INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Clop ransomware targets Windchill and FlexPLM in data theft

| 2026-07-24 07:36 CRITICAL HIGH RANSOMWARE & EXTORTION DATA BREACH
Executive Summary
AI-generated
The Clop ransomware gang launched a data theft extortion campaign targeting Internet-ex exposed PTC Windchill and FlexPLM instances, exploiting the critical improper input validation vulnerability CVE-2026-12569. The targeted sector includes aerospace, defense, automotive, heavy machinery, retail, and medtech industries, with over 1,500 brand and retail customers using FlexPLM. More than 30,000 PTC customers globally are affected by this attack. Clop operators deployed JSP webshells to exfiltrate sensitive data from compromised PLM platforms, allowing unauthenticated remote code execution and command execution for sensitive product data theft. The current status is that companies have begun receiving extortion emails with new email addresses used by the Clop gang, prompting PTC to release security patches and remediation guidance; U.S. federal agencies are also urged to secure their systems within three days.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-4681, CVE-2026-12569 and treat internet-facing systems that were not patched in time as potentially compromised until verified. • Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

su•••@cr•••.•••
cr•••••.com
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-4681CVE-2026-4681 CVE-2026-12569CVE-2026-12569
Target & Sectors
DACH DACH manufacturingmanufacturing aerospaceaerospace defensedefense retailretail governmentgovernment automotiveautomotive
Incident Timeline
‎August 2025
The U.S. Department of State offers a $10 million reward for information that could link the Clop ransomware gang's attacks to a foreign government, targeting Windchill and FlexPLM in data theft attacks starting August 2025.
financial $10 reward
‎2026/07/24
Threat actors, tracked as the Clop gang, have been exploiting a critical improper input validation vulnerability (CVE-2026-12569) to target Internet-exposed PTC Windchill and FlexPLM instances in data theft extortion campaigns.
victims 30,000 customers
victims 1,500 customers
victims 2,770 organizations
Tactical Metrics
Metrics
victims
30,000
Customers
Metrics
victims
1,500
Customers
Metrics
financial
10,000,000
Reward
Metrics
victims
2,770
Organizations
Intelligence Sources
BleepingComputer 2026-07-24