CSIDB logo
Incident

General Electric

Incident posture

Attack window
Jun 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-09 00:42

Linked entities

Victim
General Electric
Threat actors
2 actors
Sources
3 sources

Timeline

Occurred
Jun 2026
Discovered
Jun 2026
Disclosed
Aug 2026
Resolved
Pending

Summary

The Clop ransomware group exploited a zero‑day flaw in PTC’s Windchill and FlexPLM platforms, gaining unauthorized access to the networks of dozens of companies that rely on the software for product lifecycle management. Among the organizations named by the attackers were Philips, Shell, Fiserv and GE, with the hackers claiming to have taken databases, engineering documents and other files ranging from one gigabyte to several terabytes per victim. One of the listed firms said it was aware of the claim and had activated its cyber response protocols while noting that it was investigating the allegations. Other victims reported that they had detected and contained the intrusion or found no evidence of customer data being compromised, and the attackers continued to use a custom web shell to steal credentials and move laterally inside compromised systems.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

The vulnerability tracked as CVE-2026-12569 affecting PTC’s Windchill and FlexPLM platforms was disclosed by PTC on June 17, 2026, with a patch issued the following day, and the flaw was added to CISA’s known exploited vulnerabilities catalog on June 25. Researchers indicate that the zero‑day was likely exploited in early June, before the patch was available, and that the Clop ransomware group began sending threatening emails to alleged victims in mid‑July. Clop’s campaign targeted dozens of organizations using the compromised PLM software, and the group claimed to have stolen data from entities including General Electric, Philips, and Shell. General Electric was initially named among the alleged victims on the group’s leak site.

On August 12, 2026, Clop began publishing the full names of targeted organizations, and General Electric appeared on that list before later being removed; the reporting noted that the removal could indicate that the company had agreed to pay a ransom or had resumed negotiations with the hackers. A GE spokesperson confirmed that the company was aware of the claim, had initiated its cyber response protocols, and was working to assess the potential issue, while stating that no significant data breach had been confirmed. Other companies such as Shell, Philips, and Fiserv similarly acknowledged the claims and said they were investigating, but none had verified a substantial compromise of customer or operational data.

Clop employed a custom web shell designed for Windchill that decrypted credentials, delivered malware, and provided capabilities for credential theft, network traversal, and persistent access, enabling the exfiltration of databases, project files, backups, photographs, engineering documents, blueprints, diagrams, logs, and other corporate files. The group reported that the amount of stolen data per victim ranged from one gigabyte to several terabytes, and the compromised material could contain sensitive personal information and intellectual property. The campaign added to Clop’s history of mass‑exploitation efforts, which previously included zero‑day attacks on Oracle E‑Business Suite, MOVEit, Cleo, and GoAnywhere, affecting thousands of organizations across multiple years.

Sources

Sources available to members: 3 sources.

CSIDB