Live Cybersecurity News Ticker | Codekeeper

Cl0p Ransomware Names 40+ Victims in PTC Windchill Attack Campaign

Written by Content Team | Aug 20, 2026, 10:22:13 AM

The Cl0p ransomware gang has publicly named more than 40 organizations it claims to have breached through a vulnerability in PTC's Windchill and FlexPLM platforms. The flaw, CVE-2026-12569, allows unauthenticated remote code execution and was added to CISA's KEV catalog in June after active exploitation began.

High-profile alleged victims include Shell, Philips, Fiserv, Zebra Technologies, Ingersoll Rand, and Apple lens supplier Largan Precision. GE was listed but has been removed from C10p's website— possibly signaling ransom negotiations. Stolen data ranges from 1 GB to several terabytes per organization, covering databases, engineering blueprints, and corporate documents. None of the named companies have confirmed a significant breach.

Source: SecurityWeek