Clop ransomware targets Windchill, FlexPLM in data theft attacks

Clop Ransomware Gang Targets PTC Windchill and FlexPLM in Sophisticated Data Theft Attacks

A highly sophisticated cybercrime group, Clop, has launched a new wave of attacks targeting companies that use PTC Windchill and FlexPLM, enterprise software platforms used for managing complex products from design to manufacturing. The gang is exploiting a critical vulnerability, CVE-2026-12569, to gain access to sensitive data and exfiltrate it from the compromised systems.

The Clop ransomware gang has been active in various forms of cybercrime, including data theft attacks on high-profile companies worldwide. This latest campaign targets Internet-exposed PTC Windchill and FlexPLM instances, which are widely used by engineering, manufacturing, and supply chain teams across industries such as aerospace, defense, automotive, and healthcare.

The exploitation of CVE-2026-12569 allows attackers to execute arbitrary code on vulnerable Windchill and FlexPLM instances. This vulnerability has been patched by PTC since June 17, but many companies may not have applied the necessary security updates yet. The Clop gang is exploiting this flaw to deploy JSP webshells that enable remote command execution and sensitive data exfiltration.

The cybersecurity company ReliaQuest reported observing threat actors actively exploiting CVE-2026-12569 in attacks on Windchill and FlexPLM instances. This exploitation enables unauthenticated remote code execution, making it easier for attackers to gain control over the compromised systems. The Clop gang is using this vulnerability to exfiltrate sensitive data from targeted companies’ PLM platforms.

The attack follows a common pattern used by the Clop ransomware gang in previous campaigns. After breaching their systems and exfiltrating sensitive documents, Clop publishes the stolen data on its dark web leak site, making it available for download via Torrent if victims refuse to pay a ransom. This tactic has been used successfully in various high-profile attacks in the past.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-12569 to its Known Exploited Vulnerabilities catalog on June 26, urging U.S. federal agencies to secure their PTC Windchill and FlexPLM instances within three days. German authorities also took emergency action, emailing and calling PTC customers in the middle of the night and warning them to patch their systems as quickly as possible.

PTC customers are advised to patch Windchill and FlexPLM systems immediately and place them behind VPNs or trusted access gateways if possible. If they suspect compromise, they should isolate the affected servers, collect forensic artifacts, and rotate any exposed credentials before restoring service. This latest attack highlights the importance of prioritizing cybersecurity in software development and deployment.

Companies that use PTC Windchill and FlexPLM should take this threat seriously and review their systems for indicators of compromise (IOCs). It is crucial to apply security patches promptly, as vulnerabilities like CVE-2026-12569 can have severe consequences if left unaddressed. In today’s complex digital landscape, companies must remain vigilant and proactive in defending against sophisticated cyber threats.


Source: Bleeping Computer — 2026-07-24