Cyber Incident Victim: Koninklijke Philips N.V.
Timeline
Summary
A hacking group known as Cl0p claimed to have stolen large volumes of data from dozens of companies worldwide, including Philips, Shell, Fiserv and GE, by exploiting vulnerabilities in PTC Windchill and FlexPLM software. Philips stated that it identified and contained an attempted compromise of an internal enterprise server and that customer environments were not affected, while Shell said it was aware of a possible incident and was investigating, Fiserv reported finding no evidence of compromised customer or transaction data, and GE said it had activated its cyber response protocols to assess the situation. The group’s claims could not be independently verified.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 0 techniques |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On August 14, 2026, a posting on the website of the hacking group Cl0p claimed that it had stolen large volumes of data from nearly 50 companies worldwide, including Philips, Shell, Fiserv, and GE. The group said the theft resulted from exploiting software vulnerabilities to attack multiple targets simultaneously. According to threat intelligence manager Brandon Parsons, some companies began receiving extortion notices from Cl0p on July 19 or July 20, 2026. On July 22, Ransom‑ISAC issued a warning that the group was exploiting vulnerabilities in PTC Windchill and FlexPLM, software used for engineering and manufacturing processes. PTC had previously issued security notices dating to June 18 urging customers to apply a patch for the vulnerability and detailing an unnamed attacker targeting its products.

Philips responded by stating that it had been targeted by Cl0p and that it had identified and contained an attempted cybersecurity compromise of a specific enterprise server related to internal data, emphasizing that the incident did not affect customer environments. Shell said it was aware of a recent possible incident, confirming an earlier report by Dutch media outlet BNR, and noted that it was working with its security teams and relevant experts to investigate the situation. Fiserv indicated that it was aware of the threat actor's claims but, based on its comprehensive review to date, had found no evidence that customer, banking, transaction, or personal data had been compromised, nor that its operating environment had been affected. GE said it was aware of the claim and had initiated its cyber response protocols while working to assess the potential issue.
Reuters could not independently verify the hacking group's assertions regarding the type or volume of data allegedly stolen, and the group did not respond to a request for comment. The article notes that it remains unclear how the attackers allegedly gained access to the companies, but it highlights that Cl0p focuses on vulnerabilities in key software packages rather than specific companies, describing them as professional data extortionists. Brandon Parsons explained that the group targets previously unknown zero‑day vulnerabilities for which vendors have not yet issued patches, moving from one victim to another once a flaw is exploited.
