A series of prominent organisations including UK fossil fuel giant Shell, Dutch consumer and health tech multinational Philips, and the US’ General Electric (GE), are probing security breaches after being ‘named and shamed’ by the Cl0p/Clop cyber extortion gang.
Cl0p, which has a long history of targeting blue chip firms by compromising commonly used enterprise platforms, named all three organisations among close to 50 others in an update to its dark web leak site.
All of the victims appear to have been compromised via a critical zero-day flaw in PTC’s Windchill PDMLink and FlexPLM product lifecycle management software packages, tracked as CVE-2026-12569.
Identified and patched in June and added to Cisa’s Known Exploited Vulnerabilities (Kev) catalogue shortly thereafter, the flaw becomes exploitable by chaining a pre-authentication information disclosure issue in the FlexPLM WSDL endpoint with a server-side issue in Windchill’s login servlet.
Ultimately, according to members of the Ransom-ISAC anti-ransomware community, these conditions enabled the threat actors to deploy webshells, achieve unauthenticated remote code execution (RCE), and exfiltrate their victims’ data.
Ransom-ISAC’s Brandon Parsons wrote that Cl0p’s campaign seems to have begun on or around 20 July, when the gang starting emailing multiple users at the affected organisations from randomly compromised accounts.
Parsons observed: “This extortion approach is consistent with what we observed with the Oracle EBS campaign last year, except for the use of new email addresses.”
In statements shared with the media, Shell, Philips and GE all confirmed they were in the process of investigating the claims, but none of them named the Cl0p operation specifically.
Shell told Reuters it was “working with security teams and relevant experts” on its investigation, while GE said it had “initiated our cyber response protocols and are working to assess the potential issue”.
A spokesperson for Philips went further, saying: “Philips has identified and contained an attempted cyber security compromise of a specific enterprise server related to internal data.”
According to Cl0p’s unverified claims, the gang has stolen 89GB of data from Shell, 15.5GB from Philips, and 391GB from GE. In Shell’s case this information allegedly includes engineering drawings, photos of oil facilities, scans of test projects and other project plans.
Cl0p’s tactics work
As Ransom-ISAC’s analysts observed, Cl0p’s activity in this latest wave of breaches strongly echoes previous campaigns conducted by the gang, targeting the likes of Acellion, Oracle, and perhaps most famously Progress Software.
Three years on from its infamous attack on Progress’ MOVEit file transfer tool, which hit thousands of companies, Cl0p still cleaves to its simple and highly effective ‘business’ model, foregoing traditional encryption ransomware in favour of compromising widely-used software products to target multiple downstream customers, stealing their data, and exposing it if not paid.
CybaVerse chief technology officer (CTO) Simon Phillips said the developing incident had the potential to be another huge data breach along the lines of Cl0p’s previous attacks.
“Given Cl0p’s reputation of launching mass attacks, all organisations showing on the leak site must take steps to investigate these claims. They must monitor for unauthorised access and identify if any data has been exfiltrated from their systems,” he said.
“Furthermore, any organisation using either PTC Windchill PDMlink or PTC FlexPLM should apply the patches as a priority.”
Phillips added: “[A] key question this raises is around vulnerabilities in software, and customer organisations continuing to face the financial repercussions when they are exploited by attackers.
“As an industry, we need to rethink how we evaluate security and vendors, looking beyond individual vulnerabilities and identifying broader trends. Vendors with recurring vulnerabilities in critical components, such as those found in internet-facing infrastructure, should be flagged as high-risk.”

