Cl0p hacking group claims data theft from nearly 50 firms including Philips and Shell
The Cl0p hacking group has claimed to have stolen large amounts of data from nearly 50 companies worldwide, including Philips, Shell, Fiserv and General Electric, by exploiting vulnerabilities in PTC's Windchill and FlexPLM software. Philips confirmed it was attacked, while Shell said it is investigating a suspected security incident. Fiserv found no evidence of customer data exposure. An industry warning on July 22 flagged the vulnerability exploitation, with some firms receiving ransom notices from July 19.
A hacking group that specialises in exploiting software vulnerabilities to strike multiple targets simultaneously claims to have stolen vast amounts of data from nearly 50 companies worldwide, including Philips, Shell, Fiserv and General Electric. Philips confirmed it was attacked by the Cl0p hacking group, while Shell said it had noted a recent "suspected security incident". A Shell spokesperson said the company was investigating the matter together with its internal security team and relevant professionals.
Philips said in a statement that it had identified and blocked a cyberattack attempt against a specific enterprise server holding internal data, and that the incident had not affected customer environments. A Fiserv spokesperson said the company was aware of the attackers' claims, but that a comprehensive review to date had found no leakage of customer banking, transaction or personal data, nor any impact on its operating environment. General Electric did not respond immediately.
It remains unclear how the hacking group breached these companies. The Ransomware Information Sharing and Analysis Center, an industry information-sharing body, issued a warning on July 22 saying the group was exploiting vulnerabilities in PTC's Windchill and FlexPLM software, which are mainly used to support engineering design and manufacturing processes. Boston-based PTC has not responded to requests for comment. Since June 18, the company has published multiple security advisories on its website urging customers to install patches, and has disclosed details of attacks launched by unidentified hackers against its software.
Brandon Parsons, threat intelligence director at Asente Solutions and author of the R-ISAC warning, said some companies received ransom notices from the Cl0p group as early as July 19 and 20. He said the group targets vulnerabilities in mainstream software suites rather than specific companies, describing it as a "professional data extortion group". Speaking of zero-day vulnerabilities, or program flaws for which software vendors have not yet released patches and which have never been publicly disclosed, Parsons said the group does not target any single company but locks onto specific zero-day flaws as a breach point to launch attacks.