# Cl0p names more than 40 alleged victims in Windchill campaign

_Wednesday, August 19, 2026 at 7:07 AM EDT · Security · Developing · Tier 2 — Notable_

![Cl0p names more than 40 alleged victims in Windchill campaign — Primary](https://www.securityweek.com/wp-content/uploads/2024/12/cleo-file-transfer-exploit-attack.jpeg)

The Cl0p ransomware group has named more than 40 organizations it alleges were targeted through a vulnerability in PTC Windchill and FlexPLM platforms, SecurityWeek reported.

The flaw, CVE-2026-12569, allows remote unauthenticated code execution through specially crafted requests. SecurityWeek said Cl0p affiliates used it to deploy web shells and access data from Windchill users. The named organizations include Shell, Philips, Fiserv, Zebra Technologies and Ingersoll Rand.

Several companies said they were aware of the claims and investigating, but none confirmed a significant breach.

## Sources

- [SecurityWeek](https://www.securityweek.com/cl0p-ransomware-group-names-over-40-victims-of-ptc-windchill-campaign/)

---
Canonical: https://techandbusiness.org/newswire/tco4yyEJq8nsjOp9T4GVeL
Retrieved: 2026-08-19T14:25:36.265Z
Publisher: Tech & Business (techandbusiness.org)
