Fiserv
Incident posture
Timeline
Summary
The Cl0p ransomware group exploited a previously unknown flaw in PTC’s Windchill platform to gain remote access, deploy web shells that exfiltrated databases, engineering files and other corporate data ranging from one gigabyte to several terabytes from over forty organizations including Shell, Philips, Fiserv, GE, Zebra Technologies, Ingersoll Rand, Toast, Mindray and Largan Precision. Affected companies stated they were investigating the claims, with Fiserv reporting that its review found no evidence of customer, banking, transaction or personal data compromise or impact to its operating environment.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In June 2026 the Cybersecurity and Infrastructure Security Agency added the improper input validation flaw tracked as CVE‑2026‑12569 affecting PTC’s Windchill and FlexPLM platforms to its Known Exploited Vulnerabilities catalog, and PTC issued security notices urging customers to apply a patch for the vulnerability that could allow a remote, unauthenticated attacker to achieve arbitrary code execution via specially crafted requests. By late July cybersecurity observers reported exploitation of the flaw in the wild, marking the first time a Windchill vulnerability had been used in an active attack campaign. The Cl0p ransomware group leveraged the vulnerability to deploy web shells that mapped sensitive vault data, decrypted credentials from the Windchill keystore, and incorporated a custom Java class loader enabling execution of additional code inside the application process, effectively creating an unlimited backdoor for lateral movement, ransomware deployment or persistence. On August 12 Cl0p began publishing the full names of alleged victims on its leak site, identifying more than forty organizations that had been targeted in the Windchill campaign, among them the fintech firm Fiserv, and for each victim the group listed the types of data it claimed to have exfiltrated—including databases, project files, backups, photographs, engineering documents, blueprints, diagrams, logs and other corporate files—and asserted that the volume of stolen information per organization ranged from one gigabyte to several terabytes.
Fiserv responded publicly by stating that it was aware of the threat actor’s claims but, based on its comprehensive review to date, had found no evidence that customer, banking, transaction or personal data had been compromised, nor that its operating environment had been affected, and noted that it was continuing to investigate the allegations. Similar statements were issued by Shell, Philips and GE, with Shell indicating it was working with security teams and experts to investigate a possible incident, Philips reporting that it had identified and contained an attempted compromise of a specific enterprise server related to internal data and that the incident did not impact customer environments, and GE saying it had initiated its cyber response protocols and was assessing the potential issue. Reuters could not independently verify the hacking group’s claims regarding the nature or volume of the data allegedly stolen, and the group did not respond to requests for comment. Prior to the Windchill campaign, Ransom‑ISAC had issued a notice on July 22 warning that Cl0p was exploiting vulnerabilities in PTC Windchill and FlexPLM, and Brandon Parsons of Ascent Solutions observed that companies began receiving extortion notices from Cl0p on July 19 or July 20, underscoring the group’s pattern of targeting zero‑day flaws in widely used software rather than specific enterprises. Cl0p had previously conducted comparable data‑theft and extortion operations against vulnerabilities in Oracle E‑Business Suite, MOVEit, Cleo and GoAnywhere, reinforcing its reputation as a professional data extortionist that seeks to monetize access through threats of public disclosure. The situation remained under review by the affected organizations, with no confirmed significant data breach reported by Fiserv or the other named victims at the time of the statements.
Sources
Sources available to members: 2 sources.