Hackers exploit PLMs in recent cyberattacks at Shell, GE, Philips
Key Highlights
- Hackers exploited a flaw in process lifecycle management tools used by manufacturers.
- Shell, GE, and Philips were among the approximate 43 companies that were attacked.
- Experts say slow reporting and patching of complex systems leaves manufacturers vulnerable.
Hackers, reportedly from ransomware cybercriminal gang Clop, broke into product lifecycle management tools commonly used by manufacturers in recent attacks at Shell, GE, and Philips that exploited vulnerabilities in PLM software from vendor PTC.
GE and Philips confirmed investigating data breaches purportedly at the hands of Clop. Shell confirmed Aug. 14 it also had been attacked, again supposedly by Clop. The vulnerabilities in the two PTC software packages, Windchill and FlexPLM, were known.
See also: Attack chain glue: How one form of AI is hypercharging cyberattacks on manufacturing
The ransomware gang, on its dark Web site, claimed to have stolen data, including diagrams, blueprints and project plans, from 43 companies in total, likely targeted in data theft attacks exploiting a critical improper input validation vulnerability (tracked as CVE-2026-12569) against internet-connected PTC Windchill and PTC FlexPLM, according to BleepingComputer.
PTC in mid-June began releasing security patches for the software to close the vulnerability and urged customers to update their versions immediately.
The U.S. Cybersecurity and Infrastructure Agency on June 25 confirmed the existence of the vulnerability and mandated that federal agencies patch all instances of Windchill and FlexPLM within three days of the announcement.
Philips told Reuters the breach did not “impact customer environments.”
There is evidence that attackers were exploiting these PTC environments before defenders had the full benefit of the public warning and remediation process.
- Ensar Seker, CISO at cybersecurity company SOCRadar
PTC said the two enterprise software platforms are widely used by high-profile companies across the aerospace, defense, automotive, heavy machinery, retail, and medtech sectors. The company said more than 30,000 customers globally use its products, including over 1,500 brand and retail customers using FlexPLM.
See also: Implementing a true approach to PLM, the cornerstone of manufacturing
In these attacks, Clop claims it stole a wide range of sensitive data from the companies' compromised systems, including backups, project plans, photos of facilities, drawings, diagrams, blueprints, and more, belonging to Shell, GE, and Philips, according to Bleeping Computer.
The ransomware group claimed it stole it stole 89GB of data from Shell.
Warning, patches came too late to stop attacks
BleepingComputer also reported that some of the tools used by the Clop ransomware gang were specifically designed to breach PTC Windchill and FlexPLM servers, based on detailed knowledge of Windchill's functionalities.
“First, there is evidence that attackers were exploiting these PTC environments before defenders had the full benefit of the public warning and remediation process,” said Ensar Seker, chief information security officer at cybersecurity company SOCRadar.
Second, he stressed, “a patch was released” does not necessarily mean that every version of a complex enterprise platform could immediately receive it. PTC’s remediation was released in stages across different Windchill and FlexPLM versions.
Large manufacturers also can have many instances, different versions, integrations with engineering and manufacturing systems, and strict testing and availability requirements. Knowing about a vulnerability and safely remediating every affected instance across a global enterprise are two different problems.
See also: Black Kite: Ransomware increasing across all metrics in 2026
Cyberattacks against manufacturing operations are hardly new, but AI is rapidly changing how quickly attackers can identify targets, find vulnerabilities, and exploit them.
At the same time, manufacturers are taking advantage of connectivity between IT and OT systems, adopting cloud-based tools, and enabling remote access to plant-floor assets. That connectivity exposes systems that do not have up-to-date cyber defenses to possible attack.
In theory, organizations of this size ... should be able to patch or mitigate a critical vulnerability within hours. In practice, many simply cannot.
- Adam Arellano, field CTO with Harness
New pathways for hackers have been provided to critical systems such as PLCs, HMIs, drives, and other industrial controls.
In April, CISA issued a warning that cyber actors were specifically targeting OT devices, including PLCs. Hackers are looking to quickly exploit exposed controllers, poorly segmented networks, or unsecured remote access tools.
According to one expert, companies are not always able to patch advised vulnerabilities.
“The word ‘should’ is doing a lot of work here. In theory, organizations of this size, particularly those operating critical infrastructure, should be able to patch or mitigate a critical vulnerability within hours. In practice, many simply cannot,” said Adam Arellano, field chief technology officer with AI-based automation company Harness.
“There are several reasons for that. They may be running decades-old technology that cannot be easily updated, dealing with regulatory or operational constraints that make downtime difficult or lacking the leadership alignment needed to prioritize modernization. Together, these factors create a perfect storm in which even a well-publicized vulnerability may remain unpatched."
Arellano added: “I can’t speak to the specific environments at GE or Philips, but for many organizations of comparable size and complexity, patching cycles can take a month or longer, even for relatively modern applications. They may also have end-of-life systems that are no longer supported or patchable but continue to underpin critical business operations.
"The answer is partly technological, but it is ultimately a leadership issue. Organizations must be willing to modernize legacy environments, identify systems that cannot be patched, and put compensating controls in place. That urgency will only grow as AI allows attackers to identify and exploit vulnerabilities more quickly and at greater scale.”
About the Author
Sarah Mattalian
Staff Writer
Sarah Mattalian is a Chicago-based journalist writing for Smart Industry and Automation World, two brands of Endeavor Business Media, covering industry trends and manufacturing technology. In 2025, she graduated with a master's degree in journalism from Northwestern University's Medill School of Journalism, specializing in health, environment and science reporting. She does freelance work as well, covering public health and the environment in Chicagoland and in the Midwest. Her work has appeared in Inside Climate News, Inside Washington Publishers, NBC4 in Washington, D.C., The Durango Herald and North Jersey Daily News. She has a translation certificate in Spanish.
Dennis Scimeca
Dennis Scimeca is a veteran technology journalist with particular experience in vision system technology, machine learning/artificial intelligence, virtual and augmented reality, and interactive entertainment. He has experience writing for consumer, developer, and B2B audiences with bylines in many highly regarded specialist and mainstream outlets.
His home base is IndustryWeek, where he covers the continuing expansion of new technologies into the manufacturing world and the competitive advantages gained by learning and employing these new tools. He also seeks to build connections between manufacturers by sharing the stories of their challenges and successes employing new technologies. If you would like to share your story with IndustryWeek, please contact him at [email protected].


