Soft ComputersBook a free IT assessmentBook assessment

Clop Ransomware Hit Philips and GE. Your Backups Are the Only Thing That Saves You.

Backup & Recovery5 min readBy the Soft Computers Team

Philips and GE are both investigating claims that the Clop ransomware gang stole data from their systems. BleepingComputer reported this on August 17, 2026. These are not small companies with patchy IT. These are two of the largest industrial and healthcare technology corporations on the planet, and Clop got in anyway.

Clop is not new. This group has been behind some of the largest ransomware and data extortion campaigns in recent years, including attacks that exploited file transfer tools like MOVEit. Their playbook is consistent: find a vulnerability in widely used software, steal as much data as possible before anyone notices, and then threaten to publish it unless victims pay.

The Philips and GE situation is still under investigation, so we do not yet know the full scope of what was taken. But the pattern is familiar enough that every Canadian business owner should be paying attention right now.

Why This Matters If You Run a Canadian SMB

A lot of small and mid-sized business owners see a headline like this and think it does not apply to them. Clop goes after big targets. That is true sometimes. But the tools and techniques Clop uses eventually get copied, adapted, and sold to lower-tier criminal groups who do go after smaller businesses.

More directly: if your business shares data with a larger company or uses the same third-party software platforms they do, you can be caught in the same net. Supply chain attacks work exactly this way. Clop's MOVEit campaign in 2023 hit hundreds of organizations that had nothing obvious in common except that they all used the same file transfer product.

The hard question is not whether ransomware groups will ever target businesses like yours. It is whether you could recover if they did.

What Clop Actually Does to Your Data

Most people imagine ransomware as a lock on their files. Pay the key, get access back. That is an outdated picture. Clop and groups like them operate on a double extortion model. They steal your data first, then encrypt it. Even if you restore from backup and never pay a cent, they still have copies of your files and can publish them or sell them.

This means backup and recovery is not the whole answer. But it is still the foundation. Without a solid backup, you cannot recover your systems at all. With a solid backup, you at least keep your operations running while you deal with the breach. That distinction matters enormously when you are trying to stay open for business and serve your customers.

What We See Going Wrong with SMB Backups

When we assess backup setups at Canadian SMBs, we run into the same problems repeatedly.

  • Backups stored on the same network as production systems. Ransomware encrypts everything it can reach. If your backup drive is attached to the same server that gets hit, it gets encrypted too.
  • Backups that have never been tested. A backup you have never restored from is a guess, not a guarantee. We have seen businesses discover mid-incident that their backups were corrupted or incomplete.
  • No offsite or cloud copy. A fire, flood, or theft in your office takes out both your primary systems and your local backup at the same time.
  • Recovery time nobody has calculated. Even with clean backups, some businesses find it takes three to five days to fully restore operations. If you have never measured that, you are guessing at a number that directly affects your revenue.

What a Solid Backup Setup Actually Looks Like

The standard we recommend for Canadian SMBs follows the 3-2-1-1 model. Three copies of your data, on two different media types, with one copy offsite and one copy air-gapped or immutable. An immutable backup is one that cannot be modified or deleted, even by someone with admin credentials, for a defined period of time. That last part is what defeats double extortion at the recovery level.

For most businesses we work with, this means a combination of local backup appliances (we use solutions like Acronis or Veeam depending on the environment) paired with encrypted cloud replication to Canadian data centres. Keeping data on Canadian soil matters for privacy law compliance, particularly if you handle health information or financial records.

Beyond the architecture, the piece most businesses skip is the recovery test. We run scheduled restore tests for our managed clients, typically quarterly, and document the actual time it takes to bring systems back online. That number becomes the recovery time objective (RTO) that owners can plan around.

What to Do This Week

You do not need to wait for an incident to find out whether your backups work. Ask your IT provider or internal team three specific questions: Where are your backups stored right now? When was the last time a full restore was actually tested? And how long would it take to be fully operational again if your main server were encrypted at 9am on a Tuesday?

If you get vague answers, or if nobody has tested a restore in the last six months, that is the gap Clop and groups like them exploit.

We offer a backup and recovery assessment for Canadian SMBs. We look at what you have, test it, and give you a plain-language report on where the risks are. If you want to know where you actually stand, get in touch with our team.

Want this level of attention on your IT?

We publish what we practice. Book a free assessment and see where your environment stands: what is solid, what is aging, and what is at risk.