Philips and GE investigating Clop ransomware data theft claims
Philips and General Electric (GE) are investigating claims that the Clop ransomware gang breached their systems and stole data. The Clop gang has listed the companies on its leak site as part of a batch of 43 new victims likely targeted in data theft attacks.
Intelligence analysis by Llama

Philips and GE are investigating claims that the Clop ransomware gang stole data from their systems. The Clop gang has listed the companies on its leak site as part of a batch of 43 new victims.
Imagine you have a super powerful computer that can break into other computers. This is what the Clop ransomware gang does. They break into big companies' computers and steal their data. Philips and GE are investigating if the Clop gang broke into their computers and stole data.
Analysis
Philips and GE Investigate Clop Ransomware Claims
Philips and General Electric (GE) have confirmed they are investigating claims that the Clop ransomware gang breached their systems and stole data. The investigation comes after the Clop gang listed the companies on its leak site as part of a batch of 43 new victims likely targeted in data theft attacks.
The Clop gang has a long history of targeting enterprise platforms in data theft attacks, breaching Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer file-sharing servers in previous campaigns. The gang has also begun exploiting an Oracle EBS zero-day flaw to steal sensitive files from many organizations.
The list of victims includes many high-profile organizations worldwide, including The Washington Post, GlobalLogic, Harvard University, the University of Pennsylvania, Logitech, Estée Lauder, Korean Air, and American Airlines subsidiary Envoy Air. The U.S. Department of State now offers a $10 million reward for any information linking the cybercrime gang's attacks to a foreign government.
PTC Warns of CVE-2026-12569 Vulnerability
PTC, the company behind the Windchill and FlexPLM enterprise software platforms, began releasing CVE-2026-12569 security patches on June 17. The company urged customers to review environments for indicators of compromise (IOCs) in a private advisory, even though there was no confirmation of in-the-wild exploitation.
Clop's History of Data Theft Attacks
The Clop extortion gang has a history of targeting enterprise platforms in data theft attacks. In previous campaigns, the gang breached Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer file-sharing servers. The gang has also begun exploiting an Oracle EBS zero-day flaw to steal sensitive files from many organizations.
The Investigation Continues
The investigation into the Clop ransomware gang's claims of data theft from Philips and GE is ongoing. The companies have yet to share more information, but the Clop gang has listed them on its leak site as part of a batch of 43 new victims.
Key points
- Philips and GE are investigating claims that the Clop ransomware gang breached their systems and stole data.
- The Clop gang has listed the companies on its leak site as part of a batch of 43 new victims.
- The Clop gang has a long history of targeting enterprise platforms in data theft attacks.
- The gang has also begun exploiting an Oracle EBS zero-day flaw to steal sensitive files from many organizations.
If the investigation into the Clop ransomware gang's claims of data theft from Philips and GE is successful, it could lead to the gang being caught and brought to justice. This would be a significant victory in the fight against ransomware attacks.
If the Clop ransomware gang is able to successfully steal data from Philips and GE, it could lead to a significant breach of sensitive information. This could have serious consequences for the companies and their customers.



