CL 0p, a notorious ransomware group, has targeted over 40 organizations by exploiting a critical vulnerability (CVE-2026-12569) in PTC's Windchill and FlexPLM software. This flaw allows for remote code execution through deserialization of untrusted data, impacting all CPS versions and earlier releases. The group is threatening to publish names of victims unless ransoms are paid. Cl0p's custom tools enable extensive data theft without the need for additional software.
Victims include major companies like Shell, Philips, and GE, with stolen data varying from a gigabyte to multiple terabytes and encompassing sensitive engineering documents. The attack highlights risks associated with enterprise software deeply integrated into manufacturing supply chains.