Cl0p lists 40+ alleged victims of PTC Windchill exploit

Cl0p named more than 40 organizations it says were targeted after exploiting CVE-2026-12569 in PTC Windchill and FlexPLM, posting alleged databases, engineering files and backups.

Cl0p published full names of more than 40 organizations it says were targeted after exploiting a vulnerability in PTC’s Windchill and FlexPLM and posted alleged stolen databases, engineering files, images and backups on its leak site.

The group exploited CVE-2026-12569, an improper input validation flaw that allows a remote, unauthenticated attacker to execute arbitrary code by sending specially crafted requests. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog in June after PTC warned customers of active attacks. Security firms observed exploitation beginning in late July, and authorities in Germany warned organizations about imminent attacks before the broader reporting.

Affiliates of Cl0p used the flaw to deploy web shells that provided access to Windchill applications and allowed files to be exfiltrated. Security firm ReliaQuest reported the group has used a custom implant that maps sensitive vault data, decrypts credentials in the Windchill keystore and includes a Java class loader that can run additional code inside the application process, enabling follow-on activity such as lateral movement, ransomware or persistence.

On August 12 Cl0p began publishing full company names and details of the stolen material for more than 40 alleged victims. For each organization the group listed the types of data it claims to hold, including databases, project files, backups, photographs, engineering documents, blueprints, diagrams, logs and other corporate records. The posted estimates of data taken range from about 1 gigabyte to multiple terabytes per victim.

The list includes companies across energy, healthcare, finance, manufacturing and technology sectors. Names the group posted include Shell, Philips, Fiserv, Zebra Technologies, Ingersoll Rand, Toast, Mindray and Largan Precision. General Electric appeared on the list initially but was later removed from the site. Several named companies have acknowledged they are investigating the claims and have not confirmed large-scale data losses.

PTC urged customers to apply available patches and mitigations. Federal and local authorities have issued advisories to affected sectors. Investigations are ongoing at multiple companies and security teams are working to determine the extent of access and the potential impact on operations and confidential data.

Articles by this author