Cl0p Cyberattack: List of Companies Affected Includes Philips, Shell, Fiserv and GE

Cl0p claims it stole large volumes of data from nearly 50 companies, naming Philips, Shell, Fiserv and GE. The companies are investigating the claims, with Philips confirming an attempted compromise and Fiserv reporting no evidence of affected customer or banking data. The campaign has been linked to vulnerabilities in PTC Windchill and FlexPLM software.

Representative image (Photo Credit: Pixabay)

A prolific hacking group known for exploiting software vulnerabilities to attack multiple targets simultaneously claimed it had stolen large volumes of data from nearly 50 companies worldwide, including Philips, Shell, Fiserv, and GE, according to a posting on the group's website. Philips said it had been targeted by Cl0p while Shell said it was aware of a recent "possible incident", confirming an earlier report on Thursday, August 13, by Dutch media outlet BNR.

"We are working with our security teams and relevant experts to investigate the situation," a Shell spokesperson said. "Philips has identified and contained an attempted cybersecurity compromise of a specific enterprise server related to internal data," Philips said in a statement, adding that the incident does not impact customer environments. Framework Computer Data Breach: US-Based PC Brand Warns Users After Metabase Zero-Day Exploit Exposes Personal Details.

Companies Assess Claims

A spokesperson for Fiserv said the company is aware of the threat actor's claims, but "based on our comprehensive review to date", it had found no evidence that customer, banking, transaction or personal data had been compromised, or that its operating environment had been affected.

A GE spokesperson said the company is aware of the claim, and had "initiated our cyber response protocols and are working to assess the potential issue." Reuters could not independently verify the hacking group’s claims regarding the kind of data it stole and how much. The hackers did not respond to a request for comment. Bank of Baroda Clarifies Security Incident After Alleged 1TB Data Leak Claims on Dark Web.

The differing responses underscore that an appearance on Cl0p's extortion site does not, by itself, establish the scope or impact of an intrusion. The affected companies are still assessing whether data was accessed or removed.

PTC Software Vulnerability Linked to Campaign

While it’s not clear how the hackers allegedly accessed the companies, Ransom-ISAC, an industry information sharing group, issued a notice July 22 warning that the hacking group was exploiting vulnerabilities in PTC Windchill and FlexPLM, software used to aid in engineering and manufacturing processes.

PTC has identified CVE-2026-12569 as a critical vulnerability in Windchill and FlexPLM that could allow an unauthorized user to execute code remotely. PTC's security advisory says customers should apply the available patches immediately and scan their environments for indicators of compromise. The company has continued updating its advisory with new indicators and remediation guidance.

Boston-based PTC did not immediately respond to a request for comment. The company has issued multiple security notices to its website, dating to June 18, urging customers to apply a patch for a vulnerability and sharing details about an unnamed attacker attacking its products.

PTC's June 18 advisory warned customers to review their environments for indicators of compromise, including persistent JSP webshells in the Windchill login directory that could enable remote command execution and possible data exfiltration.

Cl0p Focuses on Vulnerabilities

Brandon Parsons, threat intelligence manager with Ascent Solutions and the author of the Ransom-ISAC advisory, said some companies began receiving notices from Cl0p on July 19 or July 20. The group focuses on vulnerabilities in key software packages rather than specific companies, he said, calling them “professional data extortionists.”

“They don’t really target a specific company, they target a specific zero day vulnerability and go after it,” Parsons said, referring to previously unknown bugs that software vendors haven’t yet issued patches for.

Ransom-ISAC's advisory describes active Cl0p exploitation of internet-exposed PTC Windchill and FlexPLM deployments, including the use of webshells and data theft.

The latest developments leave the extent of any compromise at the named companies unresolved. Philips has said it contained an attempted compromise and that customer environments were not affected, while Fiserv said its review had found no evidence of compromised customer, banking, transaction or personal data. Shell and GE are continuing their investigations.

The incident also highlights the broader risk posed by vulnerabilities in widely deployed enterprise software. PTC's latest security updates urge customers to implement patches and monitor for indicators of compromise as investigations into exploitation continue.

Rating:3

TruLY Score 3 – Believable; Needs Further Research | On a Trust Scale of 0-5 this article has scored 3 on LatestLY, this article appears believable but may need additional verification. It is based on reporting from news websites or verified journalists (Reuters), but lacks supporting official confirmation. Readers are advised to treat the information as credible but continue to follow up for updates or confirmations

(The above story first appeared on LatestLY on Aug 14, 2026 03:21 PM IST. For more news and updates on politics, world, sports, entertainment and lifestyle, log on to our website latestly.com).

Share Now

Share Now