Key Takeaways

  • General Electric and Philips are assessing Clop ransomware claims tied to attacks on Internet-exposed PTC software.
  • Philips stated the compromise was contained to a specific enterprise server and had no impact on customer environments.
  • The campaign highlights the systemic risks posed by enterprise platforms holding sensitive engineering, product, and operational data.

General Electric (GE) and Philips are investigating cybersecurity incidents after the Clop ransomware gang claimed to have breached their systems and stolen sensitive data, adding two major industrial and medical technology names to a widening extortion campaign.

GE said it was aware of Clop’s claim and was “working to assess the potential issue.” Philips went further, confirming that an internal system had been compromised but saying the event was contained.

“Philips has identified and contained an attempted cybersecurity compromise of a specific enterprise server related to internal data,” Philips said in a statement. “This has no impact on customer environments.”

That distinction matters. Philips has not reported an impact on customer systems, clinical environments, or medical devices. Clop’s account also remains a criminal group’s claim rather than independent confirmation of the full scope of any data theft. GE has not disclosed whether attackers accessed information or disrupted operations.

Shell is investigating a related potential incident after Clop claimed to have stolen 89GB of its data. The gang listed Shell, GE, and Philips among a batch of 43 new victims, apparently connecting them to attacks against Internet-exposed PTC Windchill and PTC FlexPLM installations.

PTC’s platforms occupy a particularly sensitive place in corporate infrastructure. Windchill supports product lifecycle management, while FlexPLM is used for retail, footwear, apparel, and consumer-product development. PTC says its products serve more than 30,000 customers globally, including over 1,500 brand and retail customers using FlexPLM.

In practical terms, these systems contain the digital workings of a business: project plans, engineering drawings, facility photographs, diagrams, blueprints, design histories, and backups. Clop claims it extracted those kinds of files from Shell, GE, and Philips.

While a product lifecycle management server may not look as immediately critical as a payment platform or hospital network, its contents can reveal intellectual property, manufacturing processes, future products, supplier relationships, and physical-site details. Compromised Internet-facing applications can expose years of engineering knowledge to extortion tactics.

The suspected entry point involves a critical improper input validation vulnerability affecting PTC Windchill and PTC FlexPLM. Following initial patch releases and private customer advisories, the U.S. Cybersecurity and Infrastructure Security Agency added the flaw to its known exploited vulnerabilities catalog and required federal agencies to secure affected installations. Germany’s Federal Office for Information Security also issued an urgent patching warning.

Investigators found attackers deploying JSP webshells on compromised platforms, giving Clop a persistent mechanism for accessing systems and removing data. That pattern fits the gang’s established model. Clop has previously targeted widely deployed enterprise products including Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer. The MOVEit campaign affected more than 2,770 organizations worldwide.

The healthcare angle raises additional concerns. ENISA found that ransomware accounted for about 54% of all cyber incidents in the European health sector between January 2021 and March 2023. Healthcare providers accounted for roughly 53% of the 215 publicly reported incidents, while hospitals represented around 42%.

Meanwhile, the Sophos State of Ransomware in Healthcare report observed that 73% of healthcare ransomware attacks resulted in data encryption in 2023. Data was also stolen in 37% of those incidents, reflecting the double-extortion approach in which attackers use disclosure threats alongside operational disruption.

For Philips, GE Healthcare, and other medical technology suppliers, incident response also intersects with product-security obligations. The FDA directs medical-device manufacturers toward risk-based lifecycle practices aligned with the NIST Cybersecurity Framework, including software bills of materials and coordinated vulnerability management.

The immediate priority for PTC customers is broader than installing a patch. Organizations need to determine whether systems were exposed before remediation, search for webshells and unusual data transfers, rotate potentially compromised credentials, and review what information resided on affected servers. Clop’s history suggests the absence of encryption does not indicate the absence of damage; in many extortion campaigns, the data theft itself is the primary attack.