Clop Internet-exposed Windchill and FlexPLM data theft extortion campaign
Campaign
Summary
Hide ▲
Show ▼
The Cl0p campaign is targeting internet-exposed PTC Windchill and FlexPLM deployments in a data extortion operation, with CVE-2026-12569 enabling unauthenticated remote code execution and JSP web shell deployment. Researchers said the attackers chain a FlexPLM WSDL information disclosure with a flaw in the Windchill login servlet, then enumerate file systems, stage engineering and design data, and steal sensitive product data. The activity has hit manufacturing, automotive, aerospace, and retail sectors, while PTC issued patches and CISA added the flaw to its Known Exploited Vulnerabilities catalog. Companies have also received extortion emails from [email protected].
Related Happenings
IT services firm in South Asia data exposed after Spirals breach
Data Leak
H score31
First: 16.07.2026 13:00
Last: 16.07.2026 13:00
Sources 1
About this happening:
Spirals stole data from an IT services firm in South Asia, creating extortion leverage and a threat of public exposure. The intrusion moved from initial access to...
IT services firm in South Asia data exposed after Spirals breach
Data LeakAbout this happening: Spirals stole data from an IT services firm in South Asia, creating extortion leverage and a threat of public exposure. The intrusion moved from initial access to...
CISA sets June 28 patch deadline for Cisco Unified Communications Manager Server
Public Sector Action
H score35
First: 26.06.2026 22:43
Last: 26.06.2026 22:43
Sources 1
About this happening:
CISA ordered federal agencies to patch CVE-2026-20230 in Cisco Unified Communications Manager Server by June 28, tightening exposure around an actively exploited...
CISA sets June 28 patch deadline for Cisco Unified Communications Manager Server
Public Sector ActionAbout this happening: CISA ordered federal agencies to patch CVE-2026-20230 in Cisco Unified Communications Manager Server by June 28, tightening exposure around an actively exploited...
PTC Windchill PDMlink and PTC FlexPLM actively exploited RCE (CVE-2026-12569)
Vulnerability
H score43
First: 26.06.2026 15:31
Last: 26.06.2026 15:31
Sources 1
How related:
"In the observed intrusions, this RCE is chained with a separate pre-authentication information-disclosure defect in the FlexPLM WSDL endpoint (CVSS v3.1 7.5) to enable unauthenticated exploitation," researchers Brandon Parsons, Corsin Camichel, and Simo Kohonen said.
About this happening:
CVE-2026-12569 is a critical vulnerability in PTC Windchill and PTC FlexPLM that has been actively exploited for unauthenticated remote code execution and...
PTC Windchill PDMlink and PTC FlexPLM actively exploited RCE (CVE-2026-12569)
VulnerabilityHow related: "In the observed intrusions, this RCE is chained with a separate pre-authentication information-disclosure defect in the FlexPLM WSDL endpoint (CVSS v3.1 7.5) to enable unauthenticated exploitation," researchers Brandon Parsons, Corsin Camichel, and Simo Kohonen said.
About this happening: CVE-2026-12569 is a critical vulnerability in PTC Windchill and PTC FlexPLM that has been actively exploited for unauthenticated remote code execution and...
Latest development: 24.07.2026 10:36
Clop (Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a data theft extortion campaign, reportedly exploiting CVE-2026-12569 to obtain unauthenticated remote code execution and deploy JSP web shells for sensitive product data exfiltration. Companies have also begun receiving extortion emails from [email protected], and ReliaQuest says threat actors are actively exploiting the flaw against PTC Windchill and FlexPLM.
CISA adds CVE-2026-12569 to KEV for PTC Windchill and FlexPLM
Public Sector Action
H score46
First: 26.06.2026 15:31
Last: 26.06.2026 15:31
Sources 1
About this happening:
CISA added CVE-2026-12569 to the KEV catalog after finding active exploitation of PTC Windchill PDMlink and PTC FlexPLM, elevating the flaw to a federal remedi...
CISA adds CVE-2026-12569 to KEV for PTC Windchill and FlexPLM
Public Sector ActionAbout this happening: CISA added CVE-2026-12569 to the KEV catalog after finding active exploitation of PTC Windchill PDMlink and PTC FlexPLM, elevating the flaw to a federal remedi...
2025 Automotive carmakers ransomware surge
Trend
H score34
First: 16.04.2026 11:35
Last: 16.04.2026 11:35
Sources 1
About this happening:
In 2025, ransomware became the fastest-growing and most disruptive threat to automotive carmakers, accounting for 44% of attacks and more than doubling over th...
2025 Automotive carmakers ransomware surge
TrendAbout this happening: In 2025, ransomware became the fastest-growing and most disruptive threat to automotive carmakers, accounting for 44% of attacks and more than doubling over th...
Timeline
-
24.07.2026 10:36 1 articles · 13d ago
PTC releases patches and remediation guidance for CVE-2026-12569
Mitigation Patch UpdatePTC began releasing security patches for CVE-2026-12569 affecting PTC Windchill and FlexPLM and issued private remediation guidance urging customers to review their environments for indicators of compromise.
Show sources
- Clop ransomware targets Windchill, FlexPLM in data theft attacks — www.bleepingcomputer.com — 24.07.2026 10:36
-
24.07.2026 10:36 1 articles · 13d ago
CISA adds CVE-2026-12569 to the Known Exploited Vulnerabilities catalog
Legal Policy Action UpdateAfter PTC warned customers of heightened threat activity, CISA added CVE-2026-12569 to its Known Exploited Vulnerabilities catalog and ordered U.S. federal agencies to secure affected PTC Windchill and FlexPLM instances within three days.
Show sources
- Clop ransomware targets Windchill, FlexPLM in data theft attacks — www.bleepingcomputer.com — 24.07.2026 10:36
-
24.07.2026 10:36 3 articles · 13d ago
Internet-exposed Windchill and FlexPLM instances face active exploitation and extortion emails
Initial DisclosureReliaQuest observed threat actors actively exploiting CVE-2026-12569 against Internet-exposed PTC Windchill and FlexPLM, with unauthenticated remote code execution enabling JSP web shell deployment and sensitive product data exfiltration. Companies also began receiving extortion emails from [email protected], and the observed tradecraft shares characteristics with prior Cl0p campaigns.
Show sources
- Clop ransomware targets Windchill, FlexPLM in data theft attacks — www.bleepingcomputer.com — 24.07.2026 10:36
- Clop ransomware targets Windchill, FlexPLM in data theft attacks — www.bleepingcomputer.com — 24.07.2026 10:36
- Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE — thehackernews.com — 25.07.2026 13:14