< Back to situations

Monitor this situation.

[SITUATION] · [ACTIVE] · [TECHNOLOGY]

2 clusters · 21 sources · 1 days · First seen · Last updated

Cl0p ransomware attacks on global corporations

Overview

The Cl0p ransomware group has claimed responsibility for targeting approximately 50 major international corporations, including Shell, Philips, General Electric, and Fiserv. The group alleges the theft of significant volumes of sensitive data, such as engineering drawings, blueprints, and project plans.

The attacks exploited a critical vulnerability in PTC software, specifically affecting PTC Windchill and FlexPLM systems. The vulnerability, identified as CVE-2026-12569, carries a CVSS score of 9.8 and allows for unauthorized remote code execution. While PTC released patches in June 2026, Cl0p reportedly distributed extortion emails in mid-July.

As of mid-August, Cl0p has provided specific claims regarding the volume of exfiltrated data. The group alleges it stole approximately 89 gigabytes of data from Shell, including facility photos and project plans, and roughly 13.5 gigabytes from Philips, including technical diagrams.

Corporate responses have varied: Shell acknowledged a “possible incident” and is investigating the matter alongside security experts, while Philips confirmed it identified and contained an attempted compromise of an enterprise server containing internal data, stating the incident did not affect customer environments. Fiserv and GE have indicated they are aware of the claims and are conducting reviews or implementing response protocols; Fiserv reported finding no evidence of compromised customer or personal data. Independent verification of the stolen data volumes and contents has not yet been established.

Entities

Shell · Philips · Cl0p · GE Aerospace · PTC

Claims

What the coverage asserts, and how well corroborated each claim is across sources.

Timeline

  1. 1 day ago

    [TECHNOLOGY] 2 sources
    Cl0p ransomware targets 50 companies via PTC Windchill vulnerability

    The Cl0p ransomware group exploited a critical vulnerability (CVE-2026-12569) in PTC Windchill software to target nearly 50 major companies, including Shell, GE, and Philips.

  2. 1 day ago

    [TECHNOLOGY] 20 sources
    Cl0p hacking group claims mass data theft from Shell and Philips

    The Cl0p hacking group claims to have stolen massive amounts of data from nearly 50 companies, including Shell and Philips, following a widespread cyberattack targeting software vulnerabilities.

Sources

1-a1072.azureedge.net · atgs.ch · atomicbird.com · bizcommunity.com · datafloq.com · drweb.de · investegate.co.uk · m.fakt.pl · malatyaguncel.com · midan.net · mix929.com · nationalcybersecurity.com · petel.bg · razydzisiaj.pl · rmf24.pl · tunisiaonlinenews.com · wixx.com · wkzo.com · wtvbam.com · wxerfm.com · zataz.com

This summary has been updated 1 time: see revision history