By 19 August 2026 the Cl0p extortion operation had listed more than 40 organisations on its leak site as victims of a campaign against PTC’s Windchill and FlexPLM platforms — product-lifecycle management systems used across manufacturing, automotive, aerospace and retail. Names listed include Shell, Philips, General Electric, Fiserv and Zebra. Research attributes the campaign to CVE-2026-12569, a flaw chain yielding unauthenticated remote code execution on internet-exposed instances.
A listing is a claim. As of this filing, none of the named organisations has confirmed a breach in the material reviewed, and this file carries every count and name on that basis.
MOVEit, Aimed At Drawings Instead Of People
The shape is the one Cl0p established at 23-0601: find one product that many organisations expose to the internet, exploit it once, take data from every reachable instance, and skip encryption entirely. What has changed is the payload. A file-transfer platform holds whatever passes through it, which is usually personal data. A product-lifecycle platform holds designs, specifications, bills of materials and engineering change history — the accumulated technical knowledge of a manufacturer.
The corpus recorded at 25-1204 what that category means for disclosure: corporate information with no data subject triggers no notification law anywhere. An organisation listed in this campaign that lost only engineering data may owe nobody a letter, and on every public register the incident will not have happened.
Partial Names, Then Full Ones
Cl0p initially published partial company names, completing them from 12 August. The redaction-then-reveal cadence is a pressure instrument: it tells each victim the group is willing to publish while selling them time to negotiate before customers and competitors can read the list. The technique costs the operation nothing and converts a static leak site into a countdown.
The Exposure Question, Again
Every reachable victim in this campaign had a product-lifecycle server facing the internet. These platforms exist so that suppliers, contractors and plants in different countries can work on the same designs — the same distributed-access logic that put file-transfer appliances at the network edge. The remediation guidance is correspondingly familiar: patch, and ask why the system was reachable from the outside at all.
Compiled from vendor research and reporting of the leak-site listings, listed below. Victim names and the 40+ count are the attackers’ claims, reproduced here as claims; no listed organisation had confirmed a breach in the material reviewed. The CVE attribution is the researchers’. Graded medium. Corrections: corrections@forensicpost.com.
- Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill CampaignSecurityWeek
- Clop ransomware targets Windchill, FlexPLM in data theft attacksBleepingComputer
- Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCEThe Hacker News
- Cl0p Targets 40+ Organizations Through PTC Windchill FlawSecurity Affairs