Harley-Davidson breach claimed by Cl0p gang with 270GB internal data dump
GE, Henry Pratt, and ALDO also made the Cl0p victim list, along with another 400GB of allegedly published data.

Image by d_odin | Shutterstock
- Cl0p claims it stole 270GB from Harley-Davidson and published a torrent link on its leak site.
- Harley-Davidson says it knows about the claims but has not commented further.
- Cybernews found file and folder names indicating possible links to PTC Windchill software used by manufacturers.
- Windchill systems handle product data and supplier workflows, meaning exposed files could contain sensitive or proprietary information.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
The Cl0p gang claims a 270 GB breach of Harley-Davidson internal networks – the motorcycle giant appearing to be the latest victim of the group’s most recent Windchill ransomware campaign.
Cl0p posted the legendary motorcycle company on its dark victim leak site on Thursday, eventually adding a “PUBLISHED VIA TORRENT, MAGNET LINK” next to its name.
The seasoned ransomware group declared Harley-Davidson to be one of four companies “THAT DID NOT REACH TO US.”
Although Cybernews researchers are still analyzing the data, the magnet link directory shows a total of 270GB of data files in the massive cache.
A spokesperson for Harley-Davidson on Friday told Cybernews the 123-year-old company was aware of the claims but is declining to comment further at this time.
Internal Harley-Davidson files exposed
In typical fashion, the Cl0p gang has only provided a published link to the alleged Harley-Davidson data, allowing viewers to determine for themselves what the dump actually contains.
After reviewing the magnet directory and what was publicly accessible, it appears the leak could have ties to Cl0p’s most recent ransomware campaign targeting manufacturing companies that use Windchill PLM software.
Windchill, made by enterprise software company PTC, is one of the most widely used product lifecycle management platforms among major manufacturers globally.
The publicly viewable directory shows folders labeled for PTC Windchill 13 service pack and third-party software files – notable as Windchill 13 is the latest major software release. Image by Cybernews.
On top of those, Cybernews viewed what appeared to be several Windchill environment indicators, including the following:
- WC12 directory of application components, including install, jmxcore
- Windchill administrator home directory (/home/wcadmin/)
- Solr server, used for Windchill search and indexing
- Vaultlist text file, consistent with Windchill's file-storage architecture
- PublishModeLog and CheckModelInput files, potentially linked to production/application environment
Additional folders and file names worth noting were related to system and administrative information, including server logs, processor and system configuration data, backup information, production environment files, and references to data vaults – although it is unknown what the individual files actually contain.
According to the Windchill-maker, PLM platforms handle real-time workflows between product data, engineers, manufacturers, and third-party suppliers across the entire organization – meaning the potential for sensitive and proprietary data to be exposed could be catastrophic.
Cl0p has also targeted PTC FlexPLM, a separate platform built on Windchill and designed specifically for retail manufacturers in apparel, footwear, and other consumer products – potentially explaining ALDO’s appearance on Thursday's list.
The Cl0p ransomware cartel is responsible for the 2023 infamous MOVEit and Fortra GoAnywhere file management software hacks.
The MOVEIT exploit was one of the largest-ever hacking campaigns, impacting over 2,600 organizations and almost 90 million individuals. The gang reportedly earned between $75 million and $100 million from the MOVEit hacks alone.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.