cl0p2 articles
Cl0p Names 40+ Windchill Victims — Shell, Philips, Fiserv Among Those Called Out
The Cl0p ransomware group has named over 40 organizations as victims of a campaign exploiting CVE-2026-12569, a critical vulnerability in PTC's Windchill PLM platform that allows unauthenticated remote code execution. Attackers deployed web shells to steal data — including databases, engineering documents, and blueprints — ranging from 1 GB to several terabytes per victim, with high-profile targets including Shell, Philips, Fiserv, and Zebra Technologies. Several named companies have acknowledged the claims and launched investigations, though none has confirmed a significant breach, and GE was notably removed from Cl0p's victim list, possibly indicating ransom negotiations.
Estée Lauder Confirms Employee Data Stolen in Oracle EBS Zero-Day Attack
Estée Lauder has begun notifying employees that their personal data was stolen from its Oracle E-Business Suite (EBS) system in August 2025, when the Cl0p cybercrime group exploited a zero-day vulnerability (CVE-2025-61882) enabling unauthenticated remote code execution. The compromised data includes sensitive information such as Social Security numbers, passport numbers, bank account details, health information, and payroll data. The company is offering affected individuals 24 months of free identity monitoring and has notified law enforcement, though it has not disclosed how many people were impacted.