Ransomware group Cl0p has named more than 40 organizations that were allegedly targeted in the recent campaign that exploited a vulnerability in PTC’s Windchill and FlexPLM product lifecycle management (PLM) platforms.
The vulnerability and its exploitation
The exploitation of the vulnerability, tracked as CVE-2026-12569, became known in June when CISA added it to its KEV catalog and the vendor warned of attacks targeting it.
The flaw is a faulty input validation issue that allows a remote, unauthenticated attacker to achieve arbitrary code execution via specially crafted requests.
The vulnerability was expected to be exploited, and police in Germany reportedly warned organizations of impending attacks.
It’s worth noting that CVE-2026-12569 is the first Windchill vulnerability to be exploited in the wild.
The cybersecurity industry reported the exploitation of the PLM product flaw in Cl0p ransomware attacks in late July. Cl0p partners exploited the vulnerability to deploy web shells that gave them access to the data of organizations using Windchill.
Security firm ReliaQuest reported Tuesday that Cl0p used one individual implant Designed to provide “complete data theft capability” without the need for additional tools.
“(The web shell) maps sensitive vault data, decrypts all credentials in the Windchill keystore, and includes a custom Java class loader that allows Clop to execute any additional code within the application process, extending the shell into an unlimited backdoor for follow-on activities such as lateral movement, ransomware, or persistence,” ReliaQuest explained.
Cl0p attacks
The cybercrime gang Cl0p initially only listed incomplete company names on its website, but on August 12 it began publishing the full names of alleged victims. So far, more than 40 organizations have been named as apparently affected by the Windchill campaign.
For each victim, the hackers listed the type and amount of information stolen.
The exfiltrated data includes databases, project files, backups, photos and other image files, technical documents, blueprints, diagrams, logs and other company documents. According to the hackers, the amount of information stolen per organization ranges from 1 GB to several terabytes.
The compromised files could contain sensitive personal information and valuable intellectual property, but much of it may be of little value and already in the public domain, which is probably why many of the organizations attacked have refused to pay a ransom.
The alleged victims include oil and gas giant Shell, technology giant Philips, fintech giant Fiserv, enterprise mobility provider Zebra Technologies, industrial equipment maker Ingersoll Rand, point-of-sale software maker Toast, global medical technology leader Mindray and key Apple camera lens supplier Largan Precision.
GE was also initially listed but has since been removed from the Cl0p website, which could indicate that the company has agreed to pay a ransom or has resumed negotiations with the hackers.
Companies like Shell, Philips, Fiserv and GE stated that they are aware of the allegations and are investigating, but none have confirmed a significant data breach.
Cl0p previously conducted similar data theft and extortion campaigns targeting vulnerabilities in Oracle E-Business Suite, MOVEit, Cleo and GoAnywhere software.
Related: CareCloud data breach impact grows to 3.7 million individuals
Related: Heights Finance data breach affects at least 1.2 million people
Related: 680,000 affected by French tax authority data breach
