Skip to content
feed: live
>_0dayNews
ransomware
● Breaking

Clop Claims GE and Philips; Both Investigating

General Electric and Philips confirm they are investigating data theft claims from the Clop ransomware gang. Neither company has confirmed exfiltration scope, affected systems, or breach date.

Clop Claims GE and Philips; Both Investigating
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
airgapMorgan "airgap" Reyes·Published ·1 min read

Clop named both General Electric and Philips on its extortion site. Both companies confirmed they are investigating. Neither has validated the claim.

BleepingComputer reports the acknowledgments came in response to Clop’s public posting — standard Clop pressure mechanics, designed to force a response or accelerate settlement negotiations. GE and Philips are not the only organizations named in this campaign period. Breach date, attack vector, data volume, and affected divisions: none of these have been confirmed from either company.

Confidence labels

Confirmed (high): GE and Philips are actively investigating Clop’s claims. Both companies issued statements to that effect.

Confirmed (medium): This is part of a wider Clop campaign. The language of each company’s statement — and the simultaneous naming on Clop’s site — is consistent with a mass-exploitation event targeting a common platform across multiple organizations. Specific co-victims: unconfirmed.

Unconfirmed: Attack vector, breach timeline, data categories affected, whether data has been published or previewed. These details originate from Clop’s own site — treat as adversary-sourced until independently corroborated.

Who is Clop

Financially motivated extortion group, active since at least 2019. Their model: exploit a widely deployed enterprise platform (file transfer software, collaboration tools), harvest data from dozens or hundreds of organizations simultaneously, then post victim names publicly to force payment. They do not typically encrypt systems — data exfiltration and the threat of public exposure is the lever.

GE spans aerospace, power generation, and healthcare. Philips is primarily healthcare technology and consumer electronics. The sectors matter: regulated personal data, intellectual property, and operational technology environments may be involved depending on which divisions were exposed. Nothing in the current reporting confirms which assets Clop claims to hold.

What to watch

  • Official breach notifications from GE or Philips (regulatory filings or SEC disclosures if material).
  • Clop adding data previews to its leak site — a tactic the group uses to increase payment pressure.
  • Additional named victims in this campaign.
  • Any identification of the exploited platform.

Developing story. Updated as confirmed details emerge.

Found this useful? Share it.