WPT A.I CyberSecurity Scoring
WPT
Company Information
Website:http://ptc.co/7LEu30h32CO
Employees number:None
Number of followers:10,315
NAICS:5112
Industry Type:Software Development
Homepage:ptc.co
WPT Risk Score (AI oriented)
Between 600 and 649
WPTSoftware Development
Updated:
24/07/2026
24/07/2026
649/1000
Poor
Caa
WPT Global Score (TPRM)
xxxx
WPTSoftware Development
Score locked

WPTPoor
Current Score
649Caa (POOR)
01000
2 incidents
-113.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
544
JULY 2026
649
JUNE 2026
649
Ransomware
01 Jun 2026 • WPT
PTC and Ransom-ISAC: Cl0p Hackers Exploit Windchill Servers to Steal Companies’ Secret Product Designs
Cl0p Ransomware Exploits PTC Windchill Servers in Targeted Data Theft Campaign
536
CRITICAL-113
PTCRAN1784903272
Cl0p Ransomware Exploits PTC Windchill Servers in Targeted Data Theft Campaign
Cl0p ransomware affiliates are actively exploiting unpatched PTC Windchill and FlexPLM servers to steal sensitive engineering and product-design data from manufacturers, automotive firms, aerospace organizations, and retail apparel companies. The campaign, identified by Ransom-ISAC in collaboration with eCrime.ch and DEFUSED, leverages critical vulnerabilities to gain unauthorized access, exfiltrate intellectual property, and pressure victims through double-extortion tactics.
### Attack Method & Vulnerabilities
The intrusion begins with the exploitation of two flaws:
1. CVE-2026-12569 (CVSS 9.8) – A critical deserialization vulnerability in PTC Windchill PDMLink and FlexPLM versions before 11.0 M030, disclosed on June 17 and added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on June 25.
2. A pre-authentication information disclosure in the FlexPLM WSDL endpoint, chained with a Windchill login servlet weakness to enable remote code execution (RCE) without credentials.
Once inside, attackers deploy JSP webshells, inspect server files, and stage engineering data for theft bypassing traditional phishing or malware delivery methods.
### Extortion & Impact
Following initial access (dating back to early June), Cl0p operators send mass extortion emails to employees, using compromised accounts to amplify pressure. The emails, observed from July 20, warn of a "Windchill PDMLink module serious data leak", forcing organizations to investigate while exposing staff to follow-on phishing attempts.
The breach poses severe risks, as Windchill systems often store unreleased product designs, specifications, and development workflows data that, if leaked, could benefit competitors or criminal buyers. The double-extortion model ensures leverage even if victims restore from backups.
### Indicators of Compromise (IoCs)
Security teams are advised to monitor for:
- C2 IP addresses: `216.152.148.54`, `216.152.151.204`, `104.243.35.63`, `5.180.41.35`
- Malicious JSP webshells: `Windchill/login/[0-9a-f]{16}.jsp`
- Reconnaissance requests: `GET /Windchill/rfa/jsp/login.jsp?wsdl` (response size: 40,454 bytes)
- File artifacts: `flst.txt` (file listing)
### Mitigation & Response
Organizations should:
- Patch vulnerable Windchill/FlexPLM servers immediately.
- Hunt for compromise dating back to early June using published IoCs.
- Review access logs for unusual outbound activity and unexpected JSP files.
- Preserve extortion emails for forensic analysis.
The campaign underscores the risks of unauthenticated RCE flaws in business-critical systems, where delayed patching can lead to rapid data theft and extortion.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MAY 2026
756
APRIL 2026
756
MARCH 2026
756
Breach
01 Mar 2026 • WPT
Paidwork: Infosec expert: Paidwork users' data pwned after 23M-record database dumped online
Massive Data Breach Exposes 23 Million Paidwork Users’ Personal and Financial Information
642
CRITICAL-114
PAI1784551106
Massive Data Breach Exposes 23 Million Paidwork Users’ Personal and Financial Information
A significant data breach has compromised the personal and financial details of over 23 million users of the microtask platform Paidwork, with the exposed database surfacing online earlier this month. The incident, first detected in March, was added to Troy Hunt’s Have I Been Pwned on July 19, confirming the leak of 23,272,765 records.
The breach came to light in April when a threat actor under the alias "HACKFORMETOME" advertised an 11 GB database on a cybercrime forum, claiming it contained records of 22+ million users. The seller attempted to auction the data via Telegram and Tox, though its authenticity was later verified by security researchers.
The exposed data extends far beyond basic contact information, including:
- Bank account numbers
- Phone numbers and physical addresses
- Dates of birth and profile photographs
- IP addresses and device details
- Financial transaction records and payout histories
- Education levels
- Passwords stored as bcrypt hashes (though weak passwords remain vulnerable to cracking)
Paidwork, which allows users to earn small payments for tasks like watching ads, completing surveys, and testing apps, has not publicly acknowledged the breach or responded to inquiries about its authenticity. Users typically need to accumulate at least $10 before cashing out, but the breach now exposes them to heightened risks of identity theft, phishing, and financial fraud.
The full scope of the incident remains unclear, as Paidwork has yet to issue an official statement or confirm remediation efforts.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
756
JANUARY 2026
756
DECEMBER 2025
756
NOVEMBER 2025
756
OCTOBER 2025
756
SEPTEMBER 2025
756
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for WPT ??
What was WPT's A.I Rankiteo Cyber Score in July 2026 ??
What was WPT's A.I Rankiteo Cyber Score in June 2026 ??
What was WPT's A.I Rankiteo Cyber Score in May 2026 ??
What was WPT's A.I Rankiteo Cyber Score in April 2026 ??
What was WPT's A.I Rankiteo Cyber Score in March 2026 ??
What was WPT's A.I Rankiteo Cyber Score in February 2026 ??
What was WPT's A.I Rankiteo Cyber Score in January 2026 ??
What was WPT's A.I Rankiteo Cyber Score in December 2025 ??
What was WPT's A.I Rankiteo Cyber Score in November 2025 ??
What was WPT's A.I Rankiteo Cyber Score in October 2025 ??
What was WPT's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on WPT's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with WPT ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view WPT's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?