Cl0p Claims Data Theft From Nearly 50 Companies Worldwide
A prolific hacking group known for exploiting software vulnerabilities has claimed it stole large volumes of data from nearly 50 companies worldwide, including Philips, Shell, Fiserv and GE.
The group, known as Cl0p, made the claims on its website. However, Reuters could not independently verify what type of data was allegedly stolen or how much information was involved.
Philips said it had been targeted by Cl0p. The company said it identified and contained an attempted cybersecurity compromise involving a specific enterprise server connected to internal data. It added that the incident did not affect customer environments.
Shell also said it was aware of a recent “possible incident”, confirming an earlier report by Dutch media outlet BNR. A Shell spokesperson said the company was working with its security teams and relevant experts to investigate the situation.
Fiserv said it was aware of the threat actor’s claims. However, the company said its comprehensive review had found no evidence that customer, banking, transaction or personal data had been compromised. It also said there was no evidence that its operating environment had been affected.
GE said it was aware of the claim. The company added that it had started its cyber response protocols and was assessing the potential issue.
Cl0p Exploits Software Vulnerabilities
The method allegedly used by the hackers to access the companies remains unclear. However, Ransom-ISAC, an industry information-sharing group, issued a notice on July 22 warning that Cl0p was exploiting vulnerabilities in PTC Windchill and FlexPLM.
The software is used to support engineering and manufacturing processes. PTC, which is based in Boston, did not immediately respond to a request for comment.
PTC has issued multiple security notices on its website since June 18. The notices have urged customers to apply a patch for a vulnerability and provided details about an unnamed attacker targeting its products.
Companies Received Cl0p Notices
Brandon Parsons, threat intelligence manager at Ascent Solutions and author of the Ransom-ISAC advisory, said some companies began receiving notices from Cl0p on July 19 or July 20.
Parsons said the group focuses on vulnerabilities in important software packages rather than individual companies. He described Cl0p as “professional data extortionists”.
He said the group does not generally select a particular company first. Instead, it identifies a specific zero-day vulnerability and then targets organisations using affected software.
A zero-day vulnerability refers to a previously unknown software flaw for which a vendor has not yet issued a patch.
Hacking Claims Remain Unverified
The hackers did not respond to a request for comment. Meanwhile, Reuters was unable to independently verify the group’s claims about the alleged data theft.
The companies named by Cl0p have reported different stages of investigation and response. Philips confirmed an attempted compromise, while Shell acknowledged a possible incident. Fiserv said it had found no evidence of compromised data or an affected operating environment, and GE said it was assessing the potential issue.
With inputs from Reuters

