General Electric and Philips are investigating cybersecurity incidents after the Clop extortion group claimed to have stolen information from their systems. Both companies were recently added to Clop’s leak site as part of a larger campaign involving dozens of organizations.
GE confirmed that it is aware of the group’s claim and is assessing the potential security issue. The company has not confirmed whether Clop successfully obtained information or disclosed what systems may have been affected.
Philips has confirmed that an intrusion occurred but described its scope more narrowly. The company identified and contained an attempted compromise involving a specific enterprise server associated with internal data. Philips said customer environments were not affected by the incident.
Clop claims it obtained sensitive corporate information from GE and Philips, including project materials, backups, engineering drawings, diagrams, blueprints and other internal files. However, the precise contents and volume of the allegedly stolen information have not been independently confirmed.
The incidents appear connected to a broader Clop campaign targeting internet-exposed instances of PTC Windchill and FlexPLM. Oil company Shell is another organization investigating a potential incident after Clop claimed to have stolen 89GB of its data.
At the center of the campaign is CVE-2026-12569, a critical vulnerability affecting PTC Windchill and FlexPLM. The enterprise platforms are used to manage product information and development processes across industries including aerospace, defense, automotive, manufacturing, retail and medical technology.
PTC began releasing security updates addressing CVE-2026-12569 in June. The company subsequently warned customers about heightened threat activity and urged organizations to apply available fixes and examine their environments for indicators of compromise. PTC security advisory
Attackers targeting vulnerable installations have been observed deploying JSP webshells. Once established on a compromised server, these tools can provide persistent remote access and facilitate the theft of information stored within affected environments.
The US Cybersecurity and Infrastructure Security Agency (CISA) has also identified CVE-2026-12569 as an actively exploited vulnerability and added it to its Known Exploited Vulnerabilities catalog, increasing the urgency for organizations still operating exposed and unpatched installations.
Clop has previously concentrated on enterprise software that can provide opportunities to compromise numerous organizations through a common vulnerability. Its previous campaigns have targeted platforms including MOVEit Transfer, GoAnywhere MFT, Cleo and Oracle E-Business Suite.
The exact impact on GE and Philips remains under investigation. Philips has confirmed and contained an intrusion involving an internal server while stating that customers were unaffected. GE, meanwhile, has acknowledged Clop’s allegation but has not confirmed a breach or data theft. Clop’s specific claims regarding the information allegedly stolen from both companies therefore remain unverified.
