The Clop ransomware group, also known as Cl0p, is focusing its efforts on a new data theft campaign, specifically targeting PTC Windchill and FlexPLM instances that are exposed on the internet.
According to reports, Clop is exploiting critical CVE-2026-12569, which involves improper input validation vulnerabilities, enabling attackers to execute arbitrary code on susceptible Windchill and FlexPLM systems.
A cybersecurity firm, ReliaQuest, has disclosed that Clop operators are utilizing a JSP web shell to siphon off sensitive data from the compromised Product Lifecycle Management (PLM) platforms of targeted organizations.
ReliaQuest has reported seeing active exploitation of the CVE-2026-12569 vulnerability, which is categorized as a Critical Insecure Deserialization Vulnerability (CVSS 9.3). Successful exploitation leads to unauthenticated remote code execution, also allowing for JSP web shell deployment, subsequently facilitating the transfer of sensitive product data.
While the identities of the attackers remain unconfirmed, their techniques exhibit similarities to past practices of the Cl0p group, known for targeting enterprise applications and high-value data stores.
The recent incidents involving Clop’s attacks on Windchill and FlexPLM were corroborated by the Ransomware Information Sharing and Analysis Center (Ransom-ISAC), a nonprofit organization dedicated to identifying and countering ransomware threats.
Victims have started receiving extortion emails from [email protected], a new email address reportedly employed by the Clop group for these campaigns.
This tactic of changing email addresses before initiating new extortion attempts is common among cybercriminal organizations, including Clop.

Vulnerability Actively Exploited
In response to the escalating threat, PTC began releasing a security patch addressing the CVE-2026-12569 vulnerability. Disclosed on June 17th, the patch laid out remediation guidance even before any active exploits were observed. Additionally, private advisories urged customers to monitor their systems for indicators of compromise (IOCs).
Following PTC’s warning on June 26 regarding “increased threat activity,” the Cybersecurity and Infrastructure Security Agency (CISA) included this vulnerability in its Known Exploited Vulnerabilities Catalog and mandated that U.S. federal agencies secure their PTC Windchill and FlexPLM instances within a specified timeframe.
Reports from German news agency Heise revealed that CVE-2026-12569 also triggered urgent responses from German authorities, with the Federal Office for Information Security (BSI) contacting PTC customers during late hours to emphasize the necessity of urgently patching their systems.
German officials had similarly urged urgent action in March following warnings of a comparable critical vulnerability in Windchill and FlexPLM (CVE-2026-4681).
On Thursday, ReliaQuest advised PTC customers to patch their Windchill and FlexPLM systems and, if feasible, position them behind a VPN or trusted access gateway. If a security breach is suspected, affected servers should be isolated, forensic artefacts collected, and exposed credentials rotated prior to restoring service.
A representative from PTC was not immediately available to comment when reached by BleepingComputer earlier this week.
PTC Windchill and FlexPLM are vital enterprise software platforms categorized as Product Lifecycle Management (PLM) tools, integral for tracking, designing, and managing products from concept through to final manufacturing.
These PLM systems are widely utilized by engineering, manufacturing, quality, and supply chain teams across prominent sectors including aerospace, defense, automotive, heavy equipment, retail, and medical technology. PTC boasts that over 30,000 customers globally use its products, including over 1,500 brand and retail clients leveraging FlexPLM.
Clop Data Theft Campaign Overview
The Clop ransomware gang has a storied history of infiltrating enterprise platforms with data theft operations, having previously targeted systems such as Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer. The latter compromised over 2,770 organizations worldwide.
Recently, Clop exploited a zero-day vulnerability in Oracle EBS to access sensitive files from multiple organizations, including Harvard University, The Washington Post, GlobalLogic, University of Pennsylvania, Logitech, Estée Lauder, Korean Air, and Envoy Air, a subsidiary of American Airlines, since early August 2025.
Upon infiltrating a system and extracting sensitive documents, Clop lists the stolen data on a dark web leak site, available for download via torrent if ransom demands are ignored.
The U.S. State Department is currently offering a $10 million reward for information connecting the cybercriminal organization’s attacks to foreign governments.
Updated July 24, 06:28 EDT: Added link to Ransom-ISAC’s report on Clop’s CVE-2026-12569 attack.
Security teams document 54% of successful attacks and issue a warning on only 14%, with the rest moving unnoticed within the environment.
Picus’ whitepaper demonstrates how to evaluate your SIEM and EDR rules through breach and attack simulations to guarantee threats do not go undetected.
Source: www.bleepingcomputer.com




