Philips A.I CyberSecurity Scoring
Philips
Company Information
Website:https://www.philips.com/a-w/about.html
Employees number:74,403
Number of followers:3,015,325
NAICS:62
Industry Type:Hospitals and Health Care
Homepage:philips.com
Philips Risk Score (AI oriented)
Between 600 and 649
PhilipsHospitals and Health Care
Updated:
14/08/2026
14/08/2026
624/1000
Poor
Caa
Philips Global Score (TPRM)
xxxx
PhilipsHospitals and Health Care
Score locked

PhilipsPoor
Current Score
624Caa (POOR)
01000
4 incidents
-49.33 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
OCTOBER 2026
622
SEPTEMBER 2026
623
AUGUST 2026
707
Ransomware
13 Aug 2026 • Philips
Philips and Shell: Russian ransomware group Clop claims cyberattacks on Shell and Philips
Clop Ransomware Group Claims Attacks on Shell and Philips
622
CRITICAL-85
PHISHE1786703569
Clop Ransomware Group Claims Attacks on Shell and Philips
The Russian ransomware group Clop has taken responsibility for recent cyberattacks on energy giant Shell and healthcare technology firm Philips. Both companies confirmed experiencing security incidents following reports of the claims.
Shell acknowledged a "potential incident" and stated that an investigation is underway with security teams and external experts. Philips described the attack as an "attempted cyberattack on a specific company server containing internal data," adding that the situation has been contained with no impact on customer environments.
Clop, known for extorting victims by stealing sensitive data, allegedly exfiltrated 89 gigabytes of Shell’s data, including technical drawings, facility images, test reports, and project plans. The group also claims to have obtained 13.5 gigabytes of Philips’ data, containing diagrams and blueprints. However, these claims sourced from the hackers themselves remain unverified by independent parties.
This is not the first time Clop has targeted Shell. In 2023, the group exploited a vulnerability in the MOVEit Transfer file-sharing software, breaching Shell and multiple other organizations. After Shell refused to pay a ransom, Clop publicly leaked stolen files on its dark web leak site.
The full extent of the damage from the latest attacks is still under investigation.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JULY 2026
708
JUNE 2026
707
MAY 2026
702
APRIL 2026
701
MARCH 2026
702
Vulnerability
25 Mar 2026 • Philips
PTC: PTC Warns of Critical Windchill, FlexPLM Flaw Enabling Remote Code Execution
Critical RCE Vulnerability in PTC Windchill and FlexPLM Exposes Systems to Attack
698
CRITICAL-4
PTC1774441546
Critical RCE Vulnerability in PTC Windchill and FlexPLM Exposes Systems to Attack
PTC has issued an urgent advisory warning of a severe Remote Code Execution (RCE) vulnerability (CVE-2026-4681) affecting its Windchill PDMLink and FlexPLM platforms. The flaw, classified as a code injection vulnerability (CWE-94), carries a CVSS v3.1 score of 10.0 and a CVSS v4 score of 9.3, indicating maximum severity.
### Affected Versions
The vulnerability impacts multiple releases, including:
- Windchill PDMLink: Versions 11.0 M030 through 13.1.3.0
- FlexPLM: Versions 11.0 M030 through 13.0.3.0
- All CPS versions prior to 11.0 M030 are also vulnerable.
PTC has confirmed no evidence of active exploitation but warns that the flaw poses a critical risk, particularly for publicly accessible instances.
### Exploitation Mechanism
The vulnerability stems from improper handling of deserialized, untrusted data, allowing attackers to execute arbitrary code and potentially gain full system control. While internet-exposed deployments are at highest risk, PTC advises applying mitigations to all installations.
### Mitigation Steps
Until official patches are released, PTC recommends the following workarounds:
#### Apache HTTP Server
- Create a configuration file (`90-app-Windchill-Auth.conf`) in `<APACHE_HOME>/conf/conf.d/` with the directive:
```apache
<LocationMatch “^.servlet/(WindchillGW|WindchillAuthGW)/com.ptc.wvs.server.publish.Publish(?:;[^/])?/.*$”>
Require all denied
```
- Ensure the file loads last and restart Apache.
#### Microsoft IIS
- Verify the URL Rewrite module is installed.
- Modify `web.config` to include the rewrite rule as the first tag under `<system.webServer>`.
- Restart IIS via `iisreset` and confirm the rule is active.
PTC notes that File Server or Replica Server configurations may require adjusted steps, and older releases could need additional modifications.
