Clop Ransomware Gang Exploits Critical Vulnerability in PTC Windchill and FlexPLM Platforms
A new wave of cyber attacks has been unleashed by the Clop ransomware gang, targeting enterprise software platforms used by high-profile companies across various industries. The attackers are exploiting a critical vulnerability in PTC Windchill and FlexPLM instances, allowing them to exfiltrate sensitive data from compromised systems.
The Clop gang’s modus operandi involves deploying JSP webshells on vulnerable Windchill and FlexPLM platforms, enabling unauthenticated remote code execution and sensitive product data theft. This is a particularly worrying development, given the widespread use of these PLM systems by engineering, manufacturing, quality, and supply chain teams in industries such as aerospace, defense, automotive, and healthcare.
According to cybersecurity company ReliaQuest, Clop operators have been actively exploiting the CVE-2026-12569 vulnerability, which was patched by PTC on June 17. However, it appears that many companies are still vulnerable, with ReliaQuest reporting observed exploitation of this critical flaw. The attackers’ tradecraft bears a striking resemblance to previous Cl0p campaigns targeting enterprise applications and high-value data repositories.
As part of their extortion efforts, Clop gang members have begun sending emails from the support@cryptohox.com address, which has been linked to previous campaigns. This tactic is not new for this cybercrime group; they often change email addresses before launching a new extortion campaign. The affected companies are likely receiving threats to either pay a ransom or face data breaches and potential reputational damage.
PTC Windchill and FlexPLM are widely used by over 30,000 customers globally, including more than 1,500 brand and retail customers using FlexPLM. It is essential for these organizations to take immediate action to protect their systems from the ongoing attacks. PTC has released private advisories and remediation guidance, urging customers to review their environments for indicators of compromise (IOCs) and apply security patches as soon as possible.
In June, PTC warned its customers about “heightened threat activity” related to CVE-2026-12569, prompting the Cybersecurity and Infrastructure Security Agency (CISA) to add this vulnerability to its Known Exploited Vulnerabilities catalog. German authorities also took emergency action, emailing and calling PTC customers in the middle of the night to warn them about the urgent need for patching.
To mitigate these attacks, ReliaQuest advises PTC customers to patch Windchill and FlexPLM systems immediately and consider placing them behind VPNs or trusted access gateways. If a compromise is suspected, affected servers should be isolated, forensic artifacts collected, and exposed credentials rotated before restoring service.
The Clop extortion gang’s track record in breaching enterprise platforms for data theft speaks to the ongoing threat posed by these attacks. With their ability to exploit critical vulnerabilities and steal sensitive files from many organizations worldwide, it is essential that companies prioritize robust security measures and stay vigilant against evolving threats like Clop ransomware.
Source: Bleeping Computer — 2026-07-24