Back Technadu Shell and Philips Confirm Investigation as Cl0p Claimed Data Theft
Shell and Philips confirmed they were targeted in attacks reportedly orchestrated by the prolific hacking group Cl0p, known for exploiting software vulnerabilities to attack multiple targets simultaneously. Cl0p claimed it exfiltrated 13.5 GB of PDF drawings, diagrams, and blueprints from Philips, and 89 GB of engineering drawings, photos of the facilities, scans of facility testing reports, and project plans from Shell.
The attackers said last month that they had targeted nearly 50 companies worldwide, including Philips, Shell, Fiserv, GE, and Mammut.
Philips said it had been targeted by the Cl0p ransomware group, stating it " has identified and contained an attempted cybersecurity compromise of a specific enterprise server related to internal data ," according to Reuters.
“ Philips has identified and brought this attempted cyberattack on a specific corporate server containing internal data under control, ” a spokesperson told Dutch media outlet BNR on Thursday, adding that the incident does not impact customer environments.
Shell said it was aware of a recent "possible incident," Reuters added. " We are working with our security teams and relevant experts to investigate the situation ," a Shell spokesperson said.
A Fiserv spokesperson said the company is aware of the claims but found no evidence that customer, banking, transaction, or personal data had been compromised. A GE spokesperson said it had " initiated our cyber response protocols” and is “working to assess the potential issue ." Reuters could not independently verify the group's claims.
According to a coordinated advisory from Ransom-ISAC, eCrime.ch, and DEFUSED, issued on July 22, Cl0p was exploiting vulnerabilities in PTC Windchill and FlexPLM, software used to aid engineering and manufacturing processes.
The specific flaw, tracked as CVE-2026-12569 , is a critical unsafe deserialization vulnerability carrying a CVSS severity score of 9.3. Attackers chain a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a separate flaw in the Windchill login servlet, achieving unauthenticated remote code execution.
Once inside, attackers plant hex-named JSP web shells, enumerate the file system, and stage engineering and design data before mass-emailing extortion demands to hundreds of employees at each targeted company. Boston-based PTC has issued multiple security notices dating to June 18, urging customers to apply a patch.
Brandon Parsons, threat intelligence manager with Ascent Solutions and author of the Ransom-ISAC advisory, said some companies began receiving notices from Cl0p on July 19 or July 20. He called the group "professional data extortionists," adding, " They don't really target a specific company, they target a specific zero-day vulnerability and go after it ."
This campaign closely mirrors Cl0p's mass exploitation of Oracle E-Business Suite (EBS) the year prior. Parsons drew the comparison directly, noting that the extortion approach is " consistent with what we observed with the Oracle EBS campaign last year, except for the use of new email addresses .”
The Russian group, also tracked under the aliases Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest, has built a long track record of weaponizing flaws in widely-used enterprise software to strike many organizations at once, including prior campaigns against Accellion FTA, GoAnywhere MFT, SolarWinds , MOVEit Transfer , and Cleo .
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
