← BACK TO FEED
Cl0pransomwarePTC WindchillCVE-2026-12569data extortion

Cl0p Names 40+ Windchill Victims — Shell, Philips, Fiserv Among Those Called Out

The Cl0p ransomware group has named over 40 organizations as victims of a campaign exploiting CVE-2026-12569, a critical vulnerability in PTC's Windchill PLM platform that allows unauthenticated remote code execution. Attackers deployed web shells to steal data — including databases, engineering documents, and blueprints — ranging from 1 GB to several terabytes per victim, with high-profile targets including Shell, Philips, Fiserv, and Zebra Technologies. Several named companies have acknowledged the claims and launched investigations, though none has confirmed a significant breach, and GE was notably removed from Cl0p's victim list, possibly indicating ransom negotiations.

The Cl0p ransomware crew has published a list of more than 40 organisations it claims to have compromised through a vulnerability in PTC's Windchill and FlexPLM product lifecycle management software. Some big names are on that list, and not all of them are being particularly forthcoming about what happened.

The underlying flaw, CVE-2026-12569, is an improper input validation bug that lets an unauthenticated remote attacker run arbitrary code by sending crafted requests to the platform. CISA added it to its Known Exploited Vulnerabilities catalog in June, around the same time PTC warned customers that active exploitation was underway. German police apparently got wind of imminent attacks and started notifying organisations at risk. For what it's worth, this is the first Windchill vulnerability ever confirmed exploited in the wild.

By late July, security researchers had tied the exploitation directly to Cl0p. The group's method of choice was deploying web shells to gain persistent access to Windchill environments, but a report published Tuesday by ReliaQuest paints a more troubling picture. Cl0p wasn't just dropping a basic web shell and poking around. According to ReliaQuest, the group used a custom implant with a built-in Java class loader capable of executing arbitrary code inside the application process itself. It mapped vault data, decrypted credentials from the Windchill keystore, and effectively turned the initial foothold into an open-ended backdoor. Lateral movement, ransomware deployment, long-term persistence — all on the table.

Cl0p initially listed victims using partial names, presumably as a pressure tactic. On 12 August it started dropping full company names. The disclosed victims now include Shell, Philips, Fiserv, Zebra Technologies, Ingersoll Rand, Toast, Mindray, and Apple camera lens supplier Largan Precision, among others.

For each named organisation, Cl0p has specified what was taken and how much of it. The data types reportedly include databases, engineering documents, blueprints, project files, corporate backups, photographs, and assorted logs. Volume varies wildly, from around 1GB up to several terabytes depending on the target. Whether any of it represents genuinely sensitive intellectual property or is largely mundane internal data is another matter — which may explain why many of these companies appear to have declined to pay.

GE appeared on the list early on but has since been removed, which in Cl0p's world typically signals either a ransom payment or resumed negotiations. No confirmation from GE either way.

Shell, Philips, and Fiserv have all acknowledged the claims and said they're investigating. None has confirmed a material breach. That holding pattern is fairly standard at this stage — say little, admit nothing, keep lawyers busy.

This follows an established playbook for Cl0p. The group has run near-identical mass-exploitation campaigns against Oracle E-Business Suite, MOVEit Transfer, Cleo, and GoAnywhere over the past few years. Find a high-value enterprise platform with a critical unauthenticated flaw, hit as many targets as possible before patches roll out, then extort the lot. It works often enough to keep them doing it.

READ NEXT
Estée Lauder Confirms Employee Data Stolen in Oracle EBS Zero-Day AttackNearly 2,000 Hacked WordPress Sites Are Powering a Surprisingly Sophisticated Criminal OperationMeet Ransom Busters: The Ransomware Affiliate Posing as Your Rescuer While Charging $60K for the Privilege