Automatically translated.View original post

Clop Hackers Hack Big Companies Shell, GE and Philips

Clop claims drill 3 big companies Shell, GE and Philips steal data through PTC vulnerability

The hacker group Clop (Cl0p) is being watched again, the latter claiming to have attacked several large companies around the world, including Shell, General Electric (GE) and Philips, by virtue of serious vulnerabilities in PTC Windchill and FlexPLM software.

This incident was part of an attack campaign aimed at stealing data and then putting pressure on it for ransom rather than encrypting conventional ransomware systems, with Clop claiming dozens of companies were victimized while each company was investigating how much data was actually stolen.

🔥 Shell was claimed to have dropped 89 GB of data.

One of the most talked about is Shell, the world's major energy company from the UK, with Clop claiming it can steal about 89 GB of data from its systems.

The information the hacker group claimed to have stolen included engineering documents, test reports, photos of the establishment, as well as information about the company's projects.

However, Shell has yet to confirm that all of the information Clop claims was actually stolen, with the company stating only that it acknowledged the potential incident and is investigating it in conjunction with an internal security team and outside experts.

🏭 GE and Philips were also claimed as victims.

In addition to Shell, Clop claims to have obtained data from General Electric (GE) and Philips, such as system files, backup files, schematics, and design data.

But likewise, this part of the data is still awaiting review from the companies involved, with Reuters reporting that GE has begun a cyber incident response process, while Philips confirmed that an attempt was made to penetrate the internal server, but indicated that the customer data had not been affected.

⚠️ The leading cause is vulnerability CVE-2026-12569.

Behind this attack is linked to the vulnerability CVE-2026-12569, located in PTC Windchill and FlexPLM software used by many organizations for managing product, engineering and manufacturing data and processes.

This vulnerability is Critical-level violent and can open the way for an unauthenticated attacker to remotely execute code on the system. NIST provides a CVSS v3.1 score of 9.8, and CISA places this vulnerability on the list of vulnerabilities that have actually been exploited.

In other words, if an organization keeps this vulnerable system open on the Internet and has not yet plugged it, hackers may use this channel to gain control of the system, install remote commanding tools, and steal important files.

🛡️ PTC accelerates reminding customers to check the system.

PTC has issued security patches and recommendations warning customers to speed up system updates and check for intrusion signals. Indicators of Compromise (IOCs) have been published for helping administrators determine if their own systems may be compromised.

# Trending # lemon 8 diary # shell # ge # Philips

23 hours agoEdited to

... Read moreจากประสบการณ์ที่ติดตามข่าวความปลอดภัยไซเบอร์ กลุ่มแฮกเกอร์ Clop ถือเป็นหนึ่งในแก๊งแรนซัมแวร์ที่มีรูปแบบการโจมตีโดยเน้นขโมยข้อมูลสำคัญไปเพื่อกดดันเรียกค่าไถ่มากกว่าการเข้ารหัสข้อมูลตรงๆ ซึ่งเหตุการณ์ครั้งนี้สะท้อนให้เห็นถึงความเสี่ยงขององค์กรใหญ่ที่ใช้ซอฟต์แวร์ด้านการจัดการผลิตภัณฑ์ เช่น PTC Windchill และ FlexPLM หากระบบเหล่านี้เปิดสู่ภายนอกโดยไม่ได้รับการอัปเดตแพตช์ช่องโหว่ CVE-2026-12569 จะถูกโจมตีได้ง่ายมาก ช่องโหว่นี้ถือว่าวิกฤติกับความปลอดภัยไซเบอร์ เพราะอนุญาตให้แฮกเกอร์สามารถสั่งรันโค้ดจากระยะไกลได้โดยไม่ต้องยืนยันตัวตน จึงเปิดทางให้เข้าสู่ระบบภายในองค์กรและเข้าถึงข้อมูลที่ละเอียดอ่อนได้ เช่น เอกสารด้านวิศวกรรม รายงาน และไฟล์สำรองข้อมูล เช่นที่ Clop อ้างขโมยจาก Shell ถึง 89 GB ซึ่งไม่เพียงแต่กระทบต่อความลับทางธุรกิจ แต่ยังอาจส่งผลต่อความน่าเชื่อถือและภาพลักษณ์ของบริษัทด้วย ผมเห็นว่าองค์กรที่ใช้ระบบ PTC ต้องรีบตรวจสอบและอัปเดตแพตช์อย่างรวดเร็ว พร้อมตรวจสอบ Indicators of Compromise (IOCs) ที่ PTC ออกมาเพื่อป้องกันไม่ให้ตกเป็นเหยื่อของกลุ่มคลิปนี้ เรื่องนี้ยังช่วยตอกย้ำว่าเรื่องความปลอดภัยไซเบอร์ต้องเป็นเรื่องเร่งด่วนของทุกองค์กร แม้จะเป็นบริษัทระดับโลกก็ไม่ควรมองข้าม จากกรณีนี้ผู้ดูแลระบบและผู้บริหารทางไอทีควรเน้นย้ำให้มีการวางแผนความปลอดภัย ทั้งการอัปเดตซอฟต์แวร์ป้องกันช่องโหว่และมีการเฝ้าระวังระบบตลอดเวลา เพื่อป้องกันการโจมตีในอนาคตที่จะทวีความซับซ้อนและรุนแรงมากขึ้น เราควรเรียนรู้จากเหตุการณ์แฮกครั้งนี้ เพราะข้อมูลที่ถูกขโมยไปอาจถูกใช้ในทางที่ไม่ดีต่อองค์กรและอุตสาหกรรมโดยรวมในระยะยาว