Cybercrime Wave Hits Shell, GE, Philips as Feds Warn on Siemens PLCs

admin

A wave of cybercrime is rippling through some of the world’s biggest industrial names this month, and the fallout is still unfolding. Shell, General Electric and Philips have all confirmed they are investigating claims made by a Russian-speaking ransomware gang, while separately, five federal agencies have issued an urgent warning about a live threat to industrial control equipment made by Siemens.

The two developments are not the same incident, but together they paint a picture of an industrial sector under sustained pressure. On one front, extortionists claim to have quietly siphoned hundreds of gigabytes of sensitive engineering data from dozens of companies. On another, government cybersecurity specialists say hackers are using artificial intelligence to scan for and probe programmable logic controllers that keep factories, power plants and water systems running.

For plant operators, IT security teams and anyone tracking the growing overlap between cybercrime and critical infrastructure, the two stories underscore the same lesson: internet-exposed industrial software and hardware remain a prime target, and the window between a known flaw and active exploitation keeps shrinking.

Clop Ransomware Gang Claims Breach of Shell, GE and Philips

The cybercrime group known as Clop, believed to operate out of Russia, says it has stolen sensitive files from more than 50 organizations, including Shell, General Electric and Philips. The gang posted the claims to its dark web leak site, listing categories of stolen material that include project blueprints, facility photos, engineering drawings and internal backup files.

According to reporting from Reuters and BleepingComputer, the companies have responded with carefully worded statements rather than outright denials. Philips said it identified and contained the intrusion, telling Reuters in a statement that the incident “has no impact on customer environments.” A Shell spokesperson said the company is “aware of a potential incident” and is working with outside security experts to investigate. General Electric said it has activated its cybersecurity response process to assess the claim, though it stopped short of confirming a breach occurred.

None of the three companies has independently verified Clop’s specific figures. The gang claims it exfiltrated roughly 89 gigabytes of data from Shell, close to 391 gigabytes from GE and around 13.5 gigabytes from Philips.

Company Clop’s Claimed Data Volume Company Response
Shell About 89 GB Investigating, working with security teams
General Electric About 391 GB Assessing claim via response process
Philips About 13.5 GB Confirmed contained incident, no customer impact

The Vulnerability Behind the Attacks

Security researchers tracing the campaign point to a critical flaw in PTC’s Windchill and FlexPLM software, two widely used product lifecycle management platforms found in aerospace, automotive, defense and manufacturing environments. The flaw, tracked as CVE-2026-12569, is a remote code execution bug tied to improper handling of untrusted data, and it carries one of the highest possible severity scores.

PTC began shipping patches in mid-June and urged customers to update immediately. CISA later added the vulnerability to its Known Exploited Vulnerabilities catalog, a designation reserved for flaws confirmed to be under active attack, and gave federal agencies a short window to apply fixes.

Ransom-ISAC, an industry information-sharing group, says some of the affected organizations began receiving extortion emails from Clop-linked addresses in mid- to late July, weeks after the patch became available. Analysts describe the group’s approach as opportunistic rather than targeted, using one shared software flaw to reach dozens of unrelated companies at once.

A Familiar Playbook for Data-Theft Extortion

Clop has built a reputation over several years for a specific style of cybercrime: rather than locking up systems with traditional ransomware, the group quietly extracts data and then pressures victims by threatening to publish it. That approach mirrors the group’s earlier campaigns exploiting shared file-transfer software, which pulled in victims across finance, healthcare, government and retail.

Security professionals note that this pattern, a single vulnerability in widely deployed enterprise software, has become one of the more efficient forms of large-scale cybercrime because it lets attackers compromise many organizations through one point of failure instead of picking targets individually.

Federal Agencies Warn of Active Threat to Siemens S7 PLCs

In a separate but related development, the National Security Agency, the Cybersecurity and Infrastructure Security Agency, the FBI, the Department of Energy and the Environmental Protection Agency jointly issued a cybersecurity advisory warning that threat actors are actively targeting Siemens S7 Series programmable logic controllers that are exposed to the internet or poorly segmented from it.

The advisory, published this week, states plainly that the danger is not hypothetical. The agencies describe an ongoing campaign in which hackers use AI-generated scripts disguised as legitimate monitoring tools to scan for and probe exposed devices.

Which Siemens Models Are Affected

The advisory names several PLC families spanning both legacy and current Siemens product lines.

Siemens PLC Series Status
S7-200 Legacy, targeted
S7-300 Legacy, targeted
S7-400 Legacy, targeted
S7-1200 Current generation, targeted
S7-1500 Current generation, targeted

How the Attackers Operate

Per the advisory, hackers are using internet scanning services to locate exposed PLCs running outdated software, then deploying custom tools capable of reading and writing PLC memory, configuration data and ladder logic programs over the S7comm communications protocol. The agencies assess this as reconnaissance and capability development aimed at pre-positioning for potentially disruptive attacks against critical infrastructure.

Sectors flagged as most exposed include critical manufacturing, energy, water and wastewater systems, chemical production, and food and agriculture, with possible spillover risk into the defense industrial base.

Siemens has said it is coordinating closely with CISA on the response. A company spokesperson said the advisory does not point to any new vulnerabilities in Siemens industrial control products, but rather new techniques exploiting misconfigurations the company had already flagged in an earlier advisory.

Recommended Protective Measures

The joint advisory urges owners and operators of industrial control systems to take several concrete steps:

  • Inventory every Siemens S7 PLC on the network, including model and firmware version
  • Apply available security patches and firmware updates without delay
  • Remove direct internet exposure and enforce network segmentation
  • Monitor S7comm traffic for unauthorized read and write commands
  • Report suspected compromise to CISA or the FBI

Why This Matters Beyond a Single Incident

Part of a Broader Pattern in Industrial Cybercrime

This month’s cybercrime activity does not exist in isolation. It follows earlier warnings from CISA and its partners about attacks on programmable logic controllers at public water utilities in states including Michigan, Minnesota and New Jersey, incidents that investigators have linked to Iran-backed actors. Taken together, the incidents point to a steady rise in attention from both financially motivated cybercrime groups and state-linked actors toward the operational technology that underpins power, water and manufacturing systems.

What Organizations Should Watch Next

Security researchers expect both stories to keep developing. Additional companies could be named on Clop’s leak site as the group continues to pressure victims, and further technical detail on the Siemens PLC campaign is likely as incident responders analyze compromised devices. Organizations running PTC Windchill, FlexPLM or internet-facing Siemens S7 controllers are advised to treat both advisories as active, not historical, threats and to check for indicators of compromise immediately rather than waiting for additional confirmation.