Koninklijke Philips N.V.
Incident posture
Linked entities
- Victim
- Koninklijke Philips N.V.
- Threat actors
- 2 actors
- Sources
- 3 sources
Timeline
Summary
The Clop ransomware group exploited a zero‑day vulnerability in PTC’s Windchill and FlexPLM platforms, gaining unauthorized access to internal systems of multiple organizations, including Philips. The company reported that it identified and contained an attempted compromise of an enterprise server containing internal data and stated that customer environments were unaffected. The attackers used a custom web shell to steal credentials and exfiltrate files ranging from gigabytes to terabytes, including engineering documents, backups and other corporate data. Other named victims said they were investigating the claims and had found no evidence of customer or operational data breach. PTC issued a patch and added the flaw to a known exploited vulnerabilities catalog after the attacks were discovered.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
The vulnerability tracked as CVE-2026-12569 affecting PTC’s Windchill and FlexPLM platforms was disclosed by PTC on June 17 2026, with a patch and initial indicators of compromise released the following day. The Cybersecurity and Infrastructure Security Agency added the flaw to its known exploited vulnerabilities catalog on June 25. Researchers noted that exploitation likely began in early June, before the patch was available, and that the Clop ransomware group started sending threatening emails to alleged victims in mid‑July. By July 19‑20 companies began receiving notices from Clop, and on August 12 the group began publishing full names of alleged victims on its website, including Koninklijke Philips N.V. among the more than 40 organizations named.
Philips responded to the allegations by stating that it had identified and contained an attempted cybersecurity compromise of a specific enterprise server related to internal data, emphasizing that the incident did not impact customer environments. The company said it was working with its security teams and relevant experts to investigate the situation and that, based on its review to date, it had found no evidence of a significant data breach. Philips confirmed it was aware of the claims made by Clop but did not provide further details about the nature or scope of the attempted compromise.
Clop’s public statements described the stolen information per victim as ranging from 1 GB to several terabytes and listed the types of data as databases, project files, backups, photographs, engineering documents, blueprints, diagrams, logs and other corporate documents. The group noted that it had exploited the Windchill vulnerability to deploy a custom web shell that enabled credential theft, data exfiltration and sustained access within affected systems. While other named victims such as Shell, Fiserv and GE acknowledged the claims and said they were investigating, none had confirmed a significant breach at the time of the reports. The narrative remains limited to the facts disclosed by the involved parties and the public statements of the ransomware group.
Sources
Sources available to members: 3 sources.