Ransomware Gang Cl0p Claims Mass Data Theft From Shell, Philips, GE Aerospace and Fiserv |

0
1
Ransomware Gang Cl0p Claims Mass Data Theft From Shell, Philips, GE Aerospace and Fiserv |


What We Know About the Windchill Campaign

Cl0p has publicly named nearly 50 companies, including Shell, Philips, Fiserv and GE, after weeks of quiet extortion tied to a critical vulnerability in PTC’s Windchill and FlexPLM software. The attacker’s claims are running ahead of the evidence. Philips has confirmed a contained attempted compromise, Shell and GE are still investigating, and Fiserv says it has found no evidence that customer or operational data was touched.

Cl0p turns a private campaign public

Reuters reported on August 13 that the extortion group had claimed large volumes of stolen data from close to 50 organizations worldwide. The report followed a wave of leak-site postings that RansomLook, a service that archives ransomware leak sites, first captured in redacted form on August 5 and then republished with company names attached on August 12. That sequence, masked descriptions first, names a week later, points to a staged pressure tactic, though that is an inference drawn from RansomLook’s archive rather than something Cl0p has stated outright.

None of this amounts to 50 confirmed breaches. Cl0p’s leak site is a criminal marketing tool, and Reuters said it could not independently verify how much data the group holds or what it contains. What the named companies themselves have confirmed is a much shorter list.

What Shell, Philips, Fiserv and GE Aerospace have confirmed

Philips told Reuters it had identified and contained an attempted cybersecurity compromise of a specific enterprise server tied to internal data, and said the incident does not affect customer environments. It has not confirmed that any data left its network, and it has not confirmed the 13.5 GB figure that appears on Cl0p’s leak site alongside a description of PDF drawings, diagrams and blueprints.

Shell said only that it is aware of a “possible incident” and that its security teams and outside experts are investigating. It has not confirmed the 89 GB that Cl0p claims to hold, described on the leak site as engineering drawings, facility photographs and testing-report scans. Shell has history with this extortion brand: it disclosed impact from the 2021 Accellion file-transfer compromise, and in 2023 confirmed a Cl0p-linked MOVEit incident exposed employee data at its Australian BG Group business. The 2026 claim would add a third association, but Shell has not yet confirmed anything was taken this time.

Fiserv’s response is the sharpest contrast between claim and confirmation in this story. Cl0p’s listing puts 874 GB against Fiserv’s name, described as projects, CAD files, Windchill files and software. Fiserv told Reuters that based on its review to date, it has found no evidence that customer, banking, transaction or personal data was compromised, and no evidence that its operating environment was affected, a useful reminder that a leak-site number is not the same thing as a verified loss.

GE, now trading as GE Aerospace on the NYSE under its long-standing ticker GE, told Reuters it is aware of the claim, has activated its cyber response protocols and is assessing the situation. The leak-site entry lists 391 GB under the domain GE.com, described as software backups, system files and project data. No independently verified evidence reviewed for this article shows that customer, patient or banking data was exposed at any of the four companies.

The Windchill vulnerability behind the wider campaign

The likely reason this wave of claims looks so similar across companies is a vulnerability security researchers have tracked since June. PTC Windchill is product lifecycle management software that companies use to store engineering and manufacturing data. FlexPLM is a related product aimed at retail, footwear and apparel workflows. Both were affected by CVE-2026-12569, a critical flaw that allows unauthenticated remote code execution through deserialization of untrusted data. PTC’s own scoring puts it at 9.3 under CVSS v4.0; the National Vulnerability Database scores the same flaw at 9.8 under CVSS v3.1, a difference that reflects the two scoring systems rather than any disagreement about severity.

PTC disclosed the vulnerability on June 17 and began publishing patches the following day, with further fixes and indicator updates continuing into late July. CISA added the flaw to its Known Exploited Vulnerabilities catalog on June 25, with a federal remediation deadline three days later. Ransom-ISAC, a threat-intelligence group tracking the campaign alongside eCrime.ch and DEFUSED, suspects Cl0p-affiliated actors were already exploiting the flaw as a zero-day in early June, before PTC or CISA had published anything. That is Ransom-ISAC’s assessment, framed in its own advisory as a suspicion rather than a proven fact. It matters because it means patching in June may have come too late for organizations already compromised.

