Core Technical Takeaways
- >Cl0p affiliates began exploiting CVE-2026-12569 as an undisclosed zero-day in early June 2026, before PTC shipped a patch on June 17. The flaw was added to CISA KEV by the end of June.
- >The vulnerability is a deserialization-of-untrusted-data flaw in PTC Windchill PDMLink and FlexPLM that allows unauthenticated remote code execution. Attackers chained a pre-authentication information disclosure bug with the RCE to gain full server control.
- >Cl0p named approximately 47 organizations on its leak site between August 12 and 16, including Shell, Philips, General Electric, and Fiserv. The campaign targets engineering data rather than consumer records.
- >Unlike the 2023 MOVEit campaign, this operation skips file encryption. Cl0p steals engineering data and threatens publication, marking a shift toward industrial espionage over traditional ransomware lockup.
Campaign overview
The Cl0p extortion group spent August 2026 naming Shell, Philips, General Electric, Fiserv, and roughly 45 other companies on its dark web leak site. The common thread is not a shared file transfer vendor but a shared product lifecycle management vendor: PTC's Windchill and FlexPLM software, which aerospace, automotive, and manufacturing firms use to store CAD files, blueprints, and supply chain data.
The vulnerability behind the campaign, CVE-2026-12569, carries a CVSS score between 9.3 and 9.8 depending on the advisory. It is a deserialization-of-untrusted-data flaw in PTC Windchill PDMLink and FlexPLM that allows unauthenticated remote code execution. According to threat intelligence firm Ransom-ISAC and CTI vendor ScruteX, Cl0p affiliates began exploiting the flaw as an undisclosed zero-day in early June 2026.
| Attribute | Specification | |
|---|---|---|
| Threat actor | Cl0p (extortion group, behind 2023 MOVEit campaign) | |
| Vulnerability | CVE-2026-12569 (deserialization, unauthenticated RCE) | |
| CVSS | 9.3 to 9.8 (varies by advisory) | |
| Affected software | PTC Windchill PDMLink, FlexPLM (pre-11.0 M030) | |
| Patch date | June 17, 2026 (PTC) | |
| CISA KEV | Added by end of June 2026 | |
| Named victims | Approximately 47 as of late August 2026 | |
| Data targeted | Engineering drawings, CAD files, blueprints, supply chain documentation |
Exploit chain and technical details
Researchers at Ransom-ISAC, eCrime.ch, and DEFUSED described a two-step exploit chain. Attackers first abuse a pre-authentication information-disclosure bug in FlexPLM, then chain it with the Windchill RCE to gain full server control. No valid credentials are required to start the attack, so any Windchill or FlexPLM instance exposed to the public internet before the June 17 patch was a viable target.
Once on the server, Cl0p affiliates dropped JSP web shells to browse the file system, locate engineering and design data, and stage it for exfiltration. Threat intelligence vendor ReliaQuest reported that Cl0p used a custom implant in some intrusions to harvest credentials and pull databases and documents directly from compromised PLM environments.
PTC shipped a patch on June 17, 2026, fixing the flaw in Windchill and FlexPLM releases at or beyond version 11.0 M030. The vulnerability was added to the CISA Known Exploited Vulnerabilities catalog by the end of June.
Timeline
Patching did not stop the bleeding. Ransom-ISAC issued a warning on July 22 that Cl0p affiliates were still hitting unpatched, internet-exposed Windchill and FlexPLM servers. Mass exploitation accelerated around July 20, and by the week of August 10 to 16, ScruteX's weekly ransomware tracker attributed all 47 of Cl0p's new leak site listings that week to this single flaw. The campaign went fully public on August 12 to 13, when Cl0p posted the names of Shell, Philips, GE, Fiserv, and dozens of other organizations.
-
1.
Early June 2026: Cl0p affiliates begin exploiting CVE-2026-12569 as an undisclosed zero-day.
-
2.
June 17, 2026: PTC ships a patch for Windchill and FlexPLM (version 11.0 M030 and later).
-
3.
Late June 2026: CVE-2026-12569 added to CISA KEV catalog.
-
4.
July 20, 2026: Mass exploitation accelerates against unpatched servers.
-
5.
July 22, 2026: Ransom-ISAC warns that Cl0p affiliates continue targeting unpatched instances.
-
6.
August 12 to 13, 2026: Cl0p posts Shell, Philips, GE, Fiserv, and other names on its leak site.
-
7.
August 10 to 16, 2026: ScruteX attributes all 47 new Cl0p listings that week to CVE-2026-12569.
Victim profile and stolen data
The victim data paints a picture of industrial espionage rather than a typical consumer data breach. Cl0p claims it took approximately 89 GB of data from Shell, described in coverage as engineering drawings, blueprints, site photographs, and inspection report scans. Philips reportedly lost around 13.5 GB, characterized as technical schematics and product lifecycle documentation. Neither company had production systems encrypted.
General Electric, named in some reports as GE Aerospace, and Fiserv round out the highest profile confirmed names. GE's exposure involves facility test reports, project plans, and engineering blueprints. Fiserv's loss involved credential theft and exfiltration of databases and documents tied to engineering and product data rather than the payments company's core financial transaction systems.
None of the outlets tracking the campaign have reported large-scale theft of customer personal or financial data. This is a notable departure from Cl0p's MOVEit era playbook, which hit healthcare records, payroll data, and government personnel files. The remaining 35-plus organizations named on Cl0p's leak site span aerospace, automotive, apparel, and manufacturing.
Comparison to prior Cl0p campaigns
Cl0p has run this playbook before. Each time, the group picks a widely deployed enterprise software product, finds or buys a zero-day in it, and automates exploitation at scale.
| Campaign | Year | Exploited Software | Estimated Victims | Data Type Stolen |
|---|---|---|---|---|
| MOVEit Transfer | 2023 | Progress Software MOVEit | 200 to 300+ | PII, healthcare, payroll, government records |
| GoAnywhere MFT | 2023 | Fortra GoAnywhere | Dozens to low hundreds | Mixed enterprise data |
| Cleo | 2024 | Cleo file transfer | Smaller scale | Mixed enterprise data |
| Windchill / FlexPLM | 2026 | PTC Windchill, FlexPLM | Approximately 47 | Engineering IP, CAD files, blueprints |
Measured by victim count, the Windchill and FlexPLM campaign sits closer to the GoAnywhere and Cleo scale than to MOVEit's hundreds. What sets it apart is the target category. MOVEit, GoAnywhere, and Cleo are file transfer tools that happened to hold whatever data passed through them. Windchill and FlexPLM are purpose-built repositories for a company's most sensitive engineering intellectual property. Stolen CAD files and bills of materials can hand competitors or nation-state actors a shortcut around years of R&D investment, even without a single customer record changing hands.
Defensive actions
Organizations running PTC Windchill or FlexPLM should verify they are running version 11.0 M030 or later. Internet-exposed instances should be moved behind a VPN or restricted to internal network access. Because the exploit chain does not require valid credentials, any instance that was reachable from the public internet before the June 17 patch should be treated as potentially compromised and examined for JSP web shells, unauthorized credential access, and data exfiltration artifacts.
The CISA KEV listing for CVE-2026-12569 carries a federal remediation deadline. Private sector organizations should apply the same urgency. Threat actors continue scanning for unpatched Windchill and FlexPLM servers months after the patch shipped, as Ransom-ISAC's July 22 warning confirmed.