The Cl0p Windchill breaches: who was named, and who is actually at risk
Nearly fifty organisations went up on an extortion site in August 2026, Shell, Philips, GE and Fiserv among them, after one flaw in engineering software left their servers open. Here is what was taken, what was not, and the honest answer if you are wondering whether it reaches you.
The Cl0p group exploited a critical flaw in PTC Windchill and FlexPLM — product design software that many manufacturers expose to the internet — and on 13–14 August 2026 published the names of roughly forty to fifty victims. What the attackers say they took is engineering material: drawings, blueprints, project plans, testing reports, backups. No customer database, no passwords, no card numbers have been claimed or found, and nothing from this campaign has been indexed by any breach-checking service, so nobody can look you up against it. Harley-Davidson was added to the same leak site on 10 September, with no files, no description and no statement from the company. The people with a real exposure are employees, contractors and suppliers whose details sit inside those documents. Everyone else should mainly be sceptical of emails about it.
The companies named so far
The leak site listed roughly forty to fifty organisations in August. These are the ones reporters have picked out by name, with the attackers’ own description of what was taken and what each company has said in response, as of 23 September 2026. Most of the list stays unnamed in the reporting, and most of the names here have said nothing at all. A claim on a leak site is an assertion by criminals, not a verified inventory: it can be inflated, recycled from an older theft, or simply wrong.
| Company | What the attackers claim | What the company has said |
|---|---|---|
| Shell | Engineering drawings, scans of facility testing reports, photographs of facilities and project plans — 89 GB by the attackers’ own count. | “We are aware of a potential incident. We are working with our security teams and relevant experts to investigate.” |
| Philips | Backups, system files, project files, drawings, diagrams and blueprints; the attackers put the volume at roughly 13.5 GB of PDF drawings and diagrams. | Said the activity has no impact on customer environments, and that it is investigating. |
| General Electric | The same categories as Philips: backups, system files, project files, drawings, diagrams and blueprints. | Said it is working to assess the potential issue. GE’s entry was later taken down from the leak site; reporting notes that a listing usually disappears when a company pays or starts negotiating, but neither GE nor anyone else has confirmed a reason. |
| Fiserv | Named on the leak site alongside the others; the payment-processing giant is the one name on the list with a direct line to ordinary consumers’ money. | Said its review so far has found no evidence that customer, banking, transaction or personal data was compromised. |
| Zebra Technologies | The same catalogue the group posted against every Windchill victim: databases, project files, backups, photographs, engineering documents, blueprints, diagrams and logs. No volume published. | No public statement we have found as of 23 September 2026. |
| Ingersoll Rand | Named in the same batch, with the same list of file categories and no volume attached. | No public statement we have found as of 23 September 2026. |
| Toast | Named in the same batch. The restaurant payments company is the second name on the list, after Fiserv, that ordinary people deal with through a card reader rather than a drawing office. | No public statement we have found as of 23 September 2026. |
| Mindray | Named in the same batch — a medical device maker, with the same file categories and no volume attached. | No public statement we have found as of 23 September 2026. |
| Largan Precision | Named in the same batch — the Taiwanese camera-lens maker, same file categories, no volume attached. | No public statement we have found as of 23 September 2026. |
| Harley-Davidson | Added to the leak site on 10 September 2026, weeks after the Windchill batch and without any inventory of files or sample posted. Reporting has repeated a figure of roughly 270 GB of internal data; nothing published so far backs it up, and no reporting ties this listing to the Windchill flaw rather than to some other way in. | Nothing. As of 23 September 2026 Harley-Davidson has not said publicly whether anyone reached its systems, and has not confirmed that customer, employee or dealer data is involved. |
The leaks that do reach you are the ones you can still check
This campaign has published nothing about you. Plenty of others have. PersProtect shows which known breaches hold your email and where your address and phone are published across 499 broker and people-search sites — then files the removals for you.
