The long tail of Clop’s PTC hack is just beginning to emerge
Clop mass-exploited CVE-2026-12569 in PTC Windchill and FlexPLM in early June, claiming data theft from dozens of large organizations.
Clop began sending extortion emails in mid-July after exploiting CVE-2026-12569 in PTC Windchill and FlexPLM, likely as a zero-day in early June before PTC's June 17 disclosure and patch. Confirmed victims include Toast and Zebra, while GE, Philips and Shell are among claimed victims. CISA added the flaw, which allows unauthenticated remote code execution, to its KEV catalog on June 25. ReliaQuest said the group used a custom Windchill-specific web shell for credential theft and large-scale exfiltration, echoing its past MOVEit and Oracle E-Business Suite mass-exploitation campaigns.
- Zero-day exploitation likely began in early June, before PTC's June 17 patch
- Toast and Zebra confirmed intrusions, reporting limited impact
- CISA added CVE-2026-12569 to the KEV catalog on June 25
- Custom Windchill web shell enabled credential theft and large-scale data exfiltration
- Campaign mirrors Clop's MOVEit and Oracle E-Business Suite operations
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-12569 | Unauthenticated RCE in PTC Windchill and FlexPLM PTC Windchill and FlexPLM contain an improper input validation flaw (CWE-20) with an associated deserialization of untrusted data weakness (CWE-502) that allows an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request over the network. An attacker who can reach a vulnerable Windchill or FlexPLM server can run arbitrary code on it, potentially gaining a foothold for lateral movement; CISA notes the flaw is being used in ransomware campaigns. All organizations running PTC Windchill or FlexPLM are affected, and the available data does not specify affected version ranges. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2026-06-25 with known ransomware use, and EPSS assigns a 40.6% probability of exploitation within 30 days (99th percentile). No CVSS score or public proof-of-concept is available yet, but the KEV listing confirms exploitation in the wild. Do: Apply the fixes in PTC's security advisory for CVE-2026-12569 to both Windchill and FlexPLM as soon as possible, prioritizing internet-facing instances, and comply with the CISA KEV required action under BOD 26-04 (patch within the required window or discontinue use if mitigations are unavailable). Until patched, restrict network exposure of Windchill/FlexPLM servers and hunt for signs of exploitation or ransomware precursor activity; the available data does not list specific patched versions, so defer to PTC's advisory. | 9.3 | 41% | KEV ransomware |
| moderatelikely on the order of thousands of enterprise deployments (a few thousand Windchill/FlexPLM servers, with only a subset internet-exposed) |
Full article842 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The data theft extortion group likely compromised a critical vulnerability affecting PTC’s product lifecycle management software in June, a month before it sent threatening emails to victims.
Listen to this article
0:00
Learn more.
A notorious cybercrime group has once again exploited a critical zero-day vulnerability on a large scale, claiming it stole data from dozens of organizations, including some of the world’s largest publicly traded companies.
Clop, a prolific but calculated data theft extortion group that’s been active since 2020, began sending threatening emails to its alleged victims in mid-July, according to researchers.
The fallout from the attack spree, which followed a familiar pattern for Clop and its targeted pool of victims, is still evolving as companies hunt for potential signs of compromise.
The vulnerability at the center of Clop’s latest campaign affects a pair of software products from PTC — Windchill and FlexPLM — which manufacturers and retailers, particularly in the manufacturing, aerospace, and automotive industries, use to automate supply chain systems and manage product lifecycles.
“This continues Clop’s trend of targeting SaaS logistics companies’ platforms with zero-days and carrying out mass-exploitation campaigns,” Allan Liska, field chief information security officer at Recorded Future, told CyberScoop.
PTC disclosed the vulnerability — CVE-2026-12569 — on June 17 and issued a patch and initial indicators of compromise the following day.
Yet, that was too late for some of Clop’s known victims who were likely compromised by exploitation of the zero-day in early June, according to Ransom-ISAC.
The Cybersecurity and Infrastructure Security Agency added the defect, which allows unauthenticated attackers to execute code remotely, to its known exploited vulnerabilities catalog June 25.
PTC consistently added new indicators of compromise as they were discovered by researchers. But the company hasn’t said how it first became aware of the vulnerability and ensuing attacks, when the earliest known instance of exploitation occurred or how many customers are known to be compromised.
PTC did not respond to a request for comment.
Clop’s claimed victim set is diverse. The point-of-sale restaurant management platform Toast and software vendor Zebra both told CyberScoop they detected and contained system intrusions, but claimed limited impacts. Other alleged victims, including GE, Philips and Shell, did not respond to requests for comment.
Researchers continue to uncover new details about the tools Clop used once it exploited and gained access to PTC customer systems. ReliaQuest said the group used a custom web shell that gave attackers a direct path to credential theft and large-scale data theft.
The fully equipped extortion platform, which was purpose-built for Windchill, decrypts credentials, delivers malware, and includes tools for sustained access, network traversal and data encryption, ReliaQuest researchers wrote in a report Tuesday.
The toolkit allows attackers to move quickly from initial access to data theft and additional post-exploitation activity without executing manual commands — a framework that mimics Windchill’s standard functions and limits defenders’ ability to detect any malicious activity.
“This campaign is another reminder that Clop remains a sleeping dragon, always looking and preparing to mass exploit vulnerabilities in software that holds sensitive data,” ReliaQuest researchers wrote in the report. “The group commonly goes inactive between campaigns but springs to life with custom-built web shells whenever there is another opportunity for mass extortion.”
The drawn-out impact of Clop’s latest attack spree also mirrors some of its previous campaigns. The threat group has successfully exploited zero-days across multiple technology vendors’ systems, allowing it to steal sensitive data for weeks — sometimes months — from many downstream customers.
Clop targeted dozens of Oracle E-Business Suite customers for more than three months, beginning in the summer of 2025, before it started bombarding victims with extortion emails. The group also achieved mass exploitation as it infiltrated MOVEit environments in 2023, ultimately exposing data from more than 2,300 organizations, making it the largest and most significant cyberattack that year.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/clop-zero-day-attacks-ptc-windchill-flexplm/