General Electric
Incident posture
Linked entities
- Victim
- General Electric
- Threat actors
- 2 actors
- Sources
- 3 sources
Timeline
Summary
The Clop ransomware group exploited a zero‑day flaw in PTC’s Windchill and FlexPLM platforms, gaining unauthorized access to the networks of dozens of companies that rely on the software for product lifecycle management. Among the organizations named by the attackers were Philips, Shell, Fiserv and GE, with the hackers claiming to have taken databases, engineering documents and other files ranging from one gigabyte to several terabytes per victim. One of the listed firms said it was aware of the claim and had activated its cyber response protocols while noting that it was investigating the allegations. Other victims reported that they had detected and contained the intrusion or found no evidence of customer data being compromised, and the attackers continued to use a custom web shell to steal credentials and move laterally inside compromised systems.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
The vulnerability tracked as CVE-2026-12569 affecting PTC’s Windchill and FlexPLM platforms was disclosed by PTC on June 17, 2026, with a patch issued the following day, and the flaw was added to CISA’s known exploited vulnerabilities catalog on June 25. Researchers indicate that the zero‑day was likely exploited in early June, before the patch was available, and that the Clop ransomware group began sending threatening emails to alleged victims in mid‑July. Clop’s campaign targeted dozens of organizations using the compromised PLM software, and the group claimed to have stolen data from entities including General Electric, Philips, and Shell. General Electric was initially named among the alleged victims on the group’s leak site.
On August 12, 2026, Clop began publishing the full names of targeted organizations, and General Electric appeared on that list before later being removed; the reporting noted that the removal could indicate that the company had agreed to pay a ransom or had resumed negotiations with the hackers. A GE spokesperson confirmed that the company was aware of the claim, had initiated its cyber response protocols, and was working to assess the potential issue, while stating that no significant data breach had been confirmed. Other companies such as Shell, Philips, and Fiserv similarly acknowledged the claims and said they were investigating, but none had verified a substantial compromise of customer or operational data.
Clop employed a custom web shell designed for Windchill that decrypted credentials, delivered malware, and provided capabilities for credential theft, network traversal, and persistent access, enabling the exfiltration of databases, project files, backups, photographs, engineering documents, blueprints, diagrams, logs, and other corporate files. The group reported that the amount of stolen data per victim ranged from one gigabyte to several terabytes, and the compromised material could contain sensitive personal information and intellectual property. The campaign added to Clop’s history of mass‑exploitation efforts, which previously included zero‑day attacks on Oracle E‑Business Suite, MOVEit, Cleo, and GoAnywhere, affecting thousands of organizations across multiple years.
Sources
Sources available to members: 3 sources.