On August 12, 2026, the Russia linked Cl0p group claimed data theft from 50 firms—including Shell (89GB) and Philips (13.5GB)—via a zero day exploit (CVE 2026 12569) in PTC Windchill PLM software, skipping encryption... Philips confirmed a containment of the attack, Shell said it's investigating, while GE and Fiserv...
Research answer

Create a landscape editorial hero image for this Studio Global article: What did Cl0p claim regarding mass data theft from nearly 50 companies including Shell, Philips, Fiserv, and GE, how has each company respon. Article summary: Here is a concise answer covering all four parts of your question.. Topic tags: general, general web, user generated, government. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clickbait thumbnails, icons, and tiny thumbnail layouts. Make it useful as an illustrative visual, not as factual evidence.
On August 12, 2026, the Russia-linked ransomware group Cl0p (also tracked as FIN11, Graceful Spider, or Lace Tempest) posted a list of nearly 50 victim companies on its dark web extortion site . The group claimed to have stolen massive troves of sensitive corporate data, including engineering blueprints, technical drawings, and project plans, from some of the world’s largest corporations, including Shell, Philips, Fiserv, and General Electric (GE)
. This article breaks down the attack, the zero-day vulnerability used, and how each company has responded.
The group's claims, reported widely by outlets including Reuters, are specific and detailed. They assert that the breach relied on a single software vulnerability rather than multiple, separate intrusions . The claimed data haul includes:
Important Caveat: The list of victims and the claimed data volumes originate from Cl0p itself and have not been independently verified by security researchers or the named companies .
The targeted companies have responded with varying degrees of confirmation and detail, all remaining in an investigation or containment phase. None have independently confirmed the full scope of Cl0p's claims.
A coordinated advisory from Ransom-ISAC, eCrime.ch, and DEFUSED linked this campaign to the exploitation of CVE-2026-12569, a critical vulnerability in PTC Windchill PDMLink and PTC FlexPLM .
What is CVE-2026-12569? This is a critical remote code execution (RCE) flaw caused by the deserialization of untrusted data . It carries a CVSS score of 9.8 (Critical) and affects Windchill and FlexPLM releases prior to version 11.0 M030
. The vulnerability allows an unauthenticated attacker to execute arbitrary code on an internet-exposed server running the vulnerable software with no valid credentials
. CISA added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on June 25, 2026
.
The Exploitation Chain: Attackers did not use CVE-2026-12569 in isolation. They chained it with a pre-authentication information disclosure flaw in the FlexPLM WSDL endpoint . This chain allowed attackers to:
Timeline of Events:
This campaign is a textbook example of Cl0p's operational model—data exfiltration without encryption. The group did not deploy file-encrypting ransomware on the targeted systems. Instead, they focused on :
In short, Cl0p weaponized a single zero-day vulnerability (CVE-2026-12569) to compromise ~50 organizations globally, stole sensitive design and engineering data, and then applied its standard extortion playbook: publish names, threaten leaks, and demand payment.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
On August 12, 2026, the Russia linked Cl0p group claimed data theft from 50 firms—including Shell (89GB) and Philips (13.5GB)—via a zero day exploit (CVE 2026 12569) in PTC Windchill PLM software, skipping encryption...
On August 12, 2026, the Russia linked Cl0p group claimed data theft from 50 firms—including Shell (89GB) and Philips (13.5GB)—via a zero day exploit (CVE 2026 12569) in PTC Windchill PLM software, skipping encryption... Philips confirmed a containment of the attack, Shell said it's investigating, while GE and Fiserv are yet to issue detailed public confirmations.
The campaign is a textbook example of Cl0p's 'big game hunting' model: exploit a single software supply chain vulnerability, steal data en masse, and threaten to publish if ransoms aren't paid.