A wave of cybercrime is rippling through some of the world’s biggest industrial names this month, and the fallout is still unfolding. Shell, General Electric and Philips have all confirmed they are investigating claims made by a Russian-speaking ransomware gang, while separately, five federal agencies have issued an urgent warning about a live threat to industrial control equipment made by Siemens.
The two developments are not the same incident, but together they paint a picture of an industrial sector under sustained pressure. On one front, extortionists claim to have quietly siphoned hundreds of gigabytes of sensitive engineering data from dozens of companies. On another, government cybersecurity specialists say hackers are using artificial intelligence to scan for and probe programmable logic controllers that keep factories, power plants and water systems running.
For plant operators, IT security teams and anyone tracking the growing overlap between cybercrime and critical infrastructure, the two stories underscore the same lesson: internet-exposed industrial software and hardware remain a prime target, and the window between a known flaw and active exploitation keeps shrinking.
Clop Ransomware Gang Claims Breach of Shell, GE and Philips
The cybercrime group known as Clop, believed to operate out of Russia, says it has stolen sensitive files from more than 50 organizations, including Shell, General Electric and Philips. The gang posted the claims to its dark web leak site, listing categories of stolen material that include project blueprints, facility photos, engineering drawings and internal backup files.
According to reporting from Reuters and BleepingComputer, the companies have responded with carefully worded statements rather than outright denials. Philips said it identified and contained the intrusion, telling Reuters in a statement that the incident “has no impact on customer environments.” A Shell spokesperson said the company is “aware of a potential incident” and is working with outside security experts to investigate. General Electric said it has activated its cybersecurity response process to assess the claim, though it stopped short of confirming a breach occurred.
None of the three companies has independently verified Clop’s specific figures. The gang claims it exfiltrated roughly 89 gigabytes of data from Shell, close to 391 gigabytes from GE and around 13.5 gigabytes from Philips.
| Company | Clop’s Claimed Data Volume | Company Response |
|---|---|---|
| Shell | About 89 GB | Investigating, working with security teams |
| General Electric | About 391 GB | Assessing claim via response process |
| Philips | About 13.5 GB | Confirmed contained incident, no customer impact |
The Vulnerability Behind the Attacks
Security researchers tracing the campaign point to a critical flaw in PTC’s Windchill and FlexPLM software, two widely used product lifecycle management platforms found in aerospace, automotive, defense and manufacturing environments. The flaw, tracked as CVE-2026-12569, is a remote code execution bug tied to improper handling of untrusted data, and it carries one of the highest possible severity scores.
PTC began shipping patches in mid-June and urged customers to update immediately. CISA later added the vulnerability to its Known Exploited Vulnerabilities catalog, a designation reserved for flaws confirmed to be under active attack, and gave federal agencies a short window to apply fixes.
Ransom-ISAC, an industry information-sharing group, says some of the affected organizations began receiving extortion emails from Clop-linked addresses in mid- to late July, weeks after the patch became available. Analysts describe the group’s approach as opportunistic rather than targeted, using one shared software flaw to reach dozens of unrelated companies at once.
A Familiar Playbook for Data-Theft Extortion
Clop has built a reputation over several years for a specific style of cybercrime: rather than locking up systems with traditional ransomware, the group quietly extracts data and then pressures victims by threatening to publish it. That approach mirrors the group’s earlier campaigns exploiting shared file-transfer software, which pulled in victims across finance, healthcare, government and retail.
Security professionals note that this pattern, a single vulnerability in widely deployed enterprise software, has become one of the more efficient forms of large-scale cybercrime because it lets attackers compromise many organizations through one point of failure instead of picking targets individually.
Federal Agencies Warn of Active Threat to Siemens S7 PLCs
In a separate but related development, the National Security Agency, the Cybersecurity and Infrastructure Security Agency, the FBI, the Department of Energy and the Environmental Protection Agency jointly issued a cybersecurity advisory warning that threat actors are actively targeting Siemens S7 Series programmable logic controllers that are exposed to the internet or poorly segmented from it.
The advisory, published this week, states plainly that the danger is not hypothetical. The agencies describe an ongoing campaign in which hackers use AI-generated scripts disguised as legitimate monitoring tools to scan for and probe exposed devices.
Which Siemens Models Are Affected
The advisory names several PLC families spanning both legacy and current Siemens product lines.
| Siemens PLC Series | Status |
|---|---|
| S7-200 | Legacy, targeted |
| S7-300 | Legacy, targeted |
| S7-400 | Legacy, targeted |
| S7-1200 | Current generation, targeted |
| S7-1500 | Current generation, targeted |
How the Attackers Operate
Per the advisory, hackers are using internet scanning services to locate exposed PLCs running outdated software, then deploying custom tools capable of reading and writing PLC memory, configuration data and ladder logic programs over the S7comm communications protocol. The agencies assess this as reconnaissance and capability development aimed at pre-positioning for potentially disruptive attacks against critical infrastructure.
Sectors flagged as most exposed include critical manufacturing, energy, water and wastewater systems, chemical production, and food and agriculture, with possible spillover risk into the defense industrial base.
Siemens has said it is coordinating closely with CISA on the response. A company spokesperson said the advisory does not point to any new vulnerabilities in Siemens industrial control products, but rather new techniques exploiting misconfigurations the company had already flagged in an earlier advisory.
Recommended Protective Measures
The joint advisory urges owners and operators of industrial control systems to take several concrete steps:
- Inventory every Siemens S7 PLC on the network, including model and firmware version
- Apply available security patches and firmware updates without delay
- Remove direct internet exposure and enforce network segmentation
- Monitor S7comm traffic for unauthorized read and write commands
- Report suspected compromise to CISA or the FBI
Why This Matters Beyond a Single Incident
Part of a Broader Pattern in Industrial Cybercrime
This month’s cybercrime activity does not exist in isolation. It follows earlier warnings from CISA and its partners about attacks on programmable logic controllers at public water utilities in states including Michigan, Minnesota and New Jersey, incidents that investigators have linked to Iran-backed actors. Taken together, the incidents point to a steady rise in attention from both financially motivated cybercrime groups and state-linked actors toward the operational technology that underpins power, water and manufacturing systems.
What Organizations Should Watch Next
Security researchers expect both stories to keep developing. Additional companies could be named on Clop’s leak site as the group continues to pressure victims, and further technical detail on the Siemens PLC campaign is likely as incident responders analyze compromised devices. Organizations running PTC Windchill, FlexPLM or internet-facing Siemens S7 controllers are advised to treat both advisories as active, not historical, threats and to check for indicators of compromise immediately rather than waiting for additional confirmation.



