2026 Philips — confirms contained internal-server incident after Clop Windchill claims; no customer impact
Data compromised
Philips: specific enterprise server related to internal data; no impact on customer environments per company. Clop claims of backups/projects/drawings remain actor-side. No attested individual census — recordsAffected 0.
Technical writeup
Company-confirmed contained incident — August 17, 2026 BleepingComputer citing a Philips statement also shared with Reuters. Philips “identified and contained an attempted cybersecurity compromise of a specific enterprise server related to internal data” and said it had no impact on customer environments. Clop had listed Philips with Shell and GE in the Windchill/FlexPLM CVE-2026-12569 theft wave. Distinct from prior Philips Respironics / MOVEit rows. recordsAffected 0 (no individual census). BreachHistory sets companyConfirmed true.
Root cause
Clop listed Philips in PTC Windchill / FlexPLM (CVE-2026-12569) wave; Philips says it identified and contained an attempted compromise of a specific enterprise server holding internal data
References
- https://www.bleepingcomputer.com/news/security/philips-and-ge-investigating-clop-ransomware-data-theft-claims/
- https://www.reuters.com/legal/government/philips-shell-targeted-by-hacking-group-2026-08-13/
- https://www.bleepingcomputer.com/news/security/clop-ransomware-targets-windchill-flexplm-in-data-theft-attacks/