Cl0p Ransomware Group Targets Over 40 Organizations with Sophisticated Windchill Campaign
A sophisticated ransomware campaign launched by the Cl0p gang has compromised over 40 organizations worldwide, exploiting a critical vulnerability in PTC’s product lifecycle management (PLM) platforms Windchill and FlexPLM. The attack not only enables arbitrary code execution but also provides full data theft capability without requiring additional tools.
The exploitation of the CVE-2026-12569 vulnerability, an improper input validation issue, was expected given its severity and the warning issued by PTC in June. However, it’s surprising that this is the first ever Windchill vulnerability to be exploited in the wild. As reported by SecurityWeek earlier this month, Cl0p affiliates were seen delivering web shells that granted them access to sensitive data of organizations using Windchill.
According to a report from security firm ReliaQuest, Cl0p has been utilizing a custom implant designed to map sensitive vault data, decrypt credentials in the Windchill keystore, and execute any additional code inside the application process. This level of sophistication allows the attackers to achieve an unlimited backdoor for follow-on activities such as lateral movement, ransomware, or persistence.
The list of alleged victims includes major corporations like Shell, Philips, Fiserv, Zebra Technologies, Ingersoll Rand, Toast, Mindray, and Largan Precision. Notably, GE was initially listed but has since been removed from the Cl0p website, which could indicate that the company has agreed to pay a ransom or is in negotiations with the hackers.
While some companies like Shell, Philips, Fiserv, and GE have acknowledged awareness of the claims and are investigating, none has confirmed a significant data breach. It’s worth noting that much of the exfiltrated data may be of little value and already in the public domain, which could explain why many targeted organizations have refused to pay a ransom.
Cl0p is no stranger to sophisticated attacks. The group previously conducted similar data theft and extortion campaigns targeting vulnerabilities in Oracle E-Business Suite, MOVEit, Cleo, and GoAnywhere software. This latest campaign highlights the importance of proper vulnerability patching, robust security measures, and regular backups to prevent such devastating attacks.
As a result, organizations should prioritize updating their Windchill and FlexPLM platforms to the latest versions and implement multi-factor authentication, network segmentation, and robust logging to detect any suspicious activity. Furthermore, it’s crucial for companies to have an incident response plan in place to quickly respond to and contain potential security breaches. By being proactive and vigilant, organizations can minimize their exposure to such attacks and protect their sensitive data from falling into the wrong hands.
Source: SecurityWeek — 2026-08-19