Urgent.News

One page, thousands of outlets. See who else covered it.

Editions

Tech

Cl0p widens data theft campaign across global firms

Cl0p has claimed a sweeping data-theft campaign affecting nearly 50 companies worldwide, placing Shell, Philips, GE and financial technology group Fiserv among the organisations named on the cybercrime operation’s leak site. Several companies have opened investigations, although the scale of the alleged theft remains unverified. The campaign appears to mark another large-scale attempt by the…

Cl0p, a cybercrime group with ties to Russia, has expanded its data-theft campaign to involve nearly 50 companies worldwide, according to a leak site. High-profile targets include Shell, Philips, GE, and Fiserv. While several firms have initiated investigations, the full scope of the alleged theft remains unclear. The group appears to be targeting weaknesses in widely-used enterprise software, rather than individualized attacks.

Security experts have linked the activity to vulnerabilities in PTC Windchill and FlexPLM systems, which are used to manage engineering designs, manufacturing data, product development, and supply-chain information. Cl0p claims to have obtained around 89GB of data from Shell, potentially including engineering drawings, facility photos, test report scans, and project documentation. Shell has acknowledged a potential security incident, but has not confirmed the volume or types of information reportedly stolen.

Philips has confirmed detecting and containing what it describes as an attempted compromise involving an internal enterprise server, with no impact on customer environments. The company's internal material is claimed by Cl0p to include diagrams and blueprints, though the accuracy of this information is yet to be independently verified. Fiserv maintains that customer, banking, transaction, or personal data have not been compromised, and its operating environment remains unaffected.

GE has initiated its cyber-response procedures and is assessing the claim made against it. Recent attention has been drawn to CVE-2026-12569, a critical vulnerability affecting PTC Windchill and FlexPLM. This flaw could permit unauthenticated remote code execution, potentially allowing attackers to deploy malicious web shells and extract sensitive data from exposed systems. PTC began releasing security updates in June, urging customers to inspect systems for signs of compromise as concerns over active exploitation grew.

US cybersecurity authorities have added CVE-2026-12569 to the Known Exploited Vulnerabilities catalogue and implemented an accelerated remediation timetable for federal agencies. The urgency stems from the risk posed by internet-facing installations of software that can contain commercially sensitive product designs, manufacturing information, specifications, and other intellectual property.

Cl0p's strategy involves identifying vulnerabilities in widely-used corporate platforms and exploiting them across numerous organizations before launching an extortion campaign, rather than focusing on a single network.

Cl0p has increasingly become associated with data theft and extortion campaigns, where encryption is not necessarily the primary weapon. After extracting corporate information, the group typically contacts victims, threatening publication unless a ransom is paid. Naming companies on a leak site adds pressure and creates reputational and regulatory risks, even before the exact extent of a breach is determined.

Earlier this year, Cl0p exploited vulnerabilities in enterprise file-transfer and business applications, and in 2023, it targeted MOVEit Transfer, affecting more than 2,700 organizations worldwide.

Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at thearabianpost.com →

More in Tech

Your Integrity Checks Are Watching the Wrong Layer

Ciao Amici 👋 Quick story before we get into the weeds. Last week I took a patient health record sitting in Amazon S3, a file clearly stamped as regulated under HIPAA, and I changed its security label…

  • S3 annotations enable attaching 1,000 structured metadata per object
  • Integrity monitors cannot detect changes to security labels
  • Document classifier assigns sensitivity labels to test vulnerability

More from Monday 17 August →