The Cl0p Windchill breaches: who was named, and who is actually at risk

Nearly fifty organisations went up on an extortion site in August 2026, Shell, Philips, GE and Fiserv among them, after one flaw in engineering software left their servers open. Here is what was taken, what was not, and the honest answer if you are wondering whether it reaches you.

ByNikita Lushpanov· Chief Product Officer ·LinkedIn
Quick answer

The Cl0p group exploited a critical flaw in PTC Windchill and FlexPLM — product design software that many manufacturers expose to the internet — and on 13–14 August 2026 published the names of roughly forty to fifty victims. What the attackers say they took is engineering material: drawings, blueprints, project plans, testing reports, backups. No customer database, no passwords, no card numbers have been claimed or found, and nothing from this campaign has been indexed by any breach-checking service, so nobody can look you up against it. The people with a real exposure are employees, contractors and suppliers whose details sit inside those documents. Everyone else should mainly be sceptical of emails about it.

The companies named so far

The leak site lists roughly forty to fifty organisations. These four are the ones reporters have confirmed by name, with the attackers’ own description of what was taken and what each company has said in response, as of 18 August 2026. A claim on a leak site is an assertion by criminals, not a verified inventory.

Sources: statements given to Reuters and BleepingComputer, 13–17 August 2026.
CompanyWhat the attackers claimWhat the company has said
ShellEngineering drawings, scans of facility testing reports, photographs of facilities and project plans — 89 GB by the attackers’ own count.“We are aware of a potential incident. We are working with our security teams and relevant experts to investigate.”
PhilipsBackups, system files, project files, drawings, diagrams and blueprints; the attackers put the volume at roughly 13.5 GB of PDF drawings and diagrams.Said the activity has no impact on customer environments, and that it is investigating.
General ElectricThe same categories as Philips: backups, system files, project files, drawings, diagrams and blueprints.Said it is working to assess the potential issue.
FiservNamed on the leak site alongside the others; the payment-processing giant is the one name on the list with a direct line to ordinary consumers’ money.Said its review so far has found no evidence that customer, banking, transaction or personal data was compromised.

The leaks that do reach you are the ones you can still check

This campaign has published nothing about you. Plenty of others have. PersProtect shows which known breaches hold your email and where your address and phone are published across 499 broker and people-search sites — then files the removals for you.

Check my exposure — free →

1. What happened, in order

PTC published fixes for a flaw in its Windchill and FlexPLM software on 17 June 2026, and within a day the bug was being reported as exploited in the wild. On 26 June the vendor warned customers of heightened threat activity, and the U.S. Cybersecurity and Infrastructure Security Agency added the flaw to its known-exploited catalogue with a three-day deadline for federal agencies to act. Through July the attackers worked quietly: web shells dropped on internet-facing servers, data pulled out, then extortion emails going out from 20 July under the subject line “Windchill PDMLink module serious data leak”. Nothing was public until 13 and 14 August, when the names went up on the group’s leak site — somewhere between forty and fifty organisations at once, with Shell, Philips, General Electric and Fiserv the ones the press picked up first.

2. Why a design-file server was the target

Windchill is where an engineering company keeps the authoritative copy of everything it is building: drawings, specifications, parts lists, test results, change requests and the approvals attached to each. It is a deliberate single point of truth, which makes it a deliberate single point of failure — one server holding decades of work, often reachable from the internet so that suppliers and remote sites can use it. The flaw let an attacker run code on such a server without any credentials at all. From there, copying the contents is not an exploit so much as a download, and the value of what comes out does not expire the way a stolen password does.

3. What was taken, and what was not claimed

Read the attackers’ own descriptions and the pattern is consistent across the named companies: engineering drawings, diagrams, blueprints, project plans, scans of facility testing reports, photographs of sites, system files and backups. Volumes are quoted in gigabytes of documents — 89 GB attributed to Shell, around 13.5 GB of drawings to Philips. What is conspicuously absent from every one of those descriptions is a customer database. No passwords, no card numbers, no lists of account holders. That is not a company denial, it is what the people who took the files say they took, and it fits the software they took it from.

4. The honest answer to “am I affected”

For the ordinary customer of these brands: on the evidence available today, no. There is no published set of consumer records from this campaign, nothing has been indexed by breach databases, and no notification letters have gone out to individuals. Sites promising to check you against “the Cl0p leak” have nothing to check you against. The people who should pay attention are the ones whose names live inside engineering paperwork — employees, contractors, suppliers and site staff at the named companies, whose contact details and signatures travel inside exactly the documents that were copied. If that is you, the realistic follow-up is a well-informed approach at work rather than anything to do with your personal accounts, and the thing to protect is the habit of verifying who is asking.

