AMSTERDAM (Europe Tech Desk): A major cybercrime campaign has placed dozens of multinational companies under scrutiny after the Cl0p hacking group claimed it had stolen large amounts of data from nearly 50 organizations across multiple industries.
Among the companies listed by the group are Shell, Philips, GE and Fiserv. The alleged victims span several countries, although the extent of the compromise and the nature of any stolen information have not been independently verified.
Shell acknowledged it is investigating what it described as a possible cybersecurity incident.
“We are working with our security teams and relevant experts to investigate the situation,” a company spokesperson said.
Philips confirmed that it detected and contained an attempted cyberattack involving a specific enterprise server used for internal data. The healthcare technology company emphasized that customer environments were not affected by the incident.
Fiserv said it is aware of the threat actor’s claims but reported that its investigation has so far found no evidence that customer, banking, transaction or personal data was compromised. The company also said there was no indication that its operating environment had been impacted.
GE likewise confirmed it is reviewing the situation after becoming aware of the hackers’ claims.
A company spokesperson said GE has activated its cyber response procedures and is assessing the potential impact.
The Cl0p group has not disclosed details about the volume or type of information it claims to have obtained, and it did not respond to requests for comment.
Cybersecurity specialists believe the campaign may be linked to vulnerabilities in PTC’s Windchill and FlexPLM software, platforms widely used in engineering and manufacturing operations. In July, ransomware intelligence-sharing organization Ransom-ISAC warned that attackers were actively exploiting security flaws in these products.
PTC had previously published multiple security advisories urging customers to apply available patches after identifying attacks targeting vulnerabilities in its software. The company has not publicly commented on the latest claims.
According to Brandon Parsons, threat intelligence manager at Ascent Solutions and author of the Ransom-ISAC advisory, some organizations began receiving extortion notices from Cl0p around July 19 and July 20.
Parsons said the group’s strategy is to exploit newly discovered software vulnerabilities rather than focus on individual organizations, describing the attackers as “professional data extortionists.”
“They don’t really target a specific company, they target a specific zero day vulnerability and go after it,” Parsons said, referring to previously unknown software flaws before vendors have fully addressed them with security updates.
Also read: French Taxpayers’ Data Exposed in Cyberattack as Finance Ministry Investigates Scope of Breach