For organizations unable to implement mitigations immediately, PTC suggests shutting down services or disconnecting systems from the internet.
### Indicators of Compromise (IOCs)
Security teams should monitor for:
- Network patterns:
- Suspicious User-Agent: `Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36`
- Malicious HTTP requests: `run?p= .jsp?p=`, `run?c= .jsp?c=`
- File system artifacts:
- `GW.class` or `payload.bin` (SHA256: `C818011CAFF82272F8CC50B670304748984350485383EBAD5206D507A4B44FF1`)
- `dpr_<8-hex-digits>.jsp` or other suspicious `.class` files (e.g., `Gen.class`, `HTTPRequest.class`).
- Log anomalies:
- Messages containing `GW_READY_OK`, `ClassNotFoundException for GW Windchill`, or `HTTP Gateway Exception`.
PTC has deployed the Apache workaround for all cloud-hosted customers and is providing 24×7 support for affected users. Organizations detecting IOCs are urged to initiate incident response protocols.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
FEBRUARY 2026
760
Breach
12 Feb 2026 • Philips
Odido: Stolen Odido data worth “gold” for criminals
Massive Data Breach at Dutch Telecom Provider Odido Exposes 6.2 Million Accounts
701
CRITICAL-59
ODI1771093701
Massive Data Breach at Dutch Telecom Provider Odido Exposes 6.2 Million Accounts
Dutch telecom provider Odido has reported one of the largest data breaches in the Netherlands, with sensitive information from 6.2 million customer accounts compromised. The company began notifying affected users on Thursday at 12 p.m., though the exact number of impacted individuals remains unclear as the investigation continues.
The stolen data varies by account but may include full names, addresses, phone numbers, email addresses, IBAN bank account numbers, dates of birth, and passport or driver’s license numbers a combination cybersecurity experts describe as unusually valuable for criminals. Notably, passwords, call logs, location data, billing details, and ID document scans were not accessed.
Ethical hacker Sijmen Ruwhof warned that the breach poses severe risks, including highly convincing phishing attacks where criminals use real customer details to impersonate legitimate companies. Fraudsters could also exploit the data to bypass authentication checks, taking out contracts or committing financial fraud in victims’ names. Matthijs Koot, another security expert, highlighted the risk of helpdesk fraud, bank scams, and targeted espionage, noting that hostile intelligence services could use the data to track politicians, government employees, or critical infrastructure workers.
The breach also raises concerns about stalking, doxxing, and organized crime, as criminals including drug offenders could use the data to identify individuals using regular phone subscriptions. Ruwhof criticized Odido’s security measures, stating that the scale of the leak suggests a failure in cybersecurity controls at the time of the incident. While the company has not disclosed whether hackers made ransom demands, experts warn the data could be sold or used for extortion.
Odido CEO Tisha van Lammeren emphasized that notifications were delayed to avoid misinformation but did not comment on the adequacy of the company’s security. She acknowledged the sophistication of cybercriminals while reiterating that customer safety remains the top priority. The full impact of the breach is still under assessment.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
760
DECEMBER 2025
756
NOVEMBER 2025
756
JUNE 2023
808
Ransomware
31 May 2023 • Philips
Philips Respironics, Inc.
Rotech Healthcare Data Breach
720
CRITICAL-88
PHI258072525
On June 3, 2024, the Washington State Office of the Attorney General reported a data breach involving Rotech Healthcare (Philips Respironics, Inc.) that occurred on May 31, 2023. The breach, identified as a cyberattack involving ransomware, affected approximately 2,802 individuals and potentially compromised personal information including name, full date of birth, health insurance policy or ID number, medical information, and other unspecified data.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Philips ??
What was Philips's A.I Rankiteo Cyber Score in September 2026 ??
What was Philips's A.I Rankiteo Cyber Score in August 2026 ??
What was Philips's A.I Rankiteo Cyber Score in July 2026 ??
What was Philips's A.I Rankiteo Cyber Score in June 2026 ??
What was Philips's A.I Rankiteo Cyber Score in May 2026 ??
What was Philips's A.I Rankiteo Cyber Score in April 2026 ??
What was Philips's A.I Rankiteo Cyber Score in March 2026 ??
What was Philips's A.I Rankiteo Cyber Score in February 2026 ??
What was Philips's A.I Rankiteo Cyber Score in January 2026 ??
What was Philips's A.I Rankiteo Cyber Score in December 2025 ??
What was Philips's A.I Rankiteo Cyber Score in November 2025 ??
What is the average per-incident point impact on Philips's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Philips ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Philips's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?