GE, Philips and Shell Suffer Cybersecurity Breaches

The Clop ransomware gang claims responsibility for all three attacks…and forty others.

Key Highlights

  • GE, Philips, Shell and purportedly 40 other companies suffered data breaches.
  • The same ransomware gang, Clop, took responsibilty for the hacks.
  • No word yet on material effects.

[This article originally ran August 17, 2026.]

Update August 19, 2026:

BleepingComputer reports today that some of the tools used by the Clop ransomware gang were specifically designed to breach PTC Windchill and FlexPLM servers, based on detailed knowledge of Windchill's functionalities.

Ensar Seker, chief information security officer (CISO) at cybersecurity company SOCRadar, wants observers to be clear about two important complications.

“First, there is evidence that attackers were exploiting these PTC environments before defenders had the full benefit of the public warning and remediation process.

Second, “a patch was released” does not necessarily mean that every version of a complex enterprise platform could immediately receive the same patch. PTC’s remediation was released in stages across different Windchill and FlexPLM versions. Large manufacturers can also have many instances, different versions, integrations with engineering and manufacturing systems, and strict testing and availability requirements. Knowing about a vulnerability and safely remediating every affected instance across a global enterprise are two different problems.

Mature organizations should know where internet-facing systems like Windchill are located, have ownership assigned to them, be able to identify vulnerable versions rapidly and have emergency procedures for patching, isolating or otherwise mitigating them. For something this serious, normal monthly patch cycles are not appropriate.

But the bigger lesson is that vulnerability management cannot stop at ‘Did we install the patch?’ For an actively exploited vulnerability, the question has to be: ‘Were we compromised before we patched?’”

Update August 18, 2026:

Adam Arellano, field CTO of AI-based automation company Harness, says we shouldn’t be harsh on these companies for not patching advertised vulnerabilities, were that the case.

“The word ‘should’ is doing a lot of work here. In theory, organizations of this size, particularly those operating critical infrastructure, should be able to patch or mitigate a critical vulnerability within hours. In practice, many simply cannot.

“There are several reasons for that. They may be running decades-old technology that cannot be easily updated, dealing with regulatory or operational constraints that make downtime difficult or lacking the leadership alignment needed to prioritize modernization. Together, these factors create a perfect storm in which even a well-publicized vulnerability may remain unpatched.

“I can’t speak to the specific environments at GE or Philips, but for many organizations of comparable size and complexity, patching cycles can take a month or longer, even for relatively modern applications. They may also have end-of-life systems that are no longer supported or patchable but continue to underpin critical business operations.

The answer is partly technological, but it is ultimately a leadership issue. Organizations must be willing to modernize legacy environments, identify systems that cannot be patched and put compensating controls in place. That urgency will only grow as AI allows attackers to identify and exploit vulnerabilities more quickly and at greater scale.”

Original story:

How many times has a cybersecurity expert here on IndustryWeek told you the importance of patching your systems to maintain cybersecurity hygiene?

Why? Because here we go:

BleepingComputer today reports that GE and Philips confirmed investigating data breaches purportedly at the hands of the Clop ransomware gang. Shell confirmed on August 14 it also had been attacked, again supposedly by Clop.

The ransomware gang on its dark Web site claimed to have stolen data including diagrams, blueprints and project plans from 43 companies in total.

Also according to Bleeping Computer, the hackers exploited vulnerabilities in two software products from PTC, the Windchill and FlexPLM product management lifecycle (PLM) tools. This was a known vulnerability.

PTC in mid-June began releasing security patches for the software to close the vulnerability and urged customers to do so.

The U.S. Cybersecurity and Infrastructure Agency (CISA) on June 25 confirmed the existence of the vulnerability and mandated federal agencies to patch all instances of Windchill and FlexPLM within three days of the announcement.

So the next time you read a cybersecurity expert on IndustryWeek advising you to patch your systems, this is what they’re talking about.

Philips told Reuters the breach did not “impact customer environments.”  No word from GE, Shell, or anyone else about the effect of the breaches. If you see anyone filing 8-K forms with the SEC, that’s when things might get a lot more interesting.

About the Author

Dennis Scimeca

Dennis Scimeca

Dennis Scimeca is a veteran technology journalist with particular experience in vision system technology, machine learning/artificial intelligence, and augmented/mixed/virtual reality (XR), with bylines in consumer, developer, and B2B outlets.

At IndustryWeek, he covers the competitive advantages gained by manufacturers that deploy proven technologies. If you would like to share your story with IndustryWeek, please contact Dennis at [email protected].

 

Sign up for our eNewsletters
Get the latest news and updates

Voice Your Opinion!

To join the conversation, and become an exclusive member of IndustryWeek, create an account today!