Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign

Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign
Cl0p has publicly named more than 40 organizations allegedly hit in a campaign that abused CVE-2026-12569 in PTC Windchill and FlexPLM, using web shells and a custom implant to steal data. The stolen information reportedly includes databases, engineering documents, backups, and other sensitive files, with victims ranging from Shell and Philips to Fiserv and Zebra Technologies. #Cl0p #CVE-2026-12569 #PTC #Windchill #FlexPLM #Shell #Philips #Fiserv #ZebraTechnologies

Keypoints

  • Cl0p named more than 40 alleged victims from the Windchill and FlexPLM campaign.
  • The attacks exploited CVE-2026-12569, an improper input validation flaw in PTC software.
  • The vulnerability allows remote, unauthenticated code execution through specially crafted requests.
  • Cl0p used web shells and a custom implant to steal data and gain persistent access.
  • Reported victims include Shell, Philips, Fiserv, Zebra Technologies, Ingersoll Rand, Toast, Mindray, and Largan Precision.

Read More: https://www.securityweek.com/cl0p-ransomware-group-names-over-40-victims-of-ptc-windchill-campaign/