Hackers, reportedly from ransomware cybercriminal gang Clop, broke into product lifecycle management tools commonly used by manufacturers in recent attacks at Shell, GE, and Philips that exploited vulnerabilities in PLM software from vendor PTC.
GE and Philips confirmed investigating data breaches purportedly at the hands of Clop. Shell confirmed Aug. 14 it also had been attacked, again supposedly by Clop. The vulnerabilities in the two PTC software packages, Windchill and FlexPLM, were known.
The ransomware gang, on its dark Web site, claimed to have stolen data, including diagrams, blueprints and project plans, from 43 companies in total, likely targeted in data theft attacks exploiting a critical improper input validation vulnerability (tracked as CVE-2026-12569) against internet-connected PTC Windchill and PTC FlexPLM
PTC in mid-June began releasing security patches for the software to close the vulnerability and urged customers to update their versions immediately.
The U.S. Cybersecurity and Infrastructure Agency on June 25 confirmed the existence of the vulnerability and mandated that federal agencies patch all instances of Windchill and FlexPLM within three days of the announcement.
Philips told Reuters the breach did not “impact customer environments.”
There is evidence that attackers were exploiting these PTC environments before defenders had the full benefit of the public warning and remediation process.
– Ensar Seker, CISO at cybersecurity company SOCRadar
PTC said the two enterprise software platforms are widely used by high-profile companies across the aerospace, defense, automotive, heavy machinery, retail, and medtech sectors. The company said more than 30,000 customers globally use its products, including over 1,500 brand and retail customers using FlexPLM.
In these attacks, Clop claims it stole a wide range of sensitive data from the companies’ compromised systems, including backups, project plans, photos of facilities, drawings, diagrams, blueprints, and more, belonging to Shell, GE, and Philips
The ransomware group claimed it stole it stole 89GB of data from Shell.
Warning, patches came too late to stop attacks
BleepingComputer also reported that some of the tools used by the Clop ransomware gang were specifically designed to breach PTC Windchill and FlexPLM servers, based on detailed knowledge of Windchill’s functionalities.
“First, there is evidence that attackers were exploiting these PTC environments before defenders had the full benefit of the public warning and remediation process,” said Ensar Seker, chief information security officer at cybersecurity company SOCRadar.
Second, he stressed, “a patch was released” does not necessarily mean that every version of a complex enterprise platform could immediately receive it. PTC’s remediation was released in stages across different Windchill and FlexPLM versions.
Large manufacturers also can have many instances, different versions, integrations with engineering and manufacturing systems, and strict testing and availability requirements. Knowing about a vulnerability and safely remediating every affected instance across a global enterprise are two different problems.
Cyberattacks against manufacturing operations are hardly new, but AI is rapidly changing how quickly attackers can identify targets, find vulnerabilities, and exploit them.
At the same time, manufacturers are taking advantage of connectivity between IT and OT systems, adopting cloud-based tools, and enabling remote access to plant-floor assets. That connectivity exposes systems that do not have up-to-date cyber defenses to possible attack.
In theory, organizations of this size … should be able to patch or mitigate a critical vulnerability within hours. In practice, many simply cannot.
– Adam Arellano, field CTO with Harness
New pathways for hackers have been provided to critical systems such as PLCs, HMIs, drives, and other industrial controls.
In April, CISA issued a warning that cyber actors were specifically targeting OT devices, including PLCs. Hackers are looking to quickly exploit exposed controllers, poorly segmented networks, or unsecured remote access tools.
According to one expert, companies are not always able to patch advised vulnerabilities.
“The word ‘should’ is doing a lot of work here. In theory, organizations of this size, particularly those operating critical infrastructure, should be able to patch or mitigate a critical vulnerability within hours. In practice, many simply cannot,” said Adam Arellano, field chief technology officer with AI-based automation company Harness.
“There are several reasons for that. They may be running decades-old technology that cannot be easily updated, dealing with regulatory or operational constraints that make downtime difficult or lacking the leadership alignment needed to prioritize modernization. Together, these factors create a perfect storm in which even a well-publicized vulnerability may remain unpatched.”
Arellano added: “I can’t speak to the specific environments at GE or Philips, but for many organizations of comparable size and complexity, patching cycles can take a month or longer, even for relatively modern applications. They may also have end-of-life systems that are no longer supported or patchable but continue to underpin critical business operations.
“The answer is partly technological, but it is ultimately a leadership issue. Organizations must be willing to modernize legacy environments, identify systems that cannot be patched, and put compensating controls in place. That urgency will only grow as AI allows attackers to identify and exploit vulnerabilities more quickly and at greater scale.”
