The Clop ransomware PTC Windchill attacks have drawn in three more household names: General Electric, Philips, and Shell have all confirmed they are investigating claims by the Clop gang that it breached their systems and made off with sensitive data. The three companies join a batch of 43 newly listed victims on Clop’s leak site, all apparently caught by the same critical vulnerability in PTC’s enterprise software platforms.
What GE, Philips and Shell Have Said So Far
The responses from the three companies range from cautious to slightly more forthcoming. A GE spokesperson said the company is aware of the claim and is ‘working to assess the potential issue,’ without elaborating. Shell has taken a similar line, with a spokesperson confirming awareness of ‘a potential incident’ and saying the company is ‘working with our security teams and relevant experts to investigate.’ Shell’s admission follows the gang’s claim that it lifted 89GB of data from the oil company’s systems.
Philips has gone a step further. The company confirmed in a statement shared with Reuters that it ‘identified and contained an attempted cybersecurity compromise of a specific enterprise server related to internal data,’ adding that the incident ‘has no impact on customer environments.’ Containment is not the same as clean bill of health, but it is at least further along than where GE and Shell currently sit.
Clop claims the haul from all three companies includes backups, project plans, photos of facilities, drawings, diagrams, and blueprints. Whether any of that ends up published on the gang’s leak site depends on whether ransom negotiations go anywhere.
The CVE at the Centre of the Clop Ransomware PTC Windchill Attacks
The common thread running through all 43 alleged victims is CVE-2026-12569, a critical improper input validation vulnerability in PTC’s Windchill and FlexPLM platforms. Penligent rates the flaw at a CVSS v3.1 score of 9.8 out of 10, placing it firmly in the ‘patch immediately’ category. According to Fidelis Security, the vulnerability affects releases prior to Windchill and FlexPLM 11.0 M030, including all CPS versions, meaning organisations running anything older than that threshold were exposed.
PTC began releasing patches for the flaw on 17 June and issued a private advisory urging customers to check their environments for indicators of compromise, even before confirmed in-the-wild exploitation was reported. Exploitation did, of course, follow. By 26 June, CISA had confirmed active exploitation and added CVE-2026-12569 to its Known Exploited Vulnerabilities catalogue, mandating federal agencies to secure their PTC instances within three days. German authorities moved at a similarly sharp pace, with the Federal Office for Information Security (BSI) issuing a middle-of-the-night warning to PTC customers to patch as quickly as possible.
In the attacks themselves, Clop has been deploying JSP webshells to steal data from compromised PLM platforms. Cybersecurity company ReliaQuest and the Ransomware Information Sharing and Analysis Centre (Ransom-ISAC) have both confirmed this technique. PTC’s platforms are used across aerospace, defence, automotive, heavy machinery, retail, and medtech, with more than 30,000 customers globally. The FlexPLM product alone counts over 1,500 brand and retail customers.
Clop’s Well-Worn Playbook
None of this should surprise anyone who has been paying attention. Clop has built its reputation on finding a single critical vulnerability in a widely deployed enterprise platform and then working through the victim list methodically. Previous campaigns have hit Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer. The MOVEit campaign alone affected more than 2,770 organisations worldwide, a number that illustrates how much damage a single well-chosen flaw can cause when the target software is ubiquitous.
Starting in early August 2025, the gang also began exploiting an Oracle EBS zero-day to steal files from a further set of organisations. The victim list across Clop’s various campaigns has at times read like a who’s-who of global institutions: The Washington Post, Harvard University, the University of Pennsylvania, Logitech, Estée Lauder, Korean Air, and Envoy Air, among others.
The US Department of State now offers a $10 million reward for information linking Clop’s attacks to a foreign government. Organisations still running Windchill or FlexPLM versions older than 11.0 M030 should treat that patch as overdue rather than optional: CISA’s catalogue entry means the exploitation timeline is documented, and Clop’s leak-site clock is already ticking for 43 named victims.

