Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Clop ransomware targets Windchill, FlexPLM in data theft attacks

    July 25, 2026

    Steam forum ClickFix attacks infect gamers with XMRig cryptominers

    July 25, 2026

    Man gets six years for hacking 750 women’s Snapchat accounts

    July 25, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Clop ransomware targets Windchill, FlexPLM in data theft attacks
    News

    Clop ransomware targets Windchill, FlexPLM in data theft attacks

    adminBy adminJuly 25, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Hacker

    The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign.

    Clop has reportedly been exploiting a critical improper input validation vulnerability tracked as CVE-2026-12569, which allows attackers to execute arbitrary code on vulnerable Windchill and FlexPLM instances.

    As cybersecurity company ReliaQuest reported on Thursday, Clop operators have been deploying JSP webshells that allow them to exfiltrate sensitive data from targeted companies’ compromised PLM platforms.

    image

    “ReliaQuest has observed threat actors actively exploiting CVE-2026-12569, a critical unsafe deserialization vulnerability (CVSS 9.3) affecting PTC Windchill and FlexPLM. Exploitation enables unauthenticated remote code execution and JSP web shell deployment for remote command execution and sensitive product data exfiltration,” the company said.

    “The actor behind these attacks remains unconfirmed. however, the observed tradecraft shares characteristics with previous Cl0p campaigns targeting enterprise applications and high-value data repositories.”

    Clop’s Windchill and FlexPLM attacks were also confirmed yesterday by the Ransomware Information Sharing and Analysis Centre (Ransom-ISAC), a non-profit organization dedicated to the tracking and defense against ransomware threats.

    Ransom-ISAC’s Brandon Parsons from Ascent Solutions told BleepingComputer that Clop is using what appear to be previously compromised email accounts to send extortion messages to multiple employees of targeted organizations.

    Clop extortion email
    Clop extortion email (Ransom-ISAC)

    “The extortion emails appear to originate from randomly compromised accounts, are sent to hundreds of users within an impacted organization and include Cl0p’s latest contact information,” Parsons said. “This extortion approach is consistent with what we observed with the Oracle EBS campaign last year, except for the use of new email addresses.”

    As BleepingComputer has learned, it is a common tactic for this cybercrime group to change email addresses before launching a new extortion campaign.

    Flagged as actively exploited in attacks

    PTC began releasing security patches for the CVE-2026-12569 flaw on June 17 and, while it didn’t confirm in-the-wild exploitation, it released remediation guidance in a private advisory and urged customers to review their environments for indicators of compromise (IOCs).

    After PTC warned customers of “heightened threat activity” on June 26, the Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities catalog and ordered U.S. federal agencies to secure their PTC Windchill and FlexPLM instances within three days.

    According to German news outlet Heise, CVE-2026-12569 also prompted emergency action from German authorities, with the Federal Office for Information Security (BSI) emailing and calling PTC customers in the middle of the night and warning them to patch their systems as quickly as possible.

    German authorities reacted with the same urgency in March after reports that a similar critical Windchill and FlexPLM flaw (CVE-2026-4681) may be exploited or was likely to be exploited soon.

    On Thursday, ReliaQuest advised PTC customers to patch Windchill and FlexPLM systems and place them behind VPNs or trusted access gateways if possible. Additionally, if they suspect compromise, they should isolate the affected servers, collect forensic artifacts, and rotate any exposed credentials before restoring service.

    A PTC spokesperson was not immediately available for comment when contacted by BleepingComputer earlier this week.

    PTC Windchill and PTC FlexPLM are enterprise software platforms in a category known as Product Lifecycle Management (PLM) and used to track, design, and manage products from original idea to final manufacturing.

    The two PLM systems are widely popular among engineering, manufacturing, quality, and supply chain teams across high-profile companies in the aerospace, defense, automotive, heavy machinery, retail, and medtech sectors. PTC says that its products are used by more than 30,000 customers globally, including over 1,500 brand and retail customers using FlexPLM.

    Clop’s data theft campaigns

    The Clop extortion gang has a long history of breaching enterprise platforms in data theft attacks, with previous campaigns targeting Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer file-sharing servers, the latter affecting more than 2,770 organizations worldwide.

    Most recently, it exploited an Oracle EBS zero-day flaw to steal sensitive files from many organizations since early August 2025, including Harvard University, The Washington Post, GlobalLogic, the University of Pennsylvania, Logitech, Estée Lauder, Korean Air, and American Airlines subsidiary Envoy Air.

    After breaching their systems and exfiltrating sensitive documents, Clop publishes the stolen data on its dark web leak site, making it available for download via Torrent if victims refuse to pay a ransom.

    The U.S. Department of State now offers a $10 million reward for information that could link this cybercrime gang’s attacks to a foreign government.

    Update July 24, 07:42 EDT: Added more info on the attacks from Ransom-ISAC.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleSteam forum ClickFix attacks infect gamers with XMRig cryptominers
    admin
    • Website

    Related Posts

    News

    Steam forum ClickFix attacks infect gamers with XMRig cryptominers

    July 25, 2026
    News

    Man gets six years for hacking 750 women’s Snapchat accounts

    July 25, 2026
    News

    ShinyHunters data leaks fuel $2,000 sextortion email scam

    July 25, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202638 Views

    The Canadian Password Playbook: Navigating Compliance and Building Strong Passwords

    March 25, 202634 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202638 Views

    The Canadian Password Playbook: Navigating Compliance and Building Strong Passwords

    March 25, 202634 Views
    Our Picks

    Clop ransomware targets Windchill, FlexPLM in data theft attacks

    July 25, 2026

    Steam forum ClickFix attacks infect gamers with XMRig cryptominers

    July 25, 2026

    Man gets six years for hacking 750 women’s Snapchat accounts

    July 25, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.