Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

wifcfieldeffect+1channelnewsasiaThe Russia-linked ransomware group Cl0p has claimed responsibility for stealing large volumes of data from nearly 50 companies worldwide, including Shell , Philips Koninklijke Philips N.V. , Fiserv , and GE , according to a posting on the group's website first reported by Dutch media outlet BNR on Thursday, August 13.channelnewsasia+1
Reuters reported that it could not independently verify the group's claims regarding the type or volume of data stolen.channelnewsasia
Shell acknowledged awareness of a "possible incident" in a statement. "We are working with our security teams and relevant experts to investigate the situation," a Shell spokesperson said.channelnewsasia+1
Philips offered more detail: "Philips has identified and contained an attempted cybersecurity compromise of a specific enterprise server related to internal data," the company said, adding that the incident does not impact customer environments.wifc+1
A Fiserv spokesperson said the company is aware of the threat actor's claims but "based on our comprehensive review to date" had found no evidence that customer, banking, transaction, or personal data had been compromised, or that its operating environment had been affected. GE has not publicly commented.channelnewsasia+1
While the exact method of access has not been confirmed by any of the named victims, security researchers have linked Cl0p's campaign to exploitation of CVE-2026-12569, a critical vulnerability in PTC's Windchill and FlexPLM software used in engineering and manufacturing processes. The flaw, which carries a CVSS score of 9.3, allows unauthenticated remote code execution through deserialization of untrusted data.securityweek+1
CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on June 25 after confirming active exploitation. Ransom-ISAC issued a notice on July 22 warning that Cl0p was exploiting these vulnerabilities, and PTC has published advisories urging customers to patch affected systems.fieldeffect+3
Cl0p does not encrypt victims' files in the traditional ransomware model. Instead, the group quietly exfiltrates data and threatens to publish it on a leak site unless the victim pays — a tactic it refined during its 2023 campaign exploiting the MOVEit file-transfer vulnerability, which compromised hundreds of organizations. The current campaign follows the same logic: identify a widely deployed enterprise tool, exploit a single flaw, and harvest data from dozens of companies at once.cryptonomist+1
Whether Cl0p follows through on its threats to publish the stolen material will likely shape how urgently organizations still running unpatched Windchill systems respond in the weeks ahead.