● Ransomware

Clop Ransomware Gang Exploits Critical PTC Windchill Flaw in New Data Theft Campaign

July 24, 2026 · snewle
Clop Ransomware Gang Exploits Critical PTC Windchill Flaw in New Data Theft Campaign

The Clop ransomware gang has launched a new data theft extortion campaign targeting organizations running Internet-exposed PTC Windchill and FlexPLM product lifecycle management platforms. Cybersecurity researchers have observed the threat actors exploiting a critical vulnerability to gain unauthorized access and steal sensitive product data from compromised systems.

According to ReliaQuest’s investigation published on Thursday, the attacks leverage CVE-2026-12569, a critical improper input validation vulnerability with a CVSS score of 9.3. This unsafe deserialization flaw enables unauthenticated remote code execution on vulnerable Windchill and FlexPLM instances. The attackers deploy JSP webshells that provide persistent remote access for executing commands and exfiltrating sensitive information from targeted companies’ PLM platforms.

How Are Victims Being Extorted?

Companies affected by the campaign have begun receiving extortion demands from support@cryptohox.com, a new email address associated with the Clop operation. The ransomware gang frequently rotates email addresses when initiating fresh extortion campaigns. Following their established pattern, Clop exfiltrates sensitive documents from breached systems and threatens to publish the stolen data on its dark web leak site via Torrent downloads if victims refuse ransom payments.

What Emergency Actions Were Taken?

PTC began releasing security patches for CVE-2026-12569 on June 17 and issued a private advisory urging customers to examine their environments for indicators of compromise. After PTC warned customers about “heightened threat activity” on June 26, CISA added the vulnerability to its Known Exploited Vulnerabilities catalog and mandated U.S. federal agencies secure their systems within three days.

German authorities responded with exceptional urgency, with the Federal Office for Information Security contacting PTC customers in the middle of the night via email and phone calls, demanding immediate patching. Similar emergency protocols were enacted in March when another critical Windchill and FlexPLM vulnerability, CVE-2026-4681, faced potential exploitation.

Why Are These Platforms High-Value Targets?

PTC Windchill and FlexPLM are enterprise Product Lifecycle Management platforms widely deployed across aerospace, defense, automotive, heavy machinery, retail, and medtech sectors. These systems manage products from initial concept through final manufacturing and are used by engineering, manufacturing, quality, and supply chain teams. PTC reports serving more than 30,000 customers globally, including over 1,500 brand and retail customers utilizing FlexPLM.

What Is Clop’s History With Enterprise Platform Attacks?

The Clop extortion operation maintains an extensive track record of targeting enterprise platforms in data theft campaigns. Previous operations compromised Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer servers, with the MOVEit campaign affecting more than 2,770 organizations worldwide. Most recently, the gang exploited an Oracle EBS zero-day vulnerability since early August 2025, victimizing Harvard University, The Washington Post, GlobalLogic, the University of Pennsylvania, Logitech, Estée Lauder, Korean Air, and American Airlines subsidiary Envoy Air. The U.S. Department of State currently offers a $10 million reward for information linking the cybercrime gang’s activities to foreign governments.

Source: BleepingComputer