Cyber Incident Victim: Largan Precision
Timeline
Summary
The Cl0p ransomware group exploited a vulnerability in PTC’s Windchill platform to infiltrate more than forty organizations, including Largan Precision, and exfiltrate data using a web shell that mapped vault data, decrypted credentials and allowed execution of additional code. The stolen information comprised databases, project files, backups, images, engineering documents, blueprints, diagrams, logs and other corporate files, with volumes ranging from one gigabyte to several terabytes per victim. Affected firms such as Shell, Philips, Fiserv, Zebra Technologies, Ingersoll Rand, Toast, Mindray and GE were named on the group’s leak site, though GE was later removed; the companies said they were aware of the claims and were investigating, but none confirmed a significant breach.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 2 techniques |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
The Cl0p ransomware group began exploiting a vulnerability in PTC’s Windchill product lifecycle management platform that was tracked as CVE‑2026‑12569, an improper input validation flaw allowing remote, unauthenticated attackers to achieve arbitrary code execution via specially crafted requests. The vulnerability was added to CISA’s Known Exploited Vulnerabilities catalog in June 2026, and PTC issued warnings about active targeting; German police also reportedly alerted organizations about imminent attacks. Security researchers observed the first successful exploitation in the wild in late July 2026, marking CVE‑2026‑12569 as the inaugural Windchill vulnerability to be used in an actual attack. Cl0p affiliates deployed web shells that provided persistent access, and they coupled these shells with a custom implant designed to deliver full data theft capability without requiring additional tools. The implant mapped sensitive vault data, decrypted every credential stored in the Windchill keystore, and incorporated a custom Java class loader that enabled the execution of arbitrary code within the application process, effectively turning the shell into an unlimited backdoor for lateral movement, ransomware deployment, or persistence. On August 12 2026, Cl0p shifted from posting partial company names on its leak site to publishing the full names of alleged victims, and among the more than forty organizations named was Largan Precision, identified as a key Apple camera lens supplier.

According to the data leaked by Cl0p, the hackers claimed to have exfiltrated a variety of file types from each victim, including databases, project files, backups, photographs and other image files, engineering documents, blueprints, diagrams, logs, and additional corporate documents. The volume of stolen information per organization was said to range from one gigabyte to several terabytes, and the compromised files could contain sensitive personal information and valuable intellectual property, although much of the material might be of low value or already publicly available. Largan Precision was therefore listed as having suffered a data theft incident whose alleged scope and content matched the general pattern described by the ransomware group. While several companies such as Shell, Philips, Fiserv and GE publicly stated that they were aware of the claims and were investigating, none of those entities confirmed a significant data breach; no comparable public statement was attributed to Largan Precision in the source material.
The Cl0p group had previously conducted similar data‑theft and extortion campaigns exploiting vulnerabilities in Oracle E‑Business Suite, MOVEit, Cleo and GoAnywhere software, demonstrating a pattern of targeting widely used enterprise applications for financial gain. The exploitation of CVE‑2026‑12569 represented a notable escalation because it marked the first time a Windchill flaw had been observed in active attacks, underscoring the potential impact of zero‑day vulnerabilities in specialized PLM systems. The incident contributed to a broader wave of ransomware‑related disclosures in mid‑2026, with affected organizations undertaking internal assessments and communicating with stakeholders about the alleged compromises, while the ransomware group continued to publish victim names and purported data inventories on its leak site.