decrypted · 17 august 2026 · ransomware and cybercrime · vulnerabilities and patching · surveillance and privacy

GE and Philips join Shell on Clop's leak site, over a flaw exploited before it had a patch

The Clop breach that put Shell on a leak site three days ago has widened. General Electric and Philips are now investigating claims that the same gang stole data from their systems, taking the campaign's public tally to 43 named organisations, all compromised through one flaw in engineering software most UK manufacturers have never had reason to think about, let alone patch on time.

What moved since Shell

Philips has confirmed a breach of "a specific enterprise server related to internal data", and says it has been contained with no impact on customer environments. GE has acknowledged the claim and says it is assessing it. Neither is a small admission: both sit in the list of 43 victims Clop has now posted to its leak site, alongside the 89 gigabytes of drawings, facility reports and project plans it says it took from Shell.

The route in was CVE-2026-12569, a deserialisation flaw in PTC's Windchill and FlexPLM software, the product lifecycle management platforms that aerospace, automotive, defence and manufacturing firms use to store engineering data and manage supplier access. Deserialisation bugs are a well understood class of problem: the software takes a block of structured data from the network and rebuilds it into a working object without properly checking what is inside first, rather like accepting a sealed parcel and letting it unwrap and assemble itself in your hallway. Rated 9.8 out of 10, it let an unauthenticated attacker run code on the server outright. PTC shipped patches on 17 June, but researchers assess Clop's affiliates were already exploiting it as a zero-day from early June, weeks before any fix existed.

The Secure by Design lesson

Windchill and FlexPLM hold exactly the kind of data a manufacturer cannot afford to lose control of: CAD files, blueprints, supplier contracts, product specifications. That makes them crown jewels, but they are frequently run as a bolt-on system, internet-facing so external suppliers can collaborate, and patched on the same cadence as everything else rather than treated as a priority asset. Deserialising untrusted input is a vulnerability class software vendors have known to avoid by design for over a decade, through safe parsers and strict allow-lists, yet it keeps resurfacing in enterprise platforms that were never built with an adversarial internet in mind. For UK manufacturers and their supply chains, the lesson isn't just "patch PTC Windchill". It's that any system holding engineering IP and offering supplier access deserves network segmentation and monitoring proportionate to what it protects, not proportionate to how often IT remembers it exists.

Also this week

Sources

If your organisation runs PTC Windchill, Cisco ASA or FTD, or handles sensitive personal data and wants a second opinion on exposure, get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.