5. One bug, dozens of brands: the pattern to expect

This is a method rather than an incident. The same group built its reputation on finding a single flaw in software that hundreds of large organisations expose to the internet, harvesting every reachable instance in one short window, and then releasing the victim names in batches over months. It means the list published in August is a first instalment, not a total; it means individual companies discover they are on it long after the data left; and it means the notifications, if any consumer data does turn up, arrive in a slow drip rather than one announcement. Judging your exposure by whether your bank or your employer has been named this week is reading the wrong signal. The other running extortion campaign of 2026 works the same way with consumer records instead of blueprints.

6. What is worth doing this week

Treat every message about this as unverified until you have opened the company’s own site yourself, and never continue a conversation somebody else started — hang up, close the email, go back through a number or an address you already had. Turn on two-factor authentication on your email account before anything else, because that is the account that resets all the others. If you work at one of the named companies, expect the approach to arrive at work quoting a real project or a real colleague, and check it through an internal channel rather than by replying. And if a genuine notification does eventually land in your post, our guide to breach letters covers how to read what it actually says.

Common questions

The Cl0p Windchill breaches, answered

I am a Shell, Philips, GE or Fiserv customer. Was my data in this?

Nothing published so far says it was. What the attackers describe taking is engineering material — drawings, blueprints, project files, backups of design systems — rather than customer databases, and the software they broke into is not the kind that holds shopping or banking records in the first place. Fiserv has said its review found no evidence that customer, banking, transaction or personal data was compromised, and Philips has said customer environments were not affected. That is where the facts stop today. It is not a guarantee for the months ahead, because reviews of this size keep turning up files nobody expected, but there is no basis right now for treating this as a consumer breach.

Can I check whether I am in this one?

No, and be sceptical of anything that says you can. Nothing from this campaign has been published as a searchable set of email addresses, so it has not reached the breach databases our free check runs against — and it has not reached anyone else’s either. A lookup that comes back empty for this campaign is telling you there is nothing indexed, not that you are clear. Any site offering to tell you whether you were “in the Cl0p leak” is either guessing or collecting your details.

So why does this matter to me at all?

Two reasons. If you work for, contract with or supply one of these companies, your name, work email, phone number and signature may well sit inside the project documents and test reports that were copied, because that is what engineering paperwork looks like — sign-offs, distribution lists, site visit records. And separately, a story this big becomes raw material for people who send emails: an alarming message about a leak at a household-name company gets opened, whether or not the sender knows anything about you.

I got an email saying my data was in the Cl0p leak. Is it real?

Almost certainly not. Companies that find your records in a breach write to you by name through the address they already have for you, and they publish the same notice on their own site where you can go and read it without touching a link. A message that arrives from a sender you do not recognise, asks you to “verify” or “check whether you are affected”, and puts a deadline on it, is working the news rather than the data. Go to the company’s own site the way you normally would and see whether the notice exists there.

What is Windchill, and why would my employer have my details in it?

It is product lifecycle management software — the system engineering firms use to hold the current version of every drawing, specification, bill of materials and change request for the things they build, along with the record of who approved what. FlexPLM is the retail and apparel version of the same idea. Nobody signs up for an account with it as a consumer. You end up inside one as a name on a document: an engineer who released a drawing, a supplier contact on a parts list, a contractor on a site report. That is the population with a real exposure here.

How did they get in, and was it a zero-day?

Through CVE-2026-12569, a flaw in Windchill and FlexPLM rated 9.8 out of 10 that let anyone reach an internet-facing server and run code on it without logging in first. PTC shipped fixes on 17 June 2026 and warned customers of heightened threat activity nine days later, and the U.S. cyber agency put the bug on its known-exploited list with a three-day deadline for federal agencies. So the patch existed well before the names appeared. What separated the companies on this list from everyone else running the same software was the weeks between the fix being available and it being applied.

Will the list get longer?

Expect it to. This is the fourth or fifth time the same group has run this play — find one flaw in a piece of software that hundreds of large organisations expose to the internet, take what is reachable from every instance at once, then publish the names in batches over the following months to keep the pressure on. In the earlier rounds the roll-call kept growing for the better part of a year, and organisations that had no idea they were in it turned up late. A quiet fortnight means nothing either way.

Should I freeze my credit over this?

Not because of this campaign specifically. A freeze answers one question — can somebody open an account in your name — and nothing reported here involves the Social Security numbers or dates of birth that make that possible. It is free at all three bureaus and worth having in place regardless, given how much else has leaked in the past two years. But doing it in response to this particular story would be treating the wrong risk.

You cannot patch a leak. You can shrink what is findable.

See which sites publish your address, phone number and relatives right now — free, in about a minute.

Run a free exposure scan →