Clop Gang Targets Critical PLM Software
Threat actors are exploiting a severe vulnerability in PTC Windchill and FlexPLM to exfiltrate sensitive enterprise product data.
The Clop ransomware group, also known as Cl0p, has turned its focus toward internet-facing PTC Windchill and FlexPLM platforms. By leveraging a critical vulnerability, these operators are conducting a calculated campaign to exfiltrate sensitive product lifecycle data from organizations across the manufacturing and engineering sectors.
Exploitation of Critical Flaws
The campaign centers on the exploitation of CVE-2026-12569, an improper input validation vulnerability within PTC's software suite. This flaw allows unauthorized parties to achieve remote code execution on affected servers. Once access is established, the attackers deploy JSP webshells to maintain persistence and facilitate the systematic theft of internal documents.
ReliaQuest has observed threat actors actively exploiting CVE-2026-12569, a critical unsafe deserialization vulnerability (CVSS 9.3) affecting PTC Windchill and FlexPLM. Exploitation enables unauthenticated remote code execution and JSP web shell deployment for remote command execution and sensitive product data exfiltration.
— ReliaQuest
Coordinated Extortion Tactics
Beyond initial access, the group has adopted a high-volume communication strategy to pressure their victims. Using email accounts that appear to be previously compromised, the threat actors distribute extortion demands to hundreds of employees within a single target organization simultaneously. This tactic mirrors methodologies previously seen during the group's campaign against Oracle EBS, where the attackers rotated through various email addresses to evade automated detection and notification blocking.
- CVE-2026-12569 carries a CVSS severity score of 9.3.
- PTC began releasing security patches for this specific flaw on June 17.
- The U.S. Department of State offers a $10 million reward for information linking the group to foreign governments.
- PTC software is utilized by over 30,000 customers globally, including 1,500 FlexPLM users.
- The MOVEit Transfer campaign attributed to Clop impacted more than 2,770 organizations.
Remediation and Agency Response
Following the emergence of CVE-2026-12569, the Cybersecurity and Infrastructure Security Agency (CISA) included the vulnerability in its Known Exploited Vulnerabilities catalog. Federal agencies were directed to secure their instances within a three-day window. International authorities, including the German Federal Office for Information Security (BSI), have also taken the unusual step of directly contacting affected customers to emphasize the urgency of applying available releasing security patches.
Implications for Product Security
For organizations relying on PLM systems, this campaign underscores the risks inherent in maintaining legacy or unpatched enterprise software with network connectivity. The shift toward targeting high-value repositories like those managed by PTC suggests that attackers are prioritizing data that holds long-term intellectual property value over simple financial disruption. Security teams are encouraged to treat these platforms as critical assets, ensuring they are shielded behind VPNs or trusted access gateways and that rigorous forensic monitoring is in place to identify potential indicators of compromise.
Sources
- BleepingComputer Original source
- added Also reporting
- its Known Exploited Vulnerabilities catalog Also reporting
- releasing security patches Also reporting
Continue Reading
Boston Scientific earnings hit by cyberattack fallout
Medical device giant warns August intrusion will dent Q3 and full-year sales and earnings as recovery drags on.
Spending Spree Unravels $240M Crypto Heist
Young scammers' lavish purchases led FBI to suspects in $240M bitcoin theft.
Grindr's £26M Settlement and the Stakes for User Trust
Grindr agrees to pay £26m to settle U.K. claims over pre-2020 data sharing, without admitting liability.