Check my exposure — free →1. What happened, in order
PTC published fixes for a flaw in its Windchill and FlexPLM software on 17 June 2026, and within a day the bug was being reported as exploited in the wild. On 26 June the vendor warned customers of heightened threat activity, and the U.S. Cybersecurity and Infrastructure Security Agency added the flaw to its known-exploited catalogue with a three-day deadline for federal agencies to act. Through July the attackers worked quietly: web shells dropped on internet-facing servers, data pulled out, then extortion emails going out from 20 July under the subject line “Windchill PDMLink module serious data leak”. Nothing was public until 13 and 14 August, when the names went up on the group’s leak site — somewhere between forty and fifty organisations at once, with Shell, Philips, General Electric and Fiserv the ones the press picked up first.
2. Why a design-file server was the target
Windchill is where an engineering company keeps the authoritative copy of everything it is building: drawings, specifications, parts lists, test results, change requests and the approvals attached to each. It is a deliberate single point of truth, which makes it a deliberate single point of failure — one server holding decades of work, often reachable from the internet so that suppliers and remote sites can use it. The flaw let an attacker run code on such a server without any credentials at all. From there, copying the contents is not an exploit so much as a download, and the value of what comes out does not expire the way a stolen password does.
3. What was taken, and what was not claimed
Read the attackers’ own descriptions and the pattern is consistent across the named companies: engineering drawings, diagrams, blueprints, project plans, scans of facility testing reports, photographs of sites, system files and backups. Volumes are quoted in gigabytes of documents — 89 GB attributed to Shell, around 13.5 GB of drawings to Philips. What is conspicuously absent from every one of those descriptions is a customer database. No passwords, no card numbers, no lists of account holders. That is not a company denial, it is what the people who took the files say they took, and it fits the software they took it from.
4. The honest answer to “am I affected”
For the ordinary customer of these brands: on the evidence available today, no. There is no published set of consumer records from this campaign, nothing has been indexed by breach databases, and no notification letters have gone out to individuals. Sites promising to check you against “the Cl0p leak” have nothing to check you against. The people who should pay attention are the ones whose names live inside engineering paperwork — employees, contractors, suppliers and site staff at the named companies, whose contact details and signatures travel inside exactly the documents that were copied. If that is you, the realistic follow-up is a well-informed approach at work rather than anything to do with your personal accounts, and the thing to protect is the habit of verifying who is asking.
5. One bug, dozens of brands: the pattern to expect
This is a method rather than an incident. The same group built its reputation on finding a single flaw in software that hundreds of large organisations expose to the internet, harvesting every reachable instance in one short window, and then releasing the victim names in batches over months. It means the list published in August is a first instalment, not a total; it means individual companies discover they are on it long after the data left; and it means the notifications, if any consumer data does turn up, arrive in a slow drip rather than one announcement. Judging your exposure by whether your bank or your employer has been named this week is reading the wrong signal. The other running extortion campaign of 2026 works the same way with consumer records instead of blueprints.
6. What changed in September
Two things, and neither of them is a leak of consumer data. On 10 September Harley-Davidson appeared on the group’s site — the most recognisable consumer brand named so far, which is why the question “was Harley-Davidson hacked” started being asked. The listing arrived with no file inventory, no sample and no stated connection to the Windchill flaw, and the company has said nothing publicly, so what exists today is a criminal claim and an absence. Then on 18 September the leak site itself was defaced and taken over by ShinyHunters, a rival extortion crew, which says it also took the site’s source code and the keys to its address. For anyone reading this the practical effect is the same either way: the roll-call is now an unreliable narrator’s list on a site under someone else’s control, and a name appearing or disappearing from it proves less than it did a month ago.
7. What is worth doing this week
Treat every message about this as unverified until you have opened the company’s own site yourself, and never continue a conversation somebody else started — hang up, close the email, go back through a number or an address you already had. Turn on two-factor authentication on your email account before anything else, because that is the account that resets all the others. If you work at one of the named companies, expect the approach to arrive at work quoting a real project or a real colleague, and check it through an internal channel rather than by replying. And if a genuine notification does eventually land in your post, our guide to breach letters covers how to read what it actually says.
The Cl0p Windchill breaches, answered
I am a Shell, Philips, GE or Fiserv customer. Was my data in this?
