Close Menu
NCIJ Network |NCIJ Network |
    What's Hot

    British-born man living in US since age of nine held by ICE under threat of deportation | ICE (US Immigration and Customs Enforcement)

    July 24, 2026

    ‘It’s generations of decline’: can Andy Burnham really end rough sleeping? | Homelessness

    July 24, 2026

    Burnham urged to lobby EU leaders directly to waive EES border controls | Travel & leisure

    July 24, 2026
    Facebook X (Twitter) Instagram
    Trending
    • British-born man living in US since age of nine held by ICE under threat of deportation | ICE (US Immigration and Customs Enforcement)
    • ‘It’s generations of decline’: can Andy Burnham really end rough sleeping? | Homelessness
    • Burnham urged to lobby EU leaders directly to waive EES border controls | Travel & leisure
    • Best Window Air Conditioners of 2026: Midea, Zafro, GE
    • Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do
    • Hyperliquid RWA Trading Surpasses All Other Asset Categories
    • Milwaukee Public Schools weighs sending more students on county buses
    • Aid cuts will harm lives and livelihoods in Somalia | Foreign policy
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network |NCIJ Network |
    Friday, July 24
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network |NCIJ Network |
    Home»Cybersecurity

    Clop ransomware targets Windchill, FlexPLM in data theft attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 24, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign.

    Clop has reportedly been exploiting a critical improper input validation vulnerability tracked as CVE-2026-12569, which allows attackers to execute arbitrary code on vulnerable Windchill and FlexPLM instances.

    As cybersecurity company ReliaQuest reported on Thursday, Clop operators have been deploying JSP webshells that allow them to exfiltrate sensitive data from targeted companies’ compromised PLM platforms.

    image

    “ReliaQuest has observed threat actors actively exploiting CVE-2026-12569, a critical unsafe deserialization vulnerability (CVSS 9.3) affecting PTC Windchill and FlexPLM. Exploitation enables unauthenticated remote code execution and JSP web shell deployment for remote command execution and sensitive product data exfiltration,” the company said.

    “The actor behind these attacks remains unconfirmed. however, the observed tradecraft shares characteristics with previous Cl0p campaigns targeting enterprise applications and high-value data repositories.”

    As BleepingComputer has learned, companies have begun to receive extortion emails from support@cryptohox.com, which is one of the new email addresses being used by the Clop gang.

    It is a common tactic for this cybercrime group to change email addresses before launching a new extortion campaign.

    Clop announcing new email addresses
    Clop announcing new email addresses (BleepingComputer)

    Flagged as actively exploited in attacks

    PTC began releasing security patches for the CVE-2026-12569 flaw on June 17 and, while it didn’t confirm in-the-wild exploitation, it released remediation guidance in a private advisory and urged customers to review their environments for indicators of compromise (IOCs).

    After PTC warned customers of “heightened threat activity” on June 26, the Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities catalog and ordered U.S. federal agencies to secure their PTC Windchill and FlexPLM instances within three days.

    According to German news outlet Heise, CVE-2026-12569 also prompted emergency action from German authorities, with the Federal Office for Information Security (BSI) emailing and calling PTC customers in the middle of the night and warning them to patch their systems as quickly as possible.

    German authorities reacted with the same urgency in March after reports that a similar critical Windchill and FlexPLM flaw (CVE-2026-4681) may be exploited or was likely to be exploited soon.

    On Thursday, ReliaQuest advised PTC customers to patch Windchill and FlexPLM systems and place them behind VPNs or trusted access gateways if possible. Additionally, if they suspect compromise, they should isolate the affected servers, collect forensic artifacts, and rotate any exposed credentials before restoring service.

    A PTC spokesperson was not immediately available for comment when contacted by BleepingComputer earlier this week.

    PTC Windchill and PTC FlexPLM are enterprise software platforms in a category known as Product Lifecycle Management (PLM), used to track, design, and manage products from original idea to final manufacturing.

    The two PLM systems are widely popular among engineering, manufacturing, quality, and supply chain teams across high-profile companies in the aerospace, defense, automotive, heavy machinery, retail, and medtech sectors. PTC says that its products are used by more than 30,000 customers globally, including over 1,500 brand and retail customers using FlexPLM.

    Clop’s data theft campaigns

    The Clop extortion gang has a long history of breaching enterprise platforms in data theft attacks, with previous campaigns targeting Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer file-sharing servers, the latter affecting more than 2,770 organizations worldwide.

    Most recently, it exploited an Oracle EBS zero-day flaw to steal sensitive files from many organizations since early August 2025, including Harvard University, The Washington Post, GlobalLogic, the University of Pennsylvania, Logitech, Estée Lauder, Korean Air, and American Airlines subsidiary Envoy Air.

    After breaching their systems and exfiltrating sensitive documents, Clop publishes the stolen data on its dark web leak site, making it available for download via Torrent if victims refuse to pay a ransom.

    The U.S. Department of State now offers a $10 million reward for information that could link this cybercrime gang’s attacks to a foreign government.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    attacks Clop data FlexPLM ransomware targets theft Windchill
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do

    Man gets six years for hacking 750 women’s Snapchat accounts

    Meta ‘unusual activity’ scam targets Facebook users with supposed PDF attachment

    Data Breach Confirmed After Australian Energy Giant Origin Is Hacked

    US attacks Iran as Houthis allow Chinese ships to pass: What’s the latest? | US-Israel war on Iran News

    Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    British-born man living in US since age of nine held by ICE under threat of deportation | ICE (US Immigration and Customs Enforcement)

    July 24, 2026

    ‘It’s generations of decline’: can Andy Burnham really end rough sleeping? | Homelessness

    July 24, 2026

    Burnham urged to lobby EU leaders directly to waive EES border controls | Travel & leisure

    July 24, 2026

    Best Window Air Conditioners of 2026: Midea, Zafro, GE

    July 24, 2026
    Latest Posts

    Trump slaps 50% tariffs on Canada and Carney vows to ‘intensify’ trade talks

    July 21, 2026

    How Two Brothers Dug for Dead Relatives: With a Shovel and a Kitchen Knife

    July 21, 2026

    Chile floods: Towns evacuated following heavy rain in Coquimbo

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    British-born man living in US since age of nine held by ICE under threat of deportation | ICE (US Immigration and Customs Enforcement)

    July 24, 2026

    ‘It’s generations of decline’: can Andy Burnham really end rough sleeping? | Homelessness

    July 24, 2026

    Burnham urged to lobby EU leaders directly to waive EES border controls | Travel & leisure

    July 24, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.