CVE Tools

Philips and GE investigating Clop ransomware data theft claims

BleepingComputerBy Sergiu Gatlan

Reported exploitedPTC WindchillClopPTC FlexPLM

Our summary

General Electric, Philips, and Shell are currently investigating reports that the Clop ransomware group accessed their networks and exfiltrated data. These breaches stem from active exploitation of CVE-2026-12569, a critical input validation vulnerability affecting Internet-exposed instances of PTC Windchill and PTC FlexPLM. While Philips has stated its response contained the incident without impacting customer environments, GE is still assessing the scope of the potential compromise.

This campaign involves Clop deploying JSP webshells to steal sensitive assets such as blueprints and project plans from enterprises relying on these PLM platforms. As CISA has added this flaw to its Known Exploited Vulnerabilities catalog, organizations should apply available patches and audit their systems for signs of intrusion.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store