Cl0p Claims Data Theft From Nearly 50 Global Firms via Industrial Software Flaws
The hacking group exploited vulnerabilities in PTC Windchill and FlexPLM to target giants including Shell, Philips, and GE.
The prolific hacking group Cl0p has claimed to have stolen large volumes of data from nearly 50 companies worldwide, including Shell, Philips, GE, and Fiserv. The breach highlights a systemic vulnerability in specialized industrial software used by some of the world's largest enterprises.
According to reports from CNA, the group targeted vulnerabilities in PTC Windchill and FlexPLM software. Ransom-ISAC issued warnings around July 22 regarding Cl0p's exploitation of these specific tools. While the group claims widespread theft, some affected companies have reported limited impact. Philips stated it identified and contained a compromise of a specific enterprise server related to internal data, noting that customer environments were not impacted. Similarly, Fiserv reported that its internal review found no evidence that personal, banking, transaction, or customer data was compromised.
The Zero-Day Strategy
Cl0p is recognized by security experts as a "professional data extortionist" that prioritizes software vulnerabilities over specific corporate targets. Brandon Parsons, a threat intelligence manager with Ascent Solutions, noted that the group does not typically target a specific company, but rather targets a specific zero-day vulnerability and pursues it across all available targets. In this instance, the focus was on software critical to engineering and manufacturing processes. PTC had issued security notices in mid-June 2026 urging customers to patch the vulnerabilities before the mass exploitation occurred.
Systemic Supply-Chain Risks
This campaign underscores the acute risk associated with supply-chain vulnerabilities in specialized industrial software. By identifying a single flaw in a widely used package, Cl0p was able to simultaneously compromise dozens of global giants across diverse sectors, including energy, healthcare, finance, and manufacturing. The attack demonstrates how a failure to patch a single piece of enterprise software can create a cascading security failure across multiple industries, regardless of the individual company's internal security posture.
Ongoing Investigations
While some firms have contained the breach, others continue to investigate the full extent of the data theft. Security analysts are monitoring the group's extortion attempts to determine exactly what data was exfiltrated from the remaining targeted companies. The incident serves as a stark reminder for industrial firms to prioritize the patching of specialized engineering tools, which are often overlooked compared to standard IT infrastructure.