LIVE
LATEST THREAT: Cl0p Goes Public: Windchill Campaign Victim List Tops 40, GE Quietly Disappears THREAT ALERT ACTIVE
Intelligence DB / Campaign Alert Cl0p

Cl0p Goes Public: Windchill Campaign Victim List Tops 40, GE Quietly Disappears

Cl0p has shifted from silent exfiltration to public shaming in its PTC Windchill and FlexPLM campaign, naming Shell, Philips, Fiserv, and dozens more since August 12. General Electric's abrupt removal from the leak site hints at a negotiation already resolved.

By Ransomware Tracker ·
cl0pclopptc-windchillflexplmcve-2026-12569data-extortionleak-siteshellphilipsgeneral-electricfiserv
Threat Level
9/10
Sectors Targeted
manufacturing
automotive
aerospace
retail
energy
healthcare
financial-services
Ransomware Family
Cl0p

From silent theft to public pressure

Cl0p’s campaign against PTC’s Windchill and FlexPLM product-lifecycle-management platforms has entered its extortion phase in earnest. When Ransomware Tracker first covered the exploitation of CVE-2026-12569 in mid-August, the group had not yet named a single victim publicly, despite researchers assessing that data theft had been underway since early June. That changed on August 12, when Cl0p began replacing the partial or redacted company names on its Tor leak site with full identities. By August 19, the list had grown to more than 40 organizations; subsequent additions have pushed the count past 43.

The named victims include some of the largest industrial and consumer brands to appear on a single Cl0p listing in months: Shell, Philips, Fiserv, Zebra Technologies, Ingersoll Rand, Toast, Mindray, and Largan Precision are among the confirmed entries, spanning oil and gas, medical technology, fintech, enterprise mobility, industrial equipment, point-of-sale systems, and precision manufacturing. General Electric was also listed when the full-name rollout began — and has since vanished from the site entirely.

What the listings claim

For each victim, Cl0p’s leak page includes a description of the data allegedly taken and a rough volume estimate, ranging from roughly 1 GB up to multiple terabytes depending on the organization. Categories cited across the listings include databases, CAD and engineering project files, product blueprints and diagrams, system backups, internal images, and general corporate documents — consistent with Windchill and FlexPLM’s role as the system of record for product design and bill-of-materials data at manufacturers. Shell’s entry specifically claims roughly 89 GB of stolen material.

None of the named companies has confirmed a significant data breach as of this writing. Philips said the incident, which it described as involving an enterprise server, has “no impact on customer environments.” Shell said it is “aware of a potential incident” and is working with its security teams to investigate. GE, before its listing disappeared, said it was “working to assess the potential issue.” Fiserv acknowledged awareness of the claims without confirming impact. This pattern — acknowledgment without confirmation — has become close to standard corporate response language for Cl0p’s mass-exploitation campaigns, dating back to MOVEit and Cleo.

The GE removal is the tell

GE’s disappearance from the leak site is the most operationally significant detail in this update. Cl0p, like most double-extortion operators, treats removal from a leak page as a negotiation signal: victims are typically pulled from public listings after paying, after entering a payment process that satisfies the group’s timeline, or occasionally after a dispute over the legitimacy of the claimed data. Cl0p does not publish removal reasons, and GE has not commented specifically on the removal, so it cannot be independently confirmed as a payment. But the timing — a listing appearing during the August 12 full-name rollout and vanishing within roughly two weeks — fits the pattern researchers have observed in prior Cl0p campaigns, where early, high-profile removals often precede a broader wave of quieter victim payments that never generate public listings at all.

Timeline recap

CVE-2026-12569, an unauthenticated remote code execution flaw reachable through chained deserialization and information-disclosure bugs in Windchill’s login servlet and the FlexPLM WSDL endpoint, was patched by PTC starting June 17. CISA added it to the Known Exploited Vulnerabilities catalog around June 25-26 after confirming in-the-wild attacks. Researchers assess Cl0p affiliates were exploiting the bug as a zero-day for weeks before the patch existed. Extortion emails to victim employees began circulating around July 19-20. The leak site initially carried partial or obfuscated company names — Cl0p’s standard tactic for generating anxiety among a broad pool of potential victims before committing to full public disclosure — before the switch to full names on August 12.

Why this matters beyond Windchill

The victim list itself is a useful proxy for how deep Cl0p’s edge-exploitation campaigns typically run before anyone notices. A single unauthenticated RCE in a moderately obscure enterprise platform — Windchill is far less of a household name than MOVEit or Oracle EBS — was enough to compromise dozens of organizations across half a dozen sectors within a roughly six-week window between first exploitation and patch availability. That is consistent with Cl0p’s operating model since 2023: identify a widely deployed but under-scrutinized enterprise application, burn a zero-day at scale before defenders can react, then run the extortion phase as a slow-drip public pressure campaign rather than a simultaneous mass disclosure.

For organizations running Windchill or FlexPLM that have not yet appeared on the leak site, the operative assumption should not be that the campaign has run its course. Cl0p’s own history — MOVEit’s victim count climbed for months after initial disclosure, and the Cleo campaign saw new names added well into the following quarter — suggests the August 26 count is a checkpoint, not a final tally. Confirming patch status against PTC’s June 17 fix, auditing Windchill and FlexPLM logs for the X-windchill-req header activity documented in earlier reporting, and reviewing outbound data transfer volumes from PLM infrastructure during the June-July window remain the most direct ways to determine exposure.

// Related Intelligence
Campaign Alert

China-Nexus Actor Exploits Critical VMware vCenter Flaw to Deploy Babuk-Derived Ransomware

Campaign Alert

Cl0p's Next Platform: Custom Web Shell Hits PTC Windchill and FlexPLM

Campaign Alert

FortiBleed Credentials Are Fuelling INC Ransom and Lynx Ransomware Attacks