Nothing published so far says it was. What the attackers describe taking is engineering material — drawings, blueprints, project files, backups of design systems — rather than customer databases, and the software they broke into is not the kind that holds shopping or banking records in the first place. Fiserv has said its review found no evidence that customer, banking, transaction or personal data was compromised, and Philips has said customer environments were not affected. That is where the facts stop today. It is not a guarantee for the months ahead, because reviews of this size keep turning up files nobody expected, but there is no basis right now for treating this as a consumer breach.
Was Harley-Davidson hacked? Should I worry about my bike or my account?
Cl0p put Harley-Davidson on its leak site on 10 September 2026. That is the whole of it so far. No files have been published, the listing came with no description of what was supposedly taken, and Harley-Davidson has not said publicly whether anything happened. Reporting has repeated a figure of around 270 GB of internal data, but that number comes from the claim rather than from anything anyone can look at, and nobody has tied the listing to the engineering-software flaw behind the rest of this campaign. So there is nothing here that says your rider account, your dealership paperwork or your finance details are anywhere. What you can reasonably do is the same thing worth doing before any of this: if you reused your Harley account password elsewhere, change it, and treat unexpected emails about “your Harley-Davidson account” with the suspicion that any big name in the news deserves.
Can I check whether I am in this one?
No, and be sceptical of anything that says you can. Nothing from this campaign has been published as a searchable set of email addresses, so it has not reached the breach databases our free check runs against — and it has not reached anyone else’s either. A lookup that comes back empty for this campaign is telling you there is nothing indexed, not that you are clear. Any site offering to tell you whether you were “in the Cl0p leak” is either guessing or collecting your details.
So why does this matter to me at all?
Two reasons. If you work for, contract with or supply one of these companies, your name, work email, phone number and signature may well sit inside the project documents and test reports that were copied, because that is what engineering paperwork looks like — sign-offs, distribution lists, site visit records. And separately, a story this big becomes raw material for people who send emails: an alarming message about a leak at a household-name company gets opened, whether or not the sender knows anything about you.
I got an email saying my data was in the Cl0p leak. Is it real?
Almost certainly not. Companies that find your records in a breach write to you by name through the address they already have for you, and they publish the same notice on their own site where you can go and read it without touching a link. A message that arrives from a sender you do not recognise, asks you to “verify” or “check whether you are affected”, and puts a deadline on it, is working the news rather than the data. Go to the company’s own site the way you normally would and see whether the notice exists there.
What is Windchill, and why would my employer have my details in it?
It is product lifecycle management software — the system engineering firms use to hold the current version of every drawing, specification, bill of materials and change request for the things they build, along with the record of who approved what. FlexPLM is the retail and apparel version of the same idea. Nobody signs up for an account with it as a consumer. You end up inside one as a name on a document: an engineer who released a drawing, a supplier contact on a parts list, a contractor on a site report. That is the population with a real exposure here.
How did they get in, and was it a zero-day?
Through CVE-2026-12569, a flaw in Windchill and FlexPLM rated 9.8 out of 10 that let anyone reach an internet-facing server and run code on it without logging in first. PTC shipped fixes on 17 June 2026 and warned customers of heightened threat activity nine days later, and the U.S. cyber agency put the bug on its known-exploited list with a three-day deadline for federal agencies. So the patch existed well before the names appeared. What separated the companies on this list from everyone else running the same software was the weeks between the fix being available and it being applied.
Will the list get longer?
Expect it to. This is the fourth or fifth time the same group has run this play — find one flaw in a piece of software that hundreds of large organisations expose to the internet, take what is reachable from every instance at once, then publish the names in batches over the following months to keep the pressure on. In the earlier rounds the roll-call kept growing for the better part of a year, and organisations that had no idea they were in it turned up late. A quiet fortnight means nothing either way.
Should I freeze my credit over this?
Not because of this campaign specifically. A freeze answers one question — can somebody open an account in your name — and nothing reported here involves the Social Security numbers or dates of birth that make that possible. It is free at all three bureaus and worth having in place regardless, given how much else has leaked in the past two years. But doing it in response to this particular story would be treating the wrong risk.
You cannot patch a leak. You can shrink what is findable.
See which sites publish your address, phone number and relatives right now — free, in about a minute.
Run a free exposure scan →