Ransom-ISAC’s advisory lays out a specific chain: attackers first pull information through the FlexPLM WSDL endpoint without authenticating, then chain that with a flaw in the Windchill login servlet to gain remote code execution. From there they drop JSP webshells with hexadecimal filenames inside the Windchill login directory, enumerate the file system, and stage data for exfiltration. Sectors Ransom-ISAC has observed in this campaign include manufacturing, automotive, aerospace and retail or apparel, the kind of companies that tend to run a PLM platform in the first place.

The extortion phase followed a now-familiar delay. Ransom-ISAC says it began observing Cl0p extortion emails on July 20, sent to hundreds of employees inside affected organizations from what appeared to be compromised internal accounts, with a subject line referencing a “Windchill PDMLink module serious data leak.” A security consultant separately told Reuters that some organizations began receiving notices around July 19 or 20. Public naming on the leak site did not start until weeks later, in the August 5 to August 12 wave.

Why engineering data changes the breach equation

Most of what Cl0p describes on its leak site is not the kind of data that triggers a typical breach-notification headline. The recurring terms are CAD files, engineering drawings, blueprints, project files, software and database backups, not customer records or payment card numbers. Censys, which measures internet-facing systems, noted in a July 30 analysis that Windchill data tends to skew toward engineering and manufacturing content rather than the HR or financial records more common in other extortion campaigns. It also found fewer than 100 internet-exposed Windchill instances going back to June 1, about 80% of them in the United States, with exposure dropping after PTC’s advisory went out.

That does not make the story smaller. A company’s engineering archive can represent years of product development and competitive advantage, even without a single customer record in it. The risk here sits closer to intellectual-property and business-continuity exposure than the identity-theft risk that usually follows a consumer data breach, based on what has been confirmed so far.

A familiar playbook, now aimed at Windchill

This is not a new operating model for Cl0p. Google’s Threat Intelligence Group has traced the same pattern through the group’s activity around Accellion FTA, GoAnywhere MFT, MOVEit, Cleo and Oracle E-Business Suite: find a widely deployed, internet-facing enterprise application, exploit it at scale, steal data quietly, then extort victims publicly weeks or months later. Google has also cautioned that the Cl0p leak site is a brand not tied to one fixed group of people, a reason to describe this as a Cl0p extortion operation rather than attribute it to a single named actor.

Weighing the claims

The more interesting story here is not that a criminal leak site posted a lot of numbers. It is that a specialized enterprise application most security teams do not scrutinize the way they scrutinize email or cloud storage has become a mass-extortion target, leaving the companies now named to prove a negative under public pressure. Fiserv’s flat denial carries weight precisely because it contradicts Cl0p’s own listing, and extortion groups have every incentive to inflate their claims. At the same time, the suspected early-June zero-day window suggests patching alone will not settle the question for organizations exposed before June 17. For anyone running Windchill or FlexPLM, the more prudent path forward looks less like a one-time patch and more like a retrospective look back at what may already have happened.

What Windchill and FlexPLM users should do now

Organizations running either product should apply PTC’s current patches if they have not already, and should not treat patching as proof that no earlier compromise occurred. Given the suspected early-June exploitation window, retrospective log review back to at least June 1 is worth the effort, focused on indicators PTC and Ransom-ISAC have published: webshells matching the pattern /Windchill/login/ followed by a 16-character hexadecimal filename, the header X-windchill-req, and requests to FlexPLM’s WSDL endpoint. Both organizations continue to update their indicator lists, so security teams should pull the current versions directly rather than rely on a list copied from any single article.

Reuters said this week that it still could not verify what Cl0p stole or how much. That gap between claim and confirmation will likely close slowly, company by company, as investigations run their course. What is already clear is that the platforms holding a company’s engineering and product data deserve the same security attention as the ones holding its customer records, because attackers have shown they no longer need the latter to make the former valuable.