Cl0p says it stole data from nearly 50 major companies
The group names Shell, Philips, GE and Fiserv among its alleged victims. Shell is investigating a potential incident, but neither its scope nor the data Cl0p says it obtained has been publicly confirmed.
What happened?
Cl0p has attributed its latest data-theft campaign to servers running PTC Windchill and FlexPLM. The exploitation activity is documented; the specific victim list and the amount of information stolen remain, in several cases, claims made by the group itself.
The distinction matters: an organisation investigating an incident does not yet confirm a breach or tell us what information may have been affected.
How did it happen?
The attackers exploited internet-facing PTC systems. The chain described by Ransom-ISAC combines a pre-authentication information disclosure in FlexPLM with CVE-2026-12569, a critical remote-code-execution vulnerability in Windchill and FlexPLM. They then deployed JSP webshells to search for and exfiltrate data.
PTC has published patches and indicators of compromise and urges customers to apply them immediately. This does not look like Shell was selected by hand: the pattern is to find one vulnerable product used by many organisations and scale from there.
Attackers do not need to choose your company first. They can choose the application you share with hundreds of companies and find you afterwards.
What can we learn?
Strong internal controls are not enough when a critical application or technology supplier sits outside the inventory, emergency-patching process or monitoring. The useful question is not only “are we protected?”, but “do we know what is exposed, who it depends on and how we learn about a critical vulnerability?”
If you run Windchill or FlexPLM, check the installed version now, apply PTC's fixes and hunt for the published indicators back to early June 2026. If you do not use these products, the exercise still applies: identify critical internet-facing software and require its owners to show a verifiable vulnerability and incident-management process.
The supplier cybersecurity assessment methodology explains how to inventory, tier and review third parties. Once you know which ones are critical, use Basic VRM Form to generate the appropriate security questionnaire for each one.
Assess the supplier before a vulnerability decides for you
Tier the third party, select what applies and generate a fillable PDF questionnaire. Everything is processed in your browser.
Create a VRM questionnaire →Primary technical sourcesPTC security advisory for Windchill and FlexPLM · Ransom-ISAC: Cl0p exploitation of CVE-2026-12569
Named companies and investigation statusTechNadu: claims concerning Shell, Philips, GE and Fiserv
Information reviewed on 17 August 2026. Claims by an extortion group are not presented as a confirmed breach without independent corroboration or confirmation from the affected organisation.