Clop Is Back: This Time It’s Targeting Windchill and FlexPLM

If the past several years have taught us anything, it’s that Clop doesn’t wait for organizations to patch.

Originally emerging around 2019 as a ransomware operation, Clop has evolved into one of the most prolific data extortion groups in the world. Rather than relying solely on traditional ransomware deployments, the group increasingly focuses on exploiting newly disclosed zero-day and n-day vulnerabilities in widely deployed enterprise software to steal sensitive data at scale. We’ve seen this playbook before with Accellion FTA, GoAnywhere MFT, MOVEit Transfer, Cleo, Oracle E-Business Suite – and now, PTC Windchill and FlexPLM.

Multiple recent reports indicate that Clop is actively exploiting CVE-2026-12569, a critical remote code execution vulnerability affecting Internet-facing PTC Windchill and FlexPLM systems. Successful exploitation allows unauthenticated attackers to execute code, deploy web shells, and exfiltrate valuable intellectual property and engineering data before moving directly to extortion. As with previous Clop campaigns, organizations may never see ransomware encryption – the theft of sensitive data alone is often sufficient to pressure victims into negotiations.

Immediate Actions

If your organization operates Windchill or FlexPLM:

  • Immediately identify all Internet-exposed Windchill and FlexPLM instances.
  • Apply PTC’s security updates for all affected versions without delay.
  • Review PTC’s published Indicators of Compromise (IOCs) and hunt for evidence of web shell deployment or unauthorized activity.
  • Inspect authentication logs, web server logs, and application logs for suspicious requests associated with exploitation attempts.
  • Look for signs of data staging or unusual outbound network traffic, particularly involving engineering repositories and PLM data.
  • Reset credentials and review privileged accounts if compromise is suspected.
  • Engage your incident response team immediately if any indicators are identified – early containment can significantly reduce downstream impact.

Clop has repeatedly demonstrated that it can weaponize newly disclosed vulnerabilities within days (sometimes hours) of public disclosure. Organizations running exposed enterprise applications should assume that patch windows are measured in hours, not weeks.

The lesson remains the same: when Clop shifts its attention to a new platform, every unpatched Internet-facing system becomes a potential target.

If your organization suspects compromise or simply wants an expert set of eyes on your exposure before Clop comes knocking, CYPFER’s incident response team is available 24/7 to help with rapid containment, investigation, and recovery. Learn more about how you can protect your organization with CYPFER.

Reference: https://www.ptc.com/en/about/trust-center/advisory-center/active-advisories/windchill-flexplm-rce-vulnerability?srsltid=AfmBOoqLetBG5IO-nQQZkxyovAkfwY9tg1SJdsD3W9N-8LLan4uihgMX

Gerelateerde inzichten

View All Insights Btn-arrowIcon for btn-arrow

Your Complete Cyber Security Partner:
Elke stap, elke dreiging.

At CYPFER, we don’t just protect your business—we become part of it.

Als uitbreiding van je team ligt onze focus exclusief op cybersecurity, voor jouw gemoedsrust. Van incidentenrespons en ransomwareherstel tot digitaal forensisch onderzoek en cyberrisico’s, wij integreren naadloos met je bedrijfsactiviteiten. We staan 24 uur per dag, 7 dagen per week voor je klaar om dreigingen de kop in te drukken en ze voor de toekomst te voorkomen.

Als je voor CYPFER kiest, ervaar je ongeëvenaarde toewijding en expertise. Vertrouw op ons om je bedrijf te allen tijde veilig en weerbaar te houden.

Team of professionals working collaboratively at a desk, focusing on laptops and business tasks in a modern office setting

Ga vandaag nog voor Cyber Certainty™

Wij zorgen dat het hart van je bedrijf blijft kloppen en beschermen je tegen cyberaanvallen. Waar je ook bent, wat de situatie ook is.

Neem vandaag nog contact op met CYPFER Btn-arrowIcon for btn-arrow