The cybercriminal group Cl0p claims to have stolen data from nearly fifty organizations worldwide. The list includes Philips, Shell, payment service provider Fiserv, and GE. Several companies have confirmed that they are investigating a potential incident, but the extent of the alleged data theft remains unclear.
Philips confirmed to Reuters that Cl0p attempted to breach a specific corporate server containing internal data. The company says it detected and contained the attack. Customer environments were reportedly not affected.
Shell is also investigating a potential security incident. The energy company says it is working with internal security teams and external experts on the matter. GE has activated its cyber incident procedures and is investigating Cl0p’s claim.
Fiserv states that, based on its own investigation, it has not yet found any evidence that customer data, banking information, transaction data, or personal information was compromised. The company’s operational environment is also reportedly unaffected.
Possible exploitation of PTC software
It has not yet been determined how Cl0p may have gained access to the various organizations. However, there is a possible link to vulnerabilities in PTC Windchill and FlexPLM, software widely used in engineering and manufacturing.
On July 22, Ransom-ISAC warned that Cl0p was actively exploiting vulnerabilities in this software. Starting on June 18, PTC published several security advisories and urged customers to install patches. The company also reported attacks on its products by an unnamed attacker.
According to Brandon Parsons, threat intelligence manager at Ascent Solutions, some affected organizations received messages from Cl0p around July 19 and 20. This modus operandi is consistent with the group’s previous campaigns: rather than targeting individual companies, Cl0p searches for vulnerabilities in widely used software that can affect many organizations simultaneously.
Reuters was unable to independently verify what data Cl0p actually stole or how much data was involved. The hackers did not respond to questions from the news agency.