Cl0p Ransomware Names 40+ Victims in PTC Windchill Zero-Day Campaign
The Cl0p ransomware group has published the names of more than 40 organizations allegedly compromised in a campaign exploiting a critical flaw in PTC's Windchill and FlexPLM product lifecycle management platforms. The vulnerability, tracked as CVE-2026-12569, is an improper input validation issue that allows a remote, unauthenticated attacker to achieve arbitrary code execution via specially crafted requests. CISA added the flaw to its Known Exploited Vulnerabilities catalog in June, and German law enforcement reportedly warned organizations of imminent attacks shortly after. Notably, CVE-2026-12569 is the first Windchill vulnerability ever observed being exploited in the wild, making it a landmark zero-day for the PLM software ecosystem.
According to ReliaQuest, Cl0p affiliates deployed a sophisticated web shell that granted persistent access to organizations using Windchill. The custom implant maps sensitive vault data, decrypts every credential stored in the Windchill keystore, and includes a custom Java class loader capable of executing arbitrary additional code inside the application process. This effectively transforms the initial foothold into an unlimited backdoor enabling lateral movement, ransomware deployment, and long-term persistence. Security teams managing exposed PLM environments should run an immediate port scanner to identify any unauthorized listeners and verify that no web shells have been planted on reachable endpoints.
The cybercrime gang initially disclosed partial company names but on August 12 began publishing full names of alleged victims along with the volume and type of stolen data. Exfiltrated files reportedly include databases, project files, backups, engineering documents, blueprints, diagrams, logs, and corporate records, with stolen volumes ranging from 1 GB to several terabytes per organization. Named victims include oil and gas giant Shell, tech conglomerate Philips, fintech leader Fiserv, enterprise mobility provider Zebra Technologies, industrial manufacturer Ingersoll Rand, point-of-sale software maker Toast, global medical technology firm Mindray, and a key Apple camera lens supplier. Because much of the stolen intellectual property may already be public or hold limited resale value, many affected organizations are reportedly refusing to pay the ransom demand.
The breach raises serious concerns for any organization whose employees or contractors may have had credentials, project files, or proprietary engineering data stored on compromised Windchill instances. Security teams should immediately audit their PLM infrastructure for indicators of compromise, rotate all keystore credentials, and conduct forensic analysis of web server logs dating back to June. Affected individuals can verify whether their personal information surfaced in this incident using the email breach checker, while security teams should ensure no exposed credentials are reused by running them through a password checker to confirm strength and uniqueness across critical systems.