Overview
- The hacking group posted its list of alleged victims on August 12 and said it stole files from about 50 companies, prompting media reports and rapid company responses.
- Philips said it identified and contained an attempted compromise of an enterprise server tied to internal data, while Shell confirmed a possible incident and launched an investigation.
- Fiserv said its review found no evidence that customer, banking, transaction, or personal data was exposed and that its operating environment was unaffected.
- Industry alerts from Ransom‑ISAC and security researchers tied the activity to vulnerabilities in PTC Windchill and FlexPLM, software used to store engineering drawings and manufacturing plans.
- Cl0p has not released any sample files and news agencies could not verify the group's claims, leaving the alleged scale of data theft unconfirmed and urging firms to patch and investigate their systems.