Security News

Cl0p Ransomware Gang Exposes 40+ Victims in Major Software Exploit Campaign

Security Week · 19 Aug 2026
Key Takeaway Keep all third-party enterprise software patched and updated promptly, and monitor vendor security advisories closely, since ransomware groups often exploit widely used business software to hit many victims at once.

The Cl0p ransomware group has listed more than 40 victims tied to a campaign exploiting vulnerabilities in PTC Windchill, a widely used product lifecycle management platform. Named organisations include major global companies such as Shell, Philips, Fiserv, Zebra, Mindray, and Largan Precision.

Cl0p is a well-known ransomware group that has previously carried out large-scale attacks by exploiting flaws in enterprise software used by many organisations at once, rather than targeting companies individually. This approach allows the group to compromise multiple victims through a single vulnerability, then pressure them into paying by threatening to leak stolen data publicly.

While this particular campaign has targeted large enterprises, Australian small and medium businesses that use PTC Windchill or similar third-party enterprise software should be aware that these mass-exploitation campaigns can also affect smaller organisations, especially those connected to larger supply chains.

Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from Security Week. We link back to every original so you can read it yourself.