Cybercrime Gang Cl0p Reveals Over 40 Victims of PTC Windchill Campaign, Exposing Sensitive Data and Intellectual Property
A recent wave of cyberattacks has left over 40 organizations reeling after the Cl0p ransomware group exploited a vulnerability in PTC’s product lifecycle management (PLM) platforms Windchill and FlexPLM. The hackers have now publicly listed the victims on their website, revealing the type and amount of sensitive data they claim to have stolen.
The exploitation of the vulnerability, tracked as CVE-2026-12569, was expected after police in Germany alerted organizations about imminent attacks. This is the first time a Windchill vulnerability has been exploited in the wild, with security firm ReliaQuest reporting that Cl0p affiliates used custom implants designed to provide “full data theft capability” without requiring additional tools.
The Cl0p gang initially only listed partial company names on their website, but on August 12 they started releasing full names. The list of alleged victims includes major players in the tech and industrial sectors, such as Shell, Philips, Fiserv, Zebra Technologies, Ingersoll Rand, and Largan Precision. Notably, GE was initially listed but has since been removed from the Cl0p website, which could indicate that the company has agreed to pay a ransom or resumed negotiations with the hackers.
The compromised files contain sensitive personal information and valuable intellectual property, including databases, project files, backups, photographs, engineering documents, blueprints, diagrams, logs, and other corporate documents. The amount of stolen information per organization ranges from 1 GB to several terabytes, according to the hackers. While much of it may be of little value and already in the public domain, the potential for significant data breaches raises alarms.
Companies such as Shell, Philips, Fiserv, and GE have confirmed that they are aware of the claims and are investigating, but none has confirmed a significant data breach. Cl0p previously conducted similar campaigns targeting vulnerabilities in Oracle E-Business Suite, MOVEit, Cleo, and GoAnywhere software.
This latest campaign serves as a reminder of the importance of prioritizing cybersecurity measures, particularly for organizations that rely on outdated or vulnerable software. PTC’s Windchill platform, specifically, has been targeted by hackers due to its potential for exploitation. As the Cl0p gang continues to name victims and extort ransoms, it is essential that affected organizations take swift action to mitigate damage and protect sensitive data.
For readers who are concerned about their organization’s security posture, a key takeaway from this incident is the importance of regular software updates and vulnerability assessments. By staying ahead of potential threats, organizations can reduce the likelihood of falling victim to cyberattacks like those perpetrated by Cl0p.
Source: SecurityWeek — 2026-08-19