decrypted · 17 august 2026 · ransomware and cybercrime · vulnerabilities and patching · surveillance and privacy
GE and Philips join Shell on Clop's leak site, over a flaw exploited before it had a patch
The Clop breach that put Shell on a leak site three days ago has widened. General Electric and Philips are now investigating claims that the same gang stole data from their systems, taking the campaign's public tally to 43 named organisations, all compromised through one flaw in engineering software most UK manufacturers have never had reason to think about, let alone patch on time.
What moved since Shell
Philips has confirmed a breach of "a specific enterprise server related to internal data", and says it has been contained with no impact on customer environments. GE has acknowledged the claim and says it is assessing it. Neither is a small admission: both sit in the list of 43 victims Clop has now posted to its leak site, alongside the 89 gigabytes of drawings, facility reports and project plans it says it took from Shell.
The route in was CVE-2026-12569, a deserialisation flaw in PTC's Windchill and FlexPLM software, the product lifecycle management platforms that aerospace, automotive, defence and manufacturing firms use to store engineering data and manage supplier access. Deserialisation bugs are a well understood class of problem: the software takes a block of structured data from the network and rebuilds it into a working object without properly checking what is inside first, rather like accepting a sealed parcel and letting it unwrap and assemble itself in your hallway. Rated 9.8 out of 10, it let an unauthenticated attacker run code on the server outright. PTC shipped patches on 17 June, but researchers assess Clop's affiliates were already exploiting it as a zero-day from early June, weeks before any fix existed.
The Secure by Design lesson
Windchill and FlexPLM hold exactly the kind of data a manufacturer cannot afford to lose control of: CAD files, blueprints, supplier contracts, product specifications. That makes them crown jewels, but they are frequently run as a bolt-on system, internet-facing so external suppliers can collaborate, and patched on the same cadence as everything else rather than treated as a priority asset. Deserialising untrusted input is a vulnerability class software vendors have known to avoid by design for over a decade, through safe parsers and strict allow-lists, yet it keeps resurfacing in enterprise platforms that were never built with an adversarial internet in mind. For UK manufacturers and their supply chains, the lesson isn't just "patch PTC Windchill". It's that any system holding engineering IP and offering supplier access deserves network segmentation and monitoring proportionate to what it protects, not proportionate to how often IT remembers it exists.
Also this week
-
Cisco ASA and FTD firewalls remain under active attack. CVE-2026-20349 lets an unauthenticated attacker crash a firewall's VPN service with a single crafted HTTP request, no credentials required. Cisco confirmed exploitation in the wild this month, and NHS England's cyber alert, issued 12 August, assesses "further exploitation as likely" and offers no workaround beyond patching. Any UK organisation using Cisco ASA or FTD for remote access VPN should treat this as done, not scheduled.
-
France's tax authority sat on a breach for six weeks before saying anything. DGFiP detected and shut down unauthorised access to its systems in late June, reached via credentials used to log into an internal VPN and search tool, but only confirmed the incident this week after a hacker calling themselves ZeroBytes began advertising 678,000 taxpayers' records for sale on a criminal forum. User passwords weren't compromised, but names, addresses, tax IDs and family details were. It's a reminder that containing an intrusion quietly is not the same as disclosing it, and that organisations sitting on an unresolved incident risk having the story told for them, by the person who broke in.
Sources
- Philips and GE investigating Clop ransomware data theft claims
- Clop exploits vulnerability in PTC Windchill and FlexPLM
- NHS England cyber alert CC-4831: Cisco Secure Firewall ASA and FTD
- Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349)
- French tax authority data breach affects 678,000 individuals
- France investigates tax authority breach after hacker claims 600,000 victims
If your organisation runs PTC Windchill, Cisco ASA or FTD, or handles sensitive personal data and wants a second opinion on exposure, get in touch.
More like this
- Apple goes back to court over the UK's iCloud backdoor 7 august 2026
- A hospital billing vendor's breach, and the 147 million records it inherited 22 july 2026
- Iran's spyware campaign starts with a chat, not an exploit 16 september 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.
Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.