INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Clop ransomware targets Windchill and FlexPLM in data theft
| 2026-07-24 07:36 CRITICAL HIGH RANSOMWARE & EXTORTION DATA BREACH
Executive Summary
AI-generated
The Clop ransomware gang launched a data theft extortion campaign targeting Internet-ex exposed PTC Windchill and FlexPLM instances, exploiting the critical improper input validation vulnerability CVE-2026-12569. The targeted sector includes aerospace, defense, automotive, heavy machinery, retail, and medtech industries, with over 1,500 brand and retail customers using FlexPLM. More than 30,000 PTC customers globally are affected by this attack. Clop operators deployed JSP webshells to exfiltrate sensitive data from compromised PLM platforms, allowing unauthenticated remote code execution and command execution for sensitive product data theft. The current status is that companies have begun receiving extortion emails with new email addresses used by the Clop gang, prompting PTC to release security patches and remediation guidance; U.S. federal agencies are also urged to secure their systems within three days.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-4681, CVE-2026-12569 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
su•••@cr•••.•••
cr•••••.com
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-4681CVE-2026-4681
CVE-2026-12569CVE-2026-12569
Target & Sectors
DACH
DACH
manufacturingmanufacturing
aerospaceaerospace
defensedefense
retailretail
governmentgovernment
automotiveautomotive
Incident Timeline
August 2025
The U.S. Department of State offers a $10 million reward for information that could link the Clop ransomware gang's attacks to a foreign government, targeting Windchill and FlexPLM in data theft attacks starting August 2025.
Click on any entity below to view its context and source!
financial
$10 reward
The U.S. Department of State now
offers a $10 million reward
for information that could link this cybercrime gang's attacks to a foreign government.
2026/07/24
Threat actors, tracked as the Clop gang, have been exploiting a critical improper input validation vulnerability (CVE-2026-12569) to target Internet-exposed PTC Windchill and FlexPLM instances in data theft extortion campaigns.
Click on any entity below to view its context and source!
victims
30,000 customers
PTC says that its products are used by more than 30,000 customers globally, including over 1,500 brand and retail customers using FlexPLM.
victims
1,500 customers
PTC says that its products are used by more than 30,000 customers globally, including over 1,500 brand and retail customers using FlexPLM.
victims
2,770 organizations
…prise platforms in data theft attacks, with previous campaigns targeting
Accellion FTA
,
GoAnywhere MFT
,
SolarWinds Serv-U FTP
,
Cleo
, and
MOVEit Transfer
file-sharing servers, the latter affecting
more than 2,770 organizations worldwide
.
Tactical Metrics
Metrics
victims
30,000
Customers
Click for context!
PTC says that its products are used by more than 30,000 customers globally, including over 1,500 brand and retail customers using FlexPLM.
Metrics
victims
1,500
Customers
PTC says that its products are used by more than 30,000 customers globally, including over 1,500 brand and retail customers using FlexPLM.
Metrics
financial
10,000,000
Reward
The U.S. Department of State now
offers a $10 million reward
for information that could link this cybercrime gang's attacks to a foreign government.
Metrics
victims
2,770
Organizations
…prise platforms in data theft attacks, with previous campaigns targeting
Accellion FTA
,
GoAnywhere MFT
,
SolarWinds Serv-U FTP
,
Cleo
, and
MOVEit Transfer
file-sharing servers, the latter affecting
more than 2,770 organizations worldwide
.
Intelligence Sources
BleepingComputer
2026-07-24
Clop ransomware targets Windchill, FlexPLM in data theft attacks
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T07:16
Comprehensive Tactical Telemetry
Highly Correlated Entities
17x
organisation
Identified Entity
Product Lifecycle Management
entity
6x
industry
Targeted Sector
Manufacturing
sector
6x
attribution
Attributing Entity
The U.S. Department of State
authority
4x
tactic
Cyber Operation Type
Ransomware
tactic
3x
timeline
Temporal Reference
June 17
date
2x
victims
Customers
30,000
customers
2x
vulnerability
Exploited CVE
CVE-2026-12569
cve
2x
general metric
%
54
%
Contextual Telemetry
Context Block
6 METRICS
financial
Reward
10,000,000
reward
victims
Organizations
2,770
organizations
vulnerability
CVSS Score
9
score
general metric
Cve-2026
12,569
cve-2026
target region
Target Country
Germany
country
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.