The Cl0p cybercrime gang claims it stole 270GB of internal data from Harley-Davidson during its latest extortion campaign. The group has published a torrent link for the files, although the motorcycle manufacturer has not confirmed a data breach.
Initial findings suggest the alleged Harley-Davidson data breach may connect to Cl0p’s campaign against organisations using PTC Windchill product lifecycle management software.
Cl0p Publishes Alleged Harley-Davidson Files
Cl0p added Harley-Davidson to its dark web leak site on Thursday. The gang later updated the entry to say that it had published the stolen information through a torrent and magnet link.
The cybercriminals listed Harley-Davidson alongside three other organisations that allegedly failed to respond to their demands. Cl0p commonly publishes stolen files when victims refuse to negotiate or pay an extortion demand.
A review of the available magnet link directory showed approximately 270GB of data. However, researchers were still analysing the contents and had not confirmed the authenticity of every file.
A Harley-Davidson spokesperson said the company knew about the claims but declined to provide further details. Therefore, the full scope and impact of the alleged incident remain unclear.
Directory Points to a Windchill Environment
Publicly visible file and folder names suggest that the data may have originated from an environment running PTC Windchill. Manufacturers use this product lifecycle management platform to organise product information and coordinate work between engineers, production teams and suppliers.
The directory reportedly contained references to a Windchill 13 service pack and associated third-party software. Researchers also observed several other indicators linked to a Windchill installation.
These included a WC12 application directory, a Windchill administrator home folder and a Solr server used for search and indexing. Other files referenced Windchill’s storage architecture, publishing processes and production environment.
The available directory also listed server logs, hardware configurations, backup information and possible data vault references. However, filenames alone do not reveal what the individual files contain.
Exposed Data Could Include Proprietary Information
Windchill platforms can process sensitive information from across a manufacturer’s operations. This data may involve product designs, engineering records, production workflows and communications with external suppliers.
Consequently, unauthorised access to a Windchill environment could expose valuable intellectual property or operational details. The consequences would depend on which systems Cl0p accessed and what information the gang successfully removed.
No evidence in the available material confirms that customer or employee personal information appears in the Harley-Davidson files. Further analysis would be necessary to determine whether the incident affected individuals or mainly involved internal technical data.
GE, ALDO and Henry Pratt Join Leak Site
Cl0p also added GE, footwear retailer ALDO and industrial valve manufacturer Henry Pratt to its victim list.
A torrent linked to GE contained around 390GB of alleged data. However, the publicly visible portion primarily consisted of compressed archives and did not clearly reference Windchill.
Researchers could not view the directories associated with ALDO and Henry Pratt. As a result, no public evidence currently shows what those archives may contain or whether they connect to the same campaign.
ALDO’s inclusion could relate to PTC FlexPLM, a platform built on Windchill for businesses in the clothing, footwear and consumer goods sectors. However, this possible connection remains unconfirmed.
Cl0p Exploited a Windchill Zero-Day
Cl0p began shifting its attention toward PTC Windchill systems in June 2026. The campaign exploited a remote code execution vulnerability now tracked as CVE-2026-12569.
Attackers used the vulnerability as a zero-day before organisations received a patch. This advantage may have allowed the group to access an unknown number of systems without warning.
By July, targeted companies had started receiving extortion emails that referred to a serious data leak involving the Windchill PDMLink module. Cl0p began naming dozens of alleged victims the following month, including GE, Philips and Shell.
The gang has also targeted PTC FlexPLM systems as part of the campaign. Both platforms can hold valuable commercial and technical information, making them attractive targets for data theft and extortion.
Cl0p Increasingly Focuses on Data Theft
Cl0p has operated since at least 2019 and has built a reputation through large-scale attacks on widely used enterprise software.
Previous campaigns exploited vulnerabilities in MOVEit Transfer, Fortra GoAnywhere and Cleo products. During 2025, the group also targeted organisations through a zero-day flaw in Oracle E-Business Suite.
Researchers estimate that Cl0p has compromised more than 3,000 organisations over the years. Its MOVEit campaign alone reportedly generated between $75 million and $100 million.
Despite its reputation as a ransomware operation, the gang increasingly appears to favour stealing data without encrypting victims’ systems. This approach allows Cl0p to pressure organisations by threatening to publish confidential information while avoiding the complexity of deploying file-encrypting malware.
The alleged Harley-Davidson data breach fits that pattern. Cl0p claims it removed a large collection of internal files and has now released them publicly after the company allegedly failed to respond.


0 responses to “Cl0p Claims 270GB Harley-Davidson Data Breach”