The Cl0p ransomware group has publicly named more than 40 organizations it allegedly targeted in a campaign focused on PTC product lifecycle management (PLM) platforms. According to the claims, the attackers exploited a vulnerability affecting PTC Windchill and FlexPLM, and then used the access to steal and potentially stage data for extortion.
Below, we summarize what’s been reported about the Cl0p Windchill victims, the vulnerability involved, how exploitation works, and which kinds of files and environments are said to be impacted.
Cl0p Windchill victims named in stages
Initially, Cl0p listed only partial company names on its leak and extortion site. On August 12, the group began posting full names of alleged victims, and more than 40 organizations have been included to date for the Windchill-focused operation.
For each entry, the attackers reportedly included the category and estimated volume of data they claim to have exfiltrated. Those details vary widely from organization to organization.
The vulnerability behind the campaign: CVE-2026-12569
The operation is tied to a security flaw tracked as CVE-2026-12569. The issue came into clearer public focus in June, when the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog.
At the same time, the vendor warned of active attacks attempting to leverage the weakness. The root cause is described as an improper input validation problem, meaning specially crafted requests can push the application beyond intended limits.
Critically, the vulnerability enables a remote, unauthenticated attacker to trigger arbitrary code execution. In practice, that kind of access can allow attackers to run code in the context of the application process, making follow-on intrusions and data collection much easier.
First Windchill vulnerability exploited in the wild
Reporting indicates that CVE-2026-12569 is the first Windchill vulnerability believed to be exploited in the wild. In Germany, law enforcement reportedly alerted organizations about imminent attacks, reflecting that exploitation was expected rather than hypothetical.
How Cl0p used Windchill access
Security reporting in late July described exploitation of the PLM flaw in attacks attributed to Cl0p. In these intrusions, affiliates reportedly used the weakness to deliver web shells, which then provided access to sensitive data stored or managed by Windchill installations.
ReliaQuest described that Cl0p has used a custom implant designed to support “full data theft capability” without requiring additional tools. The description emphasizes a workflow that goes beyond simple browsing or file extraction.
As explained by ReliaQuest, the web shell is said to:
- Map sensitive vault data
- Decrypt credentials in the Windchill keystore
- Include a custom Java class loader to execute additional code inside the application process
That combination reportedly turns the web shell into a broader backdoor for later actions. The reported follow-on activities include lateral movement, ransomware, or persistence.
What data Cl0p claims to have stolen
Cl0p’s postings for alleged Windchill victims include details about the type and size of stolen data. The categories reported include databases, project files, backups, photographs and other images, engineering documents, blueprints, diagrams, logs, and other corporate records.
Reported data volumes range from about 1 GB to several terabytes per organization. Not every organization necessarily has highly monetizable data, which may explain why some targeted companies may choose not to pay ransoms.
The stolen content could include sensitive personal information and valuable intellectual property. At the same time, much of what’s listed may be of limited value or already publicly available, depending on the organization and the nature of its engineering artifacts.
Examples of alleged Cl0p Windchill victims
Several well-known organizations have been named among the alleged victims in the Windchill campaign. The reporting includes companies such as:
- Shell
- Philips
- Fiserv
- Zebra Technologies
- Ingersoll Rand
- Toast
- Mindray
- Largan Precision
GE was reportedly listed as well at an earlier point, but that entry has since been removed from Cl0p’s site. A removal could signal different possibilities, including that an agreement was reached or that negotiations resumed—though the reporting does not confirm which scenario applies.
Company responses: claims acknowledged, breaches not confirmed
Some organizations—such as Shell, Philips, Fiserv, and GE—have stated they are aware of the allegations and are investigating. However, none has publicly confirmed a major data breach tied to the claims.
This is not unusual in extortion cases. Public naming can be used to pressure organizations, while victims may still be validating whether the exfiltration actually occurred and whether the stolen data includes what is claimed.
Why this campaign matters for PLM customers
PLM environments often contain core engineering and operational knowledge: designs, schematics, project histories, and internal records that can be difficult to replace. When attackers target systems like Windchill, they may gain access not only to confidential documents, but also to credentials and structured information stores that facilitate broader compromise.
The reported exploitation method—remote, unauthenticated arbitrary code execution followed by web shell deployment and custom tooling—highlights how quickly an attacker can move from initial access to data theft.
Cl0p’s broader pattern: extortion tied to known flaws
The Windchill campaign is part of a wider ransomware and extortion trend. Reporting notes that Cl0p previously carried out similar operations targeting vulnerabilities in products such as Oracle E-Business Suite, MOVEit, Cleo, and GoAnywhere.
For security teams, the takeaway is consistent: when vulnerabilities are added to KEV catalogs and vendor advisories warn of exploitation, patching timelines should be treated as urgent—not as guidance.
What organizations should do next
If your organization uses PTC Windchill or FlexPLM, the reported details around CVE-2026-12569 are a strong signal to verify exposure and assess likely compromise paths. That includes reviewing whether the vulnerable component is present, confirming the patch level, and investigating signs of web shell activity or suspicious process behavior within the application context.
Because attackers reportedly aimed at credential theft and access to sensitive vault data, incident response typically needs to consider both data integrity and account security. Even when public breach confirmations have not been made, the scope described by Cl0p Windchill victims suggests attackers may have sought deep access rather than minimal extraction.
Conclusion
Cl0p has named more than 40 alleged targets connected to a PTC Windchill and FlexPLM campaign. The activity is linked to CVE-2026-12569, described as an improper input validation flaw that permits remote, unauthenticated arbitrary code execution. Reporting further indicates attackers used web shells and a custom implant to map sensitive data, decrypt stored credentials, and enable broader compromise.
While some organizations acknowledge the claims and continue investigations, none has confirmed a major breach publicly so far. For PLM operators, the episode underlines how quickly exploitation can turn into credential access, large-scale data theft, and extortion pressure.
Source: https://www.securityweek.com/cl0p-ransomware-group-names-over-40-victims-of-ptc-windchill-campaign/
