Skip to content
Harley-Davidson breach claimed by Cl0p gang with 270GB internal data dump

Harley-Davidson breach claimed by Cl0p gang with 270GB internal data dump

Cybernews September 12, 2026

GE, Henry Pratt, and ALDO also made the Cl0p victim list, along with another 400GB of allegedly published data.

Image by d_odin | Shutterstock

Cl0p claims it stole 270GB from Harley-Davidson and published a torrent link on its leak site.

Harley-Davidson says it knows the claims but has not commented further.

Cybernews found file and folder names indicating possible links to PTC Windchill software used by manufacturers.

Windchill systems handle product data and supplier workflows, meaning exposed files could contain sensitive or proprietary information.

Key Takeaways by nexos.ai , reviewed by Cybernews staff.

The Cl0p gang claims a 270 GB breach of Harley-Davidson internal networks – the motorcycle giant appearing to be the latest victim of the group’s most recent Windchill ransomware campaign.

Cl0p posted the legendary motorcycle company on its dark victim leak site on Thursday, eventually adding a “PUBLISHED VIA TORRENT, MAGNET LINK” to its name.

The seasoned ransomware group declared Harley-Davidson to be one of four companies “THAT DID NOT REACH TO US.”

Although Cybernews researchers are still analyzing the data, the magnet link directory shows a total of 270GB of data files in the massive cache.

A spokesperson for Harley-Davidson on Friday told Cybernews the 123-year-old company was aware of the claims but is declining to further at this time.

Internal Harley-Davidson files exposed

In typical fashion, the Cl0p gang has only provided a published link to the alleged Harley-Davidson data, allowing viewers to determine for themselves what the dump actually contains.

After reviewing the magnet directory and what was publicly accessible, it appears the leak could have ties to Cl0p’s most recent ransomware campaign targeting manufacturing companies that use Windchill PLM software.

Windchill, made by enterprise software company PTC, is one of the most widely used product lifecycle management platforms among major manufacturers globally.

The publicly viewable directory shows folders labeled for PTC Windchill 13 service pack and third-party software files – notable as Windchill 13 is the latest major software release. Image by Cybernews.

On top of those listed above, Cybernews viewed what appeared to be several other Windchill environment indicators, including the following:

WC12 directory of application components, including install, jmxcore

Windchill administrator directory (/ /wcadmin/)

Solr server, used for Windchill and indexing

Vaultlist text file, consistent with Windchill's file-storage architecture

PublishModeLog and CheckModelInput files, potentially linked to production/application environment

Folders and file names also worth noting were related to system and administrative information, including server logs, processor and system configuration data, backup information, production environment files, and references to data vaults – although it is unknown what the individual files actually contain.

According to the Windchill-maker, PLM platforms handle real-time workflows between product data, engineers, manufacturers, and third-party suppliers across the entire organization – meaning the potential for sensitive and proprietary data to be exposed could be catastrophic.

To note, Cybernews attempted to examine the magnet links for GE, ALDO, and Henry Pratt, a global industrial valve manufacturer.

GE’s torrent showed roughly 390GB of data, although the publicly viewable portions consisted primarily of ZIP archives – no mention of Windchill. The ALDO and Henry Pratt directories were not viewable.

Cl0p’s Windchill campaign still expanding

The Cl0p ransomware gang, operating since at least 2019, is no stranger to major extortion, with past campaigns exploiting vulnerabilities in file transfer programs MOVEit , Fortra GoAnywhere , and Cleo .

The Russian-linked group spent most of 2025 extorting companies via a Remote Code Execution (RCE) zero-day in the cloud-based Oracle E-Business Suite (EBS).

In June, Cl0p shifted its focus to exploiting another RCE flaw – this one affecting PTC Windchill PLM systems.

The vulnerability – now patched and cataloged as CVE-2026-12569 – also happened to be a zero-day, allowing Cl0p to gain access to an unknown number of victims without warning.

In July, victims began reporting Cl0p extortion emails with the subject “Windchill PDMLink module serious data leak,” according to Reuters, with the gang publicly naming dozens of alleged victims by August, including GE, Philips, Shell and others.

As part of the latest extortion campaign, Cl0p also targeted PTC FlexPLM, a separate platform built on Windchill and specifically designed for retail manufacturers in apparel, footwear, and other consumer products – potentially explaining ALDO’s appearance on Thursday's list.

Over the years, the hacker group has compromised more than 3,000 major organizations, often publicly taunting victims on its dark leak site and raking in hundreds of millions of dollars.

The gang reportedly earned between $75 million and $100 million from the MOVEit hacks alone.

Ironically, Cl0p, known as a prolific “ransomware” group, appears increasingly uninterested in actually encrypting its victims' systems before exfiltrating their data – instead just focusing on the theft itself, researchers at ZeroFox said in an August profile on the gang.