Menu
Browse

Cyber Incident Victim: Toast

Date

Jul 2026

Location

Status

Unknown

Updated

2026-08-23 20:11

Timeline
Occurred
Jul 2026
Discovered
Jun 2026
Disclosed
Aug 2026
Resolved
Pending
Summary

The Cl0p ransomware group exploited a vulnerability in PTC’s Windchill product lifecycle management platform to deploy a custom web shell that gave attackers full access to victims’ data, including databases, project files, backups, photographs, engineering documents, blueprints, diagrams, logs and other corporate files, with stolen amounts ranging from one gigabyte to several terabytes per organization. Among the more than forty named targets were Shell, Philips, Fiserv, Zebra Technologies, Ingersoll Rand, Toast, Mindray and Largan Precision, while GE was initially listed but later removed; the affected companies said they are aware of the claims and are investigating, though none has confirmed a significant breach and many have reportedly refused to pay a ransom.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 2 techniques
Threat Actor Type Location
1 actor Available to members Available to members

Description

The vulnerability tracked as CVE-2026-12569 in PTC’s Windchill and FlexPLM platforms was identified as an improper input validation flaw allowing remote, unauthenticated attackers to achieve arbitrary code execution. In June 2026 the Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog and PTC issued warnings about active exploitation attempts. Security observers noted that exploitation was anticipated, with German police alerting organizations about imminent attacks, and the flaw became the first ever Windchill vulnerability observed being exploited in the wild. By late July 2026 cybersecurity firms reported that Cl0p ransomware affiliates were actively exploiting CVE-2026-12569 to deploy web shells that granted unauthorized access to Windchill environments. These web shells were coupled with a custom implant described by ReliaQuest as providing full data theft capability, including credential decryption from the Windchill keystore and a Java class loader enabling execution of additional code inside the application process. On August 12 2026 the Cl0p group began publishing the full names of alleged victims on its leak site, having previously listed only partial identifiers.

Cyber Incident Image

For each named organization the attackers disclosed the type and estimated volume of data they claimed to have exfiltrated, with amounts ranging from one gigabyte to several terabytes per victim. The disclosed data categories included databases, project files, backups, photographs and other image files, engineering documents, blueprints, diagrams, logs and assorted corporate documents. Toast, identified as a point‑of‑the‑sale software maker, appeared among the more than forty organizations listed as alleged victims of the Windchill campaign. Companies such as Shell, Philips, Fiserv and GE publicly stated they were aware of the claims and were conducting investigations, though none had confirmed a significant data breach at the time of reporting. The article notes that many of the targeted organizations likely refused to pay a ransom because much of the purportedly stolen information may be of little value and already present in the public domain. No specific details regarding Toast’s alleged data loss, response actions, or any public statement from Toast are provided in the source material.

Sources
Sources available to members
2 sources