Cyber Incident Victim: Ingersoll Rand
Timeline
Summary
The Cl0p ransomware group exploited a vulnerability in PTC’s Windchill PLM platform to gain unauthorized access to the networks of more than forty organizations, including Ingersoll Rand, and deployed a custom web shell that enabled full data theft capability. The attackers exfiltrated a variety of files such as databases, project files, engineering documents and backups, with the volume of stolen data ranging from one gigabyte to several terabytes per victim, and used the access to potentially support further activities like lateral movement or ransomware deployment.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 2 techniques |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
The Cl0p ransomware group began exploiting CVE-2026-12569, an improper input validation vulnerability in PTC’s Windchill and FlexPLM platforms, after the flaw was added to CISA’s KEV catalog in June 2026 and warned about by the vendor. Police in Germany reportedly alerted organizations about imminent attacks, and the vulnerability was first observed being used in the wild in late July 2026. Cl0p affiliates used the flaw to deploy web shells that provided unauthorized access to the Windchill environments of victim organizations, including the industrial equipment manufacturer Ingersoll Rand. The web shells mapped sensitive vault data, decrypted every credential in the Windchill keystore, and incorporated a custom Java class loader that allowed execution of additional code within the application process, effectively creating an unlimited backdoor for lateral movement, ransomware deployment, or persistence. On August 12 2026, Cl0p shifted from listing partial company names to publishing the full names of alleged victims, adding Ingersoll Rand to a list that also included Shell, Philips, Fiserv, Zebra Technologies, Toast, Mindray, and Largan Precision.

For each named victim, Cl0p disclosed the type and estimated volume of data exfiltrated, noting that the stolen information could consist of databases, project files, backups, photographs and other image files, engineering documents, blueprints, diagrams, logs, and other corporate documents, with amounts ranging from one gigabyte to several terabytes per organization. The group asserted that while some of the compromised files might contain sensitive personal information or valuable intellectual property, much of the data could be of limited value and already publicly available, which they suggested explained why many targeted organizations had likely refused to pay a ransom. Ingersoll Rand, like Shell, Philips, Fiserv, and GE, stated that it was aware of the claims and was investigating, but none of these companies had confirmed a significant data breach at the time of reporting. GE’s name was later removed from the Cl0p leak site, a development the source noted could indicate that GE had either agreed to pay a ransom or resumed negotiations with the attackers.
The activity was part of a broader pattern for Cl0p, which had previously conducted similar data‑theft and extortion campaigns exploiting vulnerabilities in Oracle E‑Business Suite, MOVEit, Cleo, and GoAnywhere software. The Windchill campaign marked the first time a vulnerability in PTC’s PLM suite had been exploited in the wild, highlighting a new vector for the group’s operations. No further details about specific remediation steps taken by Ingersoll Rand were provided in the source material.