Clop Ransomware Gang Exploits PTC Windchill & FlexPLM in New Data Theft Campaign
The notorious **Clop** ransomware gang is leveraging a critical vulnerability, **CVE-2026-12569**, in **PTC Windchill** and **FlexPLM** instances to conduct a new wave of data theft and extortion. This campaign, confirmed by cybersecurity firms and government agencies, targets sensitive product lifecycle management data from a wide array of industries.
The **Clop** ransomware gang, also tracked as **Cl0p**, is actively exploiting a critical improper input validation vulnerability, **CVE-2026-12569**, in internet-exposed **PTC Windchill** and **FlexPLM** instances. This allows attackers to execute arbitrary code on vulnerable systems.
Cybersecurity firm **ReliaQuest** first reported on Thursday that **Clop** operators have been deploying JSP webshells. These webshells facilitate the exfiltration of sensitive data from compromised Product Lifecycle Management (PLM) platforms.
**ReliaQuest** noted, "**ReliaQuest** has observed threat actors actively exploiting **CVE-2026-12569**, a critical unsafe deserialization vulnerability (CVSS 9.3) affecting **PTC Windchill** and **FlexPLM**. Exploitation enables unauthenticated remote code execution and JSP web shell deployment for remote command execution and sensitive product data exfiltration."
While the actor behind these attacks remains unconfirmed by **ReliaQuest**, the observed tradecraft shares characteristics with previous **Cl0p** campaigns targeting enterprise applications and high-value data repositories.
### Ransomware Information Sharing and Analysis Centre Confirms Attacks
The **Clop** attacks targeting **Windchill** and **FlexPLM** were also confirmed by the **Ransomware Information Sharing and Analysis Centre (Ransom-ISAC)**, a non-profit organization focused on tracking and defending against ransomware threats.
Brandon Parsons from **Ascent Solutions**, representing **Ransom-ISAC**, disclosed that **Clop** is using what appear to be previously compromised email accounts to send extortion messages to multiple employees within targeted organizations.

*Clop extortion email (Ransom-ISAC)*
Parsons stated, "The extortion emails appear to originate from randomly compromised accounts, are sent to hundreds of users within an impacted organization and include **Cl0p**βs latest contact information." He added that "This extortion approach is consistent with what we observed with the Oracle EBS campaign last year, except for the use of new email addresses."
It's a common tactic for this cybercrime group to change email addresses before launching a new extortion campaign.
### Vulnerability Flagged as Actively Exploited
**PTC** began releasing security patches for the **CVE-2026-12569** flaw on June 17. While **PTC** did not explicitly confirm in-the-wild exploitation, it issued remediation guidance in a private advisory, urging customers to review their environments for indicators of compromise (IOCs).
Following **PTC**'s warning of "heightened threat activity" on June 26, the **Cybersecurity and Infrastructure Security Agency (CISA)** added the vulnerability to its **Known Exploited Vulnerabilities catalog**. **CISA** mandated U.S. federal agencies to secure their **PTC Windchill** and **FlexPLM** instances within three days.
German news outlet **Heise** reported that **CVE-2026-12569** also prompted emergency action from German authorities. The **Federal Office for Information Security (BSI)** emailed and called **PTC** customers in the middle of the night, urging them to patch their systems immediately.
German authorities showed similar urgency in March after reports of another critical **Windchill** and **FlexPLM** flaw (**CVE-2026-4681**) potentially being exploited or likely to be exploited soon.
### Mitigation Recommendations
**ReliaQuest** advises **PTC** customers to patch **Windchill** and **FlexPLM** systems and, if possible, place them behind VPNs or trusted access gateways. In cases of suspected compromise, organizations should isolate affected servers, collect forensic artifacts, rotate any exposed credentials, and then restore service.
**PTC Windchill** and **PTC FlexPLM** are enterprise software platforms in the Product Lifecycle Management (PLM) category. They are crucial for tracking, designing, and managing products from conception to manufacturing. These systems are widely used by engineering, manufacturing, quality, and supply chain teams in high-profile companies across sectors such as aerospace, defense, automotive, heavy machinery, retail, and medtech. **PTC** states its products are used by over 30,000 customers globally, with more than 1,500 brand and retail customers using **FlexPLM**.
### Clop's History of Data Theft Campaigns
The **Clop** extortion gang has a long history of breaching enterprise platforms for data theft. Previous campaigns targeted **Accellion FTA**, **GoAnywhere MFT**, **SolarWinds Serv-U FTP**, **Cleo**, and **MOVEit Transfer** file-sharing servers. The **MOVEit Transfer** attack alone affected over 2,770 organizations worldwide.
More recently, **Clop** exploited an **Oracle EBS** zero-day flaw to steal sensitive files from numerous organizations since early August 2025. Notable victims included **Harvard University**, **The Washington Post**, **GlobalLogic**, the **University of Pennsylvania**, **Logitech**, **EstΓ©e Lauder**, **Korean Air**, and **American Airlines** subsidiary **Envoy Air**.
After breaching systems and exfiltrating sensitive documents, **Clop** typically publishes the stolen data on its dark web leak site, making it available for download via Torrent if victims refuse to pay a ransom.
The U.S. Department of State currently offers a $10 million reward for information linking this cybercrime gang's attacks to a foreign government.