General Electric and Philips are investigating claims by the Clop ransomware gang that it breached their systems and stole data, according to BleepingComputer. The report says the companies have not confirmed Clop’s data-theft claims, but both have acknowledged they are assessing or responding to a potential security issue. GE told BleepingComputer it was aware of the claim and was working to assess the potential issue. Philips gave a more specific response, saying it had identified and contained an attempted cybersecurity compromise of a specific enterprise server related to internal data. Philips said the incident had no impact on customer environments, according to a statement BleepingComputer says was shared with Reuters. The claims put GE and Philips alongside Shell, which BleepingComputer reported on Friday was also investigating a potential security incident after Clop claimed it had stolen 89GB of data. Shell told the outlet it was aware of a potential incident and was working with security teams and relevant experts to investigate. BleepingComputer reports that Clop listed Shell, GE and Philips as part of a batch of 43 new victims on its leak site. The gang claims it stole a range of sensitive information from compromised systems, including backups, project plans, facility photos, drawings, diagrams and blueprints. Those claims have not been confirmed by the affected companies in the provided reporting. The likely technical path, according to BleepingComputer, is exploitation of CVE-2026-12569, a critical improper input validation vulnerability affecting Internet-exposed PTC Windchill and PTC FlexPLM instances. PTC describes the two enterprise platforms as widely used across aerospace, defense, automotive, heavy machinery, retail and medtech, with more than 30,000 customers globally and more than 1,500 brand and retail customers using FlexPLM. PTC began releasing security patches for CVE-2026-12569 on June 17, BleepingComputer reports, and urged customers through a private advisory to review environments for indicators of compromise. The outlet says ReliaQuest and the Ransomware Information Sharing and Analysis Centre later confirmed Clop attacks against Windchill and FlexPLM environments, with attackers deploying JSP webshells to steal sensitive data from compromised product lifecycle management platforms. The U.S. Cybersecurity and Infrastructure Security Agency also confirmed active exploitation of the flaw after PTC warned of heightened threat activity on June 26, according to BleepingComputer. CISA added the vulnerability to its known exploited vulnerabilities catalog and directed federal agencies to secure affected PTC Windchill and FlexPLM instances within three days. Who benefits: Security teams with PTC Windchill or FlexPLM exposure get a clearer priority signal: review patch status, exposure and indicators of compromise. Incident-response vendors may also see demand from organizations in sectors PTC says use these platforms heavily. Who's exposed: Companies running Internet-exposed PTC Windchill or FlexPLM instances are the most directly exposed group identified in the reporting. GE and Philips have not confirmed Clop’s theft claims, so the scale of any data exposure remains unresolved.