CVE Tools
Back to feed
Exploited in the wild PTC Cl0p ransomware data-breach

Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign

SecurityWeek·By Eduard Kovacs··3 min read
CVE Tools coverage

The Cl0p ransomware group has published the full names of over 40 organizations allegedly targeted through a campaign exploiting CVE-2026-12569, a critical vulnerability in PTC’s Windchill and FlexPLM product lifecycle management platforms. This improper input validation flaw allows unauthenticated remote attackers to execute arbitrary code, marking the first time a Windchill defect has been exploited in the wild. ReliaQuest noted that Cl0p deployed a custom implant to steal credentials and exfiltrate vast amounts of data, including engineering documents and databases, from victims such as Shell, Philips, and Fiserv.