Skip to content
Vulnerability exploitOngoing

Cl0p exploits PTC Windchill and FlexPLM flaw in data-theft campaign

Researchers reported that Cl0p was exploiting CVE-2026-12569 in internet-exposed PTC Windchill and FlexPLM product lifecycle management servers to steal engineering data, sending extortion emails to victims from 20 July 2026.

Part of campaigncl0p mass exploitation
Victim
PTC Windchill and FlexPLM customers (Cl0p campaign)
Threat actorCl0p
CVECVE-2026-12569

On 24 July 2026, research by Ransom-ISAC became public showing that the Cl0p extortion group was exploiting internet-facing installations of PTC Windchill and FlexPLM, product lifecycle management (PLM) platforms that store engineering designs, bills of materials and supplier data for manufacturers and retailers. Since 20 July, Cl0p had been sending extortion emails with the subject "Windchill PDMLink module serious data leak" to hundreds of recipients.

The attackers chain a pre-authentication information leak in a FlexPLM WSDL endpoint with CVE-2026-12569, a critical deserialization flaw in the Windchill login servlet that allows unauthenticated remote code execution. Researchers suspect Cl0p used the bug as a zero-day from early June, before PTC's advisory on 17 June; CISA added it to its Known Exploited Vulnerabilities catalog on 25 June.

How the attacks work

After gaining access, the intruders deploy hex-named JSP web shells under /Windchill/login/, enumerate the file system and stage intellectual property such as product designs and supplier information for exfiltration, then follow up with double-extortion demands. ReliaQuest later reported a custom Java class loader that let the attackers run arbitrary code inside the application process. Manufacturing, automotive, aerospace and retail organizations were identified as the most exposed.

Why it matters

The campaign repeats Cl0p's signature model seen with MOVEit, GoAnywhere and Oracle E-Business Suite: find a flaw in a niche enterprise platform that holds high-value data, exploit it at scale, then extort victims in bulk. From 12 August the group began naming victims, and by mid-August it had listed more than 40 organizations, including Shell, Philips, Fiserv and Zebra Technologies, with stolen data ranging from 1 GB to several terabytes per victim. GE was initially listed and later removed. Cl0p claimed about 89 GB from Shell, including technical drawings, facility images, test report scans and project plans, and about 13.5 GB from Philips, mostly diagrams and blueprints. Philips said it had identified and contained an attempted compromise of a specific enterprise server with no customer impact, while Shell, Fiserv and GE said they were aware of the claims and investigating; none confirmed a significant data breach. These victims are sometimes wrongly attributed to Cl0p's Oracle E-Business Suite extortion wave, a separate 2025 campaign.

Timeline

  1. Cl0p is suspected of beginning to exploit CVE-2026-12569 as a zero-day.

  2. PTC publishes an advisory for CVE-2026-12569 in Windchill and FlexPLM.

  3. CISA adds CVE-2026-12569 to its Known Exploited Vulnerabilities catalog.

  4. Cl0p starts sending extortion emails titled 'Windchill PDMLink module serious data leak' to hundreds of recipients.

  5. Ransom-ISAC research attributing the campaign to Cl0p is publicly reported.

  6. Cl0p begins naming victims on its leak site; more than 40 organizations are listed by mid-August.

Sources

  1. techzine.euhttps://www.techzine.eu/news/security/143159/clop-exploits-vulnerability-in-ptc-windchill-and-flexplm/
  2. thehackernews.comhttps://thehackernews.com/2026/07/cl0p-affiliates-target-internet-exposed.html
  3. securityweek.comhttps://www.securityweek.com/cl0p-ransomware-group-names-over-40-victims-of-ptc-windchill-campaign/
  4. dutchnews.nlhttps://www.dutchnews.nl/2026/08/shell-and-philips-hit-by-russian-ransomware-attack/

Related incidents