Cl0p, a hacking group, said on August 13 that it stole large volumes of data from nearly 50 companies globally, including Philips, Shell, Fiserv, and General Electric (GE) [1, 2, 3].
The cyberattacks exploit vulnerabilities in enterprise software such as PTC Windchill and FlexPLM, allowing Cl0p to target multiple companies simultaneously. Ransom-ISAC issued an advisory on July 22 warning about these exploits [1]. Threat intelligence manager Brandon Parsons of Ascent Solutions explained, "They don’t really target a specific company, they target a specific zero day vulnerability and go after it" [1].
Some companies first received notices from Cl0p about the attacks around July 19 or 20 [1]. Philips confirmed it identified and contained an attempted cybersecurity compromise on a specific internal enterprise server but said customer environments were not affected. Philips stated, "This incident does not impact customer environments" [1, 2, 3].
Shell acknowledged a "possible incident" and said, "We are working with our security teams and relevant experts to investigate the situation" [1, 2, 3]. Fiserv said it is aware of Cl0p’s claims but found no evidence that customer, banking, transaction, or personal data was compromised following a comprehensive review. The company said, "We have found no evidence that customer, banking, transaction or personal data has been compromised, or that our operating environment has been affected" [1, 2, 3].
GE confirmed its awareness of the claim and said it has activated cyber response protocols while assessing the potential issue. A GE spokesperson said, "We have initiated our cyber response protocols and are working to assess the potential issue" [1, 2, 3].
Reuters and other news agencies have not independently verified the extent or kind of data stolen by Cl0p [1, 2, 3].
The affected companies continue investigations into the incidents. Security experts are monitoring any further exploitation of the PTC software vulnerabilities Cl0p exploits. Ransom-ISAC’s July 22 advisory remains a key alert for organizations using the affected applications [1].