← BACK TO FEED
TAG

data extortion2 articles

Cl0p Names 40+ Windchill Victims — Shell, Philips, Fiserv Among Those Called Out

The Cl0p ransomware group has named over 40 organizations as victims of a campaign exploiting CVE-2026-12569, a critical vulnerability in PTC's Windchill PLM platform that allows unauthenticated remote code execution. Attackers deployed web shells to steal data — including databases, engineering documents, and blueprints — ranging from 1 GB to several terabytes per victim, with high-profile targets including Shell, Philips, Fiserv, and Zebra Technologies. Several named companies have acknowledged the claims and launched investigations, though none has confirmed a significant breach, and GE was notably removed from Cl0p's victim list, possibly indicating ransom negotiations.

20 Aug 2026

Fake IT Support Calls Are How This Gang Walks Into Law Firms and Walks Out With Everything

The Silent Ransom Group (also tracked as UNC3753/Luna Moth) is actively targeting U.S. law firms and professional services organisations using social engineering tactics, including fake IT support phone calls that trick employees into installing remote access tools, enabling data theft within hours. Once inside a network, attackers steal sensitive legal and financial documents before sending highly aggressive ransom demands — sometimes within 30 minutes of exiting the victim's environment — threatening to notify clients and regulators if payment is not made. Cybersecurity firm Mandiant and the FBI recommend organisations counter these attacks by enforcing strict IT verification procedures, limiting remote access tools, implementing multi-factor authentication, and training staff to recognise voice phishing attempts.

26 Jun 2026