Cyber Incident Victim: Fiserv
Timeline
Summary
A hacking group known as Cl0p claimed to have stolen large volumes of data from dozens of companies worldwide, citing targets such as Philips, Shell, Fiserv, and GE. Fiserv stated it reviewed the claim and found no evidence that customer, banking, transaction, or personal data had been compromised or that its operating environment was affected. Philips said it contained an attempted compromise of an internal server, Shell noted it was assessing a possible incident, and GE said it had activated cyber response protocols to evaluate the claim. The group reportedly exploited vulnerabilities in PTC’s Windchill and FlexPLM software, focusing on zero‑day flaws rather than specific organizations.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 0 techniques |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
A hacking group identified as Cl0p posted a claim on its website on August 14 2026 stating that it had stolen large volumes of data from nearly fifty companies worldwide, naming Philips, Shell, Fiserv and GE among the victims. The post described the group as exploiting software vulnerabilities to attack multiple targets simultaneously, and it was accompanied by statements from the affected companies. Philips said it had been targeted by Cl0p and had identified and contained an attempted compromise of a specific enterprise server related to internal data, adding that the incident did not affect customer environments. Shell’s spokesperson said the company was aware of a possible incident and was working with its security teams and relevant experts to investigate the situation. A GE spokesperson said the company was aware of the claim and had initiated its cyber response protocols while working to assess the potential issue. The article noted that Reuters could not independently verify the hacking group’s claims about the type or amount of data taken, and the hackers did not respond to a request for comment. Ransom‑ISAC issued an advisory on July 22 2026 warning that the group was exploiting vulnerabilities in PTC Windchill and FlexPLM, software used for engineering and manufacturing processes, and PTC had previously issued multiple security notices dating to June 18 urging customers to apply a patch for a vulnerability and sharing details about an unnamed attacker targeting its products. Brandon Parsons, threat intelligence manager with Ascent Solutions and author of the Ransom‑ISAC advisory, said some companies began receiving notices from Cl0p on July 19 or July 20, that the group focuses on vulnerabilities in key software packages rather than specific companies, and that it describes itself as professional data extortionists that target a specific zero‑day vulnerability and go after it.

In response to the claim, a spokesperson for Fiserv said the company was aware of the threat actor’s allegations but, based on its comprehensive review to date, had found no evidence that customer, banking, transaction, or personal data had been compromised, nor that its operating environment had been affected. The spokesperson did not disclose further details about the scope or methodology of the review, nor did Fiserv report any disruption to its services or systems as a result of the alleged incident. The article provided no indication that Fiserv had detected any intrusion, issued any public advisory, or taken any containment measures beyond the internal review. No additional statements from Fiserv regarding ongoing monitoring, forensic analysis, or coordination with law enforcement were included in the source material.
The narrative presented in the source material reflects that, while the hacking group asserted a broad data theft campaign affecting multiple corporations, the only confirmed information concerning Fiserv is the company’s assertion that its review uncovered no evidence of data compromise or operational impact. Other companies mentioned in the article offered varying responses, with Philips reporting containment of an attempted compromise, Shell indicating an active investigation, and GE stating it had activated its cyber response protocols. The article concluded without further updates on any of the companies’ post‑incident statuses, leaving the factual record limited to the statements and advisories cited.
