Clop Hacks Shell, GE, Philips in 43-Victim PTC Windchill Zero-Day Campaign
Ransomware group Clop says it breached 43 organizations, naming Shell, GE, and Philips, by exploiting a PTC Windchill PDMLink and FlexPLM zero-day. Shell confirmed it is investigating a potential incident and said it is working with security teams. The exploited flaw is CVE-2026-12569 (CVSS 9.8), chained with a FlexPLM WSDL issue. PTC began patches June 17; CISA added the CVE to KEV on June 25.







