# Clop lists General Electric as ransomware victim

Published: 2026-08-12 · Severity: high · Sectors: manufacturing, energy, healthcare
Canonical: https://vorant.io/reports/98864d55-5ae6-51eb-bc41-5bedf7c628f2/clop-lists-general-electric-as-ransomware-victim

> The Clop ransomware group claims to have breached General Electric, listing the industrial conglomerate on its leak site.

Ransomware.live has recorded a new Clop ransomware group listing naming General Electric (GE), the American multinational conglomerate with operations spanning aviation, healthcare, and energy sectors, as a victim. The entry was discovered on August 12, 2026, with the claimed attack date on the same day, indicating a recent leak-site posting rather than a long-dormant claim.

The listing itself contains no technical detail on the intrusion vector, exfiltrated data, or ransom demands beyond standard DNS/WHOIS reconnaissance data and third-party SaaS domain-verification records associated with GE's domain (Proofpoint mail routing, Atlassian, DocuSign, Adobe, Cisco, Smartsheet, and similar services). These records are typical infrastructure metadata rather than evidence of compromise and do not confirm the scope or veracity of Clop's claim. As with most leak-site listings, independent verification of the breach and any stolen data has not been established at this time.

Clop is a long-running ransomware/extortion operation known for exploiting file-transfer and enterprise software vulnerabilities (e.g., Accellion FTA, GoAnywhere MFT, MOVEit Transfer) for mass data-theft extortion campaigns. Given GE's footprint across critical manufacturing, energy, healthcare, and defense-adjacent sectors, a confirmed breach would carry significant downstream risk, but at this stage the claim should be treated as unverified.

## Mentioned in this report

- Threat actors: Clop
- Malware: Clop

Source reporting: https://www.ransomware.live/id/R0UuQ09NQGNsb3A=

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/98864d55-5ae6-51eb-bc41-5bedf7c628f2/clop-lists-general-electric-as-ransomware-victim.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
