Desk live·
ForensicPost
Ransomware/Third party/File 26-0819

Cl0p Names More Than 40 Organisations in Its PTC Windchill Campaign

The group that ran MOVEit is applying the same playbook to PTC’s Windchill and FlexPLM product-lifecycle platforms — the systems that hold engineering IP. Shell, Philips and GE are among the names listed. No breach is confirmed by any of them.

Constructed geometry · not a chart of case data
TargetPTC Windchill / FlexPLM operators
ActorCl0p
S. Rosler12 min readConfidence: medium4 sources reviewed

By 19 August 2026 the Cl0p extortion operation had listed more than 40 organisations on its leak site as victims of a campaign against PTC’s Windchill and FlexPLM platforms — product-lifecycle management systems used across manufacturing, automotive, aerospace and retail. Names listed include Shell, Philips, General Electric, Fiserv and Zebra. Research attributes the campaign to CVE-2026-12569, a flaw chain yielding unauthenticated remote code execution on internet-exposed instances.

A listing is a claim. As of this filing, none of the named organisations has confirmed a breach in the material reviewed, and this file carries every count and name on that basis.

MOVEit, Aimed At Drawings Instead Of People

The shape is the one Cl0p established at 23-0601: find one product that many organisations expose to the internet, exploit it once, take data from every reachable instance, and skip encryption entirely. What has changed is the payload. A file-transfer platform holds whatever passes through it, which is usually personal data. A product-lifecycle platform holds designs, specifications, bills of materials and engineering change history — the accumulated technical knowledge of a manufacturer.

The corpus recorded at 25-1204 what that category means for disclosure: corporate information with no data subject triggers no notification law anywhere. An organisation listed in this campaign that lost only engineering data may owe nobody a letter, and on every public register the incident will not have happened.

Partial Names, Then Full Ones

Cl0p initially published partial company names, completing them from 12 August. The redaction-then-reveal cadence is a pressure instrument: it tells each victim the group is willing to publish while selling them time to negotiate before customers and competitors can read the list. The technique costs the operation nothing and converts a static leak site into a countdown.

The Exposure Question, Again

Every reachable victim in this campaign had a product-lifecycle server facing the internet. These platforms exist so that suppliers, contractors and plants in different countries can work on the same designs — the same distributed-access logic that put file-transfer appliances at the network edge. The remediation guidance is correspondingly familiar: patch, and ask why the system was reachable from the outside at all.

How we reported this

Compiled from vendor research and reporting of the leak-site listings, listed below. Victim names and the 40+ count are the attackers’ claims, reproduced here as claims; no listed organisation had confirmed a breach in the material reviewed. The CVE attribution is the researchers’. Graded medium. Corrections: corrections@forensicpost.com.

Sources
  1. Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill CampaignSecurityWeek
  2. Clop ransomware targets Windchill, FlexPLM in data theft attacksBleepingComputer
  3. Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCEThe Hacker News
  4. Cl0p Targets 40+ Organizations Through PTC Windchill FlawSecurity Affairs
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary