A Hacker Collective Claims to Have Stolen Large Amounts of Data from Shell, Philips, GE, Fiserv, And Numerous

According to a post on the group’s website, a prolific hacking group known for using software vulnerabilities to attack multiple targets at once claimed to have stolen massive amounts of data from almost 50 companies worldwide, including Philips (PHG.AS), Shell (SHEL.L), Fiserv (FISV.O), and GE (GE.N).
Shell confirmed an earlier claim on Thursday by Dutch media site BNR that it was aware of a recent “possible incident,” while Philips acknowledged it had been targeted by Cl0p.”We are investigating the situation with our security teams and pertinent experts,” a Shell representative stated.
In a statement, Philips stated, “Philips has identified and contained an attempted cybersecurity compromise of a specific enterprise server related to internal data,” adding that client environments are unaffected.
According to a Fiserv representative, the business is aware of the threat actor’s allegations, but “based on our comprehensive review to date” it had not discovered any proof that its operational environment or customer, financial, transaction, or personal data had been compromised.
According to a GE representative, the corporation has “initiated our cyber response protocols and are working to assess the potential issue.”
Reuters was unable to independently confirm the hacking group’s assertions about the type and quantity of data it pilfered. A request for comment was not answered by the hackers.
Ransom-ISAC, an industry information sharing group, released a notice on July 22 that warned that the hacking group was taking advantage of flaws in PTC Windchill and FlexPLM, software used to support engineering and manufacturing processes, tho it’s unclear how the hackers allegedly gained access to the businesses.
A request for comment was not immediately answered by Boston-based PTC. Since June 18, the company has sent out many security notifications on its website, requesting users to apply a patch for a vulnerability and providing information about an unidentified attacker targeting its goods.
