Hacker group claims mass data theft from dozens of companies, including Philips, Shell, Fiserv, GE
Summarized and contextualized by DistantNews.
At a glance
- A prolific hacking group known as Cl0p claimed to have stolen data from nearly 50 companies, including Philips, Shell, Fiserv, and GE.
- The group reportedly exploited vulnerabilities in software used for engineering and manufacturing processes.
- Several targeted companies confirmed they are investigating the claims, with some stating no customer data appears to be compromised.
A hacking group identified as Cl0p has claimed responsibility for a massive data breach, asserting it has stolen large volumes of data from approximately 50 companies globally. Among the alleged victims are major corporations such as Philips, Shell, Fiserv, and General Electric.
We are working with our security teams and relevant experts to investigate the situation.
The group's claims were posted on its website. Philips confirmed it was targeted, stating it identified and contained an attempted compromise of a specific enterprise server, but assured that customer environments were not impacted. Shell acknowledged awareness of a potential incident and is investigating with security teams. Fiserv reported that its review found no evidence of compromised customer, banking, transaction, or personal data, nor any impact on its operating environment. GE stated it is aware of the claim and has activated its cyber response protocols.
Philips has identified and contained an attempted cybersecurity compromise of a specific enterprise server related to internal data.
Reuters could not independently verify the extent or nature of the data allegedly stolen. The hacking group did not respond to requests for comment. Industry group Ransom-ISAC had previously warned that Cl0p was exploiting vulnerabilities in PTC's Windchill and FlexPLM software, which are widely used in engineering and manufacturing. These vulnerabilities, often zero-day exploits unknown to software vendors, allow the group to target specific software packages rather than individual companies, positioning them as "professional data extortionists."
based on our comprehensive review to date, we have found no evidence that customer, banking, transaction, or personal data has been compromised, nor that our operating environment has been affected.
Originally published by Jerusalem Post. Summarized and contextualized by our editorial team with added local perspective. Read our editorial standards.