Press "Enter" to skip to content

Clop Is Back: Ransomware Gang Targets Windchill and FlexPLM

The Clop (also written Cl0p) ransomware and extortion gang has returned with another large-scale campaign, this time targeting organizations that use PTC Windchill and PTC FlexPLM. While most home users have probably never heard of either product, these systems often contain some of a company’s most valuable intellectual property, making them an attractive target for cybercriminals.

According to security researchers, attackers are actively exploiting a critical vulnerability identified as CVE-2026-12569 to gain access to vulnerable servers, install web shells, steal sensitive information, and later attempt to extort the victim organization.

What are Windchill and FlexPLM?

Unlike office software or email servers, Windchill and FlexPLM are Product Lifecycle Management (PLM) platforms. Think of them as centralized platforms that help companies design, develop, manufacture, and maintain products throughout every stage of a product’s life cycle.

These systems may contain:

  • Engineering drawings and CAD files
  • Product specifications
  • Manufacturing procedures
  • Supplier information
  • Quality assurance documentation
  • Bills of materials
  • Future product plans

PTC says its products are used by more than 30,000 organizations worldwide across industries such as aerospace, automotive, defense, medical technology, manufacturing, retail, and consumer products.

What is happening?

Researchers say Clop operators are exploiting a critical remote code execution vulnerability that allows attackers to compromise Internet-facing Windchill and FlexPLM servers without authentication.

Once inside, the attackers reportedly deploy JSP web shells that provide long-term remote access, search the affected system for valuable files, and exfiltrate that data before demanding payment from the victim organization.

This is another example of “double extortion.” Instead of relying only on encrypting files, attackers first steal confidential information and then threaten to publish it if the victim refuses to pay.

Why should consumers care?

You probably don’t run Windchill or FlexPLM in your home. However, there is a good chance that a company you do business with does.

Many organizations that manufacture or design products use PLM software behind the scenes. If one of those organizations is compromised, the effects can extend well beyond engineering documents.

Depending on what information is stored or connected to these systems, a breach could potentially expose:

  • Employee information
  • Customer information
  • Supplier and partner records
  • Internal business documents
  • Future product information
  • Other sensitive corporate data

While engineering data is usually the primary target, organizations often integrate PLM platforms with ERP systems, document management systems, supplier portals, and other business applications. As a result, a successful intrusion may have broader consequences than simply exposing engineering documents.

Another example of Clop’s evolving strategy

Long-time readers of this blog may remember that Clop has repeatedly shifted its attention toward enterprise software rather than individual computers.

Over the past several years, the group has launched major campaigns against products including:

The common theme is that these platforms often contain large amounts of valuable business information belonging to hundreds or even thousands of organizations. Instead of attacking one computer at a time, compromising one enterprise application can give criminals access to enormous quantities of sensitive data.

What organizations should do

PTC has already released security updates for the affected products, and CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog after active exploitation was confirmed.

Organizations using Windchill or FlexPLM should:

  • Apply PTC’s security updates immediately.
  • Remove unnecessary Internet exposure.
  • Place systems behind VPNs or other trusted access gateways where possible.
  • Investigate for indicators of compromise.
  • Rotate credentials if a compromise is suspected.

Because Clop has a history of moving quickly once vulnerabilities become public, delaying patches can significantly increase the likelihood of compromise.

Final thoughts

This incident is another reminder that cybercriminals increasingly target the software most people have never heard of. Consumers may never log into Windchill or FlexPLM, but the companies that manufacture cars, airplanes, medical devices, clothing, electronics, and countless other products often do.

As we’ve seen with previous Clop campaigns, today’s enterprise vulnerability can become tomorrow’s breach notification. Even if you never use these platforms yourself, understanding how attacks like this unfold helps explain why organizations continue to experience large-scale data breaches and why timely security updates remain so important.

Sources

If you’d like to read our previous coverage of this group, you can browse articles tagged under both Clop and Klop. Some of our earlier articles used the alternate spelling before the group’s name became more widely standardized.


Discover more from Jared's Technology podcast network

Subscribe to get the latest posts sent to your email.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.