# Cl0p ransomware attacks on global corporations

> Live situation record from CLSTR: https://clstr.news/situations/cl0p-ransomware-attacks-on-global-corporations
> Updated: 2026-08-13T23:14:14.000Z. Sources: 21. Developments: 2.

The Cl0p ransomware group has claimed responsibility for targeting approximately 50 major international corporations, including Shell, Philips, General Electric, and Fiserv. The group alleges the theft of significant volumes of sensitive data, such as engineering drawings, blueprints, and project plans.

The attacks exploited a critical vulnerability in PTC software, specifically affecting PTC Windchill and FlexPLM systems. The vulnerability, identified as CVE-2026-12569, carries a CVSS score of 9.8 and allows for unauthorized remote code execution. While PTC released patches in June 2026, Cl0p reportedly distributed extortion emails in mid-July.

As of mid-August, Cl0p has provided specific claims regarding the volume of exfiltrated data. The group alleges it stole approximately 89 gigabytes of data from Shell, including facility photos and project plans, and roughly 13.5 gigabytes from Philips, including technical diagrams. 

Corporate responses have varied: Shell acknowledged a “possible incident” and is investigating the matter alongside security experts, while Philips confirmed it identified and contained an attempted compromise of an enterprise server containing internal data, stating the incident did not affect customer environments. Fiserv and GE have indicated they are aware of the claims and are conducting reviews or implementing response protocols; Fiserv reported finding no evidence of compromised customer or personal data. Independent verification of the stolen data volumes and contents has not yet been established.

## Claims

- Philips identified and contained an attempted compromise of an enterprise server containing internal data. (corroborated by 14 sources)
- The cybersecurity incident at Philips does not affect customer environments. (corroborated by 14 sources)
- Shell is aware of a possible recent security incident and is investigating with security teams. (corroborated by 14 sources)
- Cl0p claims to have stolen approximately 89 gigabytes of data from Shell, including engineering drawings and project plans. (corroborated by 14 sources)
- Cl0p claims to have stolen approximately 13.5 gigabytes of data from Philips, including blueprints and diagrams. (corroborated by 14 sources)
- The hacking group Cl0p targeted Philips and Shell. (corroborated by 11 sources)
- The Cl0p hacking group claims to have targeted nearly 50 companies globally. (corroborated by 5 sources)
- Fiserv reported finding no evidence of compromised customer, banking, or personal data. (corroborated by 4 sources)
- The group may be exploiting vulnerabilities in PTC Windchill and FlexPLM software. (corroborated by 3 sources)

## Timeline

### 2026-08-13: Cl0p ransomware targets 50 companies via PTC Windchill vulnerability

The Cl0p ransomware group exploited a critical vulnerability (CVE-2026-12569) in PTC Windchill software to target nearly 50 major companies, including Shell, GE, and Philips.

2 sources. https://clstr.news/cluster/cl0p-ransomware-targets-50-companies-via-ptc-windchill-vulnerability

### 2026-08-13: Cl0p hacking group claims mass data theft from Shell and Philips

The Cl0p hacking group claims to have stolen massive amounts of data from nearly 50 companies, including Shell and Philips, following a widespread cyberattack targeting software vulnerabilities.

20 sources. https://clstr.news/cluster/philips-and-shell-targeted-by-cl0p-hacking-group

---
Cite as: Cl0p ransomware attacks on global corporations. CLSTR, https://clstr.news/situations/cl0p-ransomware-attacks-on-global-corporations
