public warnings and remediation processes were fully implemented.
Security analysts highlighted the difficulty of managing vulnerabilities in complex enterprise platforms, noting that large manufacturers often struggle to rapidly patch multiple versions and integrated systems across global operations. Philips stated that the breach did not impact its customer environments.