Menu
Browse

Cyber Incident Victim: General Electric

Date

Jul 2026

Location

United States of America

Status

Ongoing

Updated

2026-08-14 16:36

Timeline
Occurred
Undetermined
Discovered
Undetermined
Disclosed
Aug 2026
Resolved
Pending
Summary

A hacking group known as Cl0p claimed to have stolen large volumes of data from dozens of companies worldwide, including GE, Philips, Shell and Fiserv, by exploiting zero‑day vulnerabilities in PTC Windchill and FlexPLM software. GE said it had been alerted to the claim, initiated its cyber response protocols and was working to assess the potential issue, while Philips reported it had contained an attempted compromise of an internal server, Shell said it was aware of a possible incident and was investigating, and Fiserv stated its review found no evidence that customer or transaction data had been affected. The group’s assertions could not be independently verified.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On June 18, PTC posted security notices on its website urging customers to apply a patch for a vulnerability in its Windchill and FlexPLM products and sharing details about an unnamed attacker targeting those products. On July 19 or July 20, the hacking group known as Cl0p began sending notices to multiple companies, claiming responsibility for exploiting a zero‑day vulnerability in the PTC software. The group’s messages asserted that it had stolen large volumes of data from dozens of organizations worldwide. On July 22, Ransom‑ISAC issued an advisory warning that Cl0p was actively exploiting vulnerabilities in PTC Windchill and FlexPLM, software used to support engineering and manufacturing processes. The advisory noted that the attacker was focusing on the vulnerability rather than specific targets. By August 14, a posting on the group’s website claimed that it had stolen data from nearly 50 companies, including Philips, Shell, Fiserv, and General Electric. Reuters could not independently verify the hacking group’s claims regarding the type or amount of data taken, and the group did not respond to a request for comment.

Cyber Incident Image

Philips stated that it had identified and contained an attempted cybersecurity compromise of a specific enterprise server related to internal data, emphasizing that the incident did not affect customer environments. Shell said it was aware of a recent "possible incident" and was working with its security teams and relevant experts to investigate the situation. Fiserv reported that, based on a comprehensive review to date, it had found no evidence that customer, banking, transaction, or personal data had been compromised, nor that its operating environment had been affected. A GE spokesperson said the company was aware of the claim and had initiated its cyber response protocols while working to assess the potential issue. PTC had previously issued multiple security notices dating to June 18, urging customers to apply a patch for the vulnerability and providing information about the unnamed attacker. Brandon Parsons, threat intelligence manager with Ascent Solutions and author of the Ransom‑ISAC advisory, noted that some companies began receiving notices from Cl0p on July 19 or July 20 and described the group as focusing on zero‑day vulnerabilities in key software packages rather than targeting specific organizations.

Sources
Sources available to members
1 source