Cl0p Claims Data Theft at Philips, Shell and Around 50 Firms

Step by step
How the attack unfolded
Click a phase for details – or let the animation play through.
PHASE 1/6 · Initial Access

Attackers exploit the critical RCE vulnerability CVE-2026-12569 in PTC Windchill and FlexPLM over the internet.

T1190 – Exploit Public-Facing Application
  • CVE-2026-12569 with CVSS 9.3 of 10
  • Attack over the network, without credentials and without user interaction
  • Root cause: insecure deserialization of untrusted data
  • Affected: PTC Windchill PDMLink and FlexPLM
PHASE 2/6 · Execution

The vulnerability allows arbitrary remote code execution on the Windchill server.

T1203 – Exploitation for Client Execution T1059 – Command and Scripting Interpreter
  • Remote code execution (RCE) on the PLM server
  • PTC: 'This vulnerability could allow an unauthorized user to execute code remotely.'
  • CISA confirms active exploitation, added to KEV catalog on 25 June 2026
PHASE 3/6 · Persistence

Attackers deploy hidden JSP web shells to persistently run commands on the server.

T1505.003 – Server Software Component: Web Shell
  • Web shells as hidden JSP files in the Windchill login directory
  • PTC added IOCs for known JSP web shell paths on 27 July 2026
  • Persistent access for ongoing command execution
PHASE 4/6 · Collection

Attackers enumerate files and collect engineering and design data from the PLM system.

T1083 – File and Directory Discovery T1005 – Data from Local System
  • Indicator: created file named flst.txt (file listing)
  • Aggregation of engineering and design data (CAD drawings, bills of materials)
  • PLM systems manage design, development and product data
PHASE 5/6 · Exfiltration

Collected data is exfiltrated over command-and-control channels for extortion.

T1041 – Exfiltration Over C2 Channel
  • PTC added IOCs including C2 addresses on 27 July 2026
  • Ransom-ISAC observed extortion emails referencing Windchill from 20 July 2026
  • On 14 August 2026 an additional C2 indicator observed in an active incident
PHASE 6/6 · Impact

Cl0p claims to have stolen data from nearly 50 companies and pressures victims through extortion.

T1657 – Financial Theft
  • Cl0p claims data theft from nearly 50 companies on 13 August 2026
  • Named: Philips, Shell, Fiserv, GE – data type and scope not independently confirmed
  • Philips reports contained attempt, Fiserv found no evidence of compromise
  • Attribution unconfirmed per ReliaQuest: 'The actor behind these attacks remains unconfirmed.'
Short & clear answers
Frequently asked questions about this incident
As an ordinary website operator, am I affected by CVE-2026-12569?
No, this is not a WordPress, CMS or general website issue. If you run a standard business website and use neither PTC Windchill PDMLink nor FlexPLM, you are not directly affected on a technical level. The main targets are industrial, machinery and manufacturing companies with in-house product development, as well as IT service providers hosting such systems.
How do I check whether my company is affected?
First determine via your IT asset inventory and hosting provider whether PTC Windchill PDMLink or FlexPLM is running in your company at all. For each instance, identify the product, version, patch level and whether it is reachable from the internet, and compare this against PTC article CS473270. Also search your HTTP logs for suspicious POST requests to /Windchill/login/*.jsp, since legitimate Windchill traffic does not use this path.
What exactly should I do now if I use Windchill or FlexPLM?
Act immediately, as the flaw is critical at CVSS 9.3 and is being actively exploited in ransomware campaigns according to CISA. Apply the patches provided by PTC and scan your environment for the published indicators of compromise (such as suspicious JSP files, the file flst.txt, or the hash 55a1eb4c…). For PTC-hosted instances, PTC support is the authoritative point of contact.
Is it true that Cl0p stole data from nearly 50 companies like Philips and Shell?
The figure of 'nearly 50' is initially a claim by the Cl0p extortion group, not a confirmed damage report. Reuters could not independently verify the type or volume of the allegedly stolen data, and no named company has confirmed a full data breach in the claimed form—Fiserv even found no evidence of compromised data. Security experts also state that attributing all attacks to Cl0p remains unconfirmed.
Can I be indirectly affected as an SME even if I don't use the software myself?
Yes, that is possible. If an external development, engineering or IT service provider uses PTC Windchill or FlexPLM and processes your data there, your design documents, supplier data or personal data of your employees and customers could be affected. You should therefore review your supply chain and proactively ask relevant service providers about their exposure.
More security news
You might also be interested in
Critical Elementor Pro Flaw: Attackers Can Fully Take Over WordPress Sites
A file upload bug in Elementor Pro up to 4.2.1 allows RCE without login. Version 4.2.2 fixes the flaw – update now!
Pods Plugin: Critical Flaw Enables Admin Takeover, No Login
A critical flaw in the WordPress plugin Pods lets attackers overwrite admin passwords without login. Over 100,000 sites are affected.
miniOrange SAML SSO: Critical Bypass Turns Attackers Into Admins
Two critical auth bypasses in the miniOrange SAML SSO plugin allow forged SAML assertions—up to full WordPress admin access.