What We Know
The Cl0p ransomware group published a list naming over 40 organizations it says were targeted in an extortion campaign tied to PTC Windchill, a development reported by multiple security outlets.2Backed by 2 sourcessecurityweek.comSecurity Affairs
Reporting and monitoring indicate the wave moved from leak-site assertion toward partial corroboration: Philips and Shell have publicly responded to being named, several European organizations appear on the listings, and a second security vendor confirmed the same Windchill webshell artefact that PTC had already documented.1Backed by 1 sourcessecurityweek.com
Security analysts and blogs covering the incident describe the technical linkage to a Windchill webshell artefact and have published lists and analyses of affected organizations while investigations and vendor confirmations continue.1Backed by 1 sourcesSecurity Affairs