← General Electric

2026 General Electric — investigating Clop Windchill/FlexPLM data-theft claims

2026 Unknown records affected Share on X

Data compromised

Clop claims include backups, projects, drawings, diagrams, blueprints. No attested individual census — recordsAffected 0. Scope unverified pending GE assessment.

Technical writeup

Company-confirmed investigation after Clop claim — August 17, 2026. BleepingComputer reported a GE spokesperson saying the company is aware of the claim and “working to assess the potential issue,” alongside Shell’s earlier “potential incident” investigation and Philips’ contained-server statement. Clop listed the firms among ~43 new victims tied to Internet-exposed PTC Windchill/FlexPLM (CVE-2026-12569). Actor descriptions of stolen projects, drawings, and blueprints remain unverified as to GE’s attested inventory. recordsAffected 0 pending a personal-data census. BreachHistory sets companyConfirmed true for the investigation, matching the Shell row pattern.

Root cause

Clop leak-site listing in PTC Windchill / FlexPLM (CVE-2026-12569) data-theft wave; GE says it is aware and assessing the potential issue

References