Cl0p Ransomware Exploits PTC Windchill CVE-2026-12569: Shell, Philips, GE Among 47 Named Victims
The Cl0p extortion group exploited CVE-2026-12569, a deserialization flaw in PTC Windchill and FlexPLM, to steal engineering data from Shell, Philips, General Electric, Fiserv, and roughly 45 other companies. Unlike Cl0p's MOVEit campaign, this operation skips file encryption and targets CAD files, blueprints, and supply chain documentation.