Hacker Group Claims Data Theft From GE, Shell, Philips and Others
- A prolific cybercrime group has claimed responsibility for a mass data theft targeting nearly 50 major companies worldwide.
- Reuters could not independently verify the hacking group's claims regarding the volume or type of data stolen.
- A spokesperson for GE stated that the company is aware of the claim, and had initiated our cyber response protocols and are working to assess the potential issue.
Global Giants Face Mass Extortion Threat
A prolific cybercrime group has claimed responsibility for a mass data theft targeting nearly 50 major companies worldwide. The breach swept through high-profile institutions, catching industrial giant GE, medical equipment maker Philips, energy major Shell, and financial technology firm Fiserv in its dragnet.
Reuters could not independently verify the hacking group’s claims regarding the volume or type of data stolen. The hackers did not respond to requests for comment.
Corporate Containment and Assessment Underway
A spokesperson for GE stated that the company is aware of the claim, and had initiated our cyber response protocols and are working to assess the potential issue.
Philips reported that it had been targeted by the group known as Cl0p, identifying an attempted compromise of a specific enterprise server related to internal data. Philips has identified and contained an attempted cybersecurity compromise of a specific enterprise server related to internal data,
the company said in a statement, adding that customer environments remain unaffected.
Shell and Fiserv Evaluate the Fallout
Shell acknowledged that it was aware of a recent possible incident following initial reports from Dutch media outlet BNR. We are working with our security teams and relevant experts to investigate the situation,
a Shell spokesperson said.
Meanwhile, Fiserv reported that a comprehensive review found no evidence that customer, banking, transaction, or personal data had been compromised, nor that its operating environment had been affected, though it acknowledged being aware of the threat actor’s claims.
Zero-Day Exploits Target Engineering Software
While the method of access for each company remains under investigation, industry groups have pointed to software weaknesses as a primary vector. Ransom-ISAC, an industry information sharing group, issued a notice warning that the threat actor was actively exploiting vulnerabilities in PTC Windchill and FlexPLM software, which are widely used to manage engineering and manufacturing processes.
Boston-based PTC did not immediately respond to requests for comment, but the company has posted multiple security notices to its website urging customers to apply patches for the identified vulnerabilities.
Inside the Professional Extortion Playbook
Brandon Parsons, threat intelligence manager with Ascent Solutions and author of the Ransom-ISAC advisory, described the actors as professional data extortionists who began issuing notices to companies.
According to Parsons, the group focuses its attacks on zero-day software vulnerabilities rather than singling out specific corporate targets. The incident highlights ongoing cybersecurity risks tied to widely deployed enterprise software packages used across global manufacturing, energy, and financial sectors.
