Clop Internet-exposed Windchill and FlexPLM data theft extortion campaign
Campaign
Summary
Hide ▲
Show ▼
The Clop ransomware gang (Cl0p) is running a new data theft extortion campaign against Internet-exposed PTC Windchill and FlexPLM instances, putting enterprise PLM data at immediate risk. Reported exploitation of CVE-2026-12569 enables unauthenticated remote code execution and JSP web shell deployment. The operation is already producing extortion emails and threatens the exfiltration of sensitive product data from targeted companies.
Related Happenings
IT services firm in South Asia data exposed after Spirals breach
Data Leak
H score31
First: 16.07.2026 13:00
Last: 16.07.2026 13:00
Sources 1
About this happening:
Spirals stole data from an IT services firm in South Asia, creating extortion leverage and a threat of public exposure. The intrusion moved from initial access to...
IT services firm in South Asia data exposed after Spirals breach
Data LeakAbout this happening: Spirals stole data from an IT services firm in South Asia, creating extortion leverage and a threat of public exposure. The intrusion moved from initial access to...
PTC Windchill PDMlink and PTC FlexPLM actively exploited RCE (CVE-2026-12569)
Vulnerability
H score43
First: 26.06.2026 15:31
Last: 26.06.2026 15:31
Sources 1
How related:
ReliaQuest has observed threat actors actively exploiting CVE-2026-12569, a critical unsafe deserialization vulnerability (CVSS 9.3) affecting PTC Windchill and FlexPLM. Exploitation enables unauthenticated remote code execution and JSP web shell deployment for remote command execution and sensitive product data exfiltration,
About this happening:
CVE-2026-12569 is a critical vulnerability in PTC Windchill and PTC FlexPLM that has been actively exploited for unauthenticated remote code execution and...
PTC Windchill PDMlink and PTC FlexPLM actively exploited RCE (CVE-2026-12569)
VulnerabilityHow related: ReliaQuest has observed threat actors actively exploiting CVE-2026-12569, a critical unsafe deserialization vulnerability (CVSS 9.3) affecting PTC Windchill and FlexPLM. Exploitation enables unauthenticated remote code execution and JSP web shell deployment for remote command execution and sensitive product data exfiltration,
About this happening: CVE-2026-12569 is a critical vulnerability in PTC Windchill and PTC FlexPLM that has been actively exploited for unauthenticated remote code execution and...
Latest development: 24.07.2026 10:36
Clop (Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a data theft extortion campaign, reportedly exploiting CVE-2026-12569 to obtain unauthenticated remote code execution and deploy JSP web shells for sensitive product data exfiltration. Companies have also begun receiving extortion emails from [email protected], and ReliaQuest says threat actors are actively exploiting the flaw against PTC Windchill and FlexPLM.
Storm-1175 high-velocity exploit campaign
Campaign
H score59
First: 06.04.2026 19:56
Last: 06.04.2026 19:56
Sources 1
About this happening:
Storm-1175 is running a high-velocity exploit campaign that rapidly turns access into Medusa ransomware deployment, creating risk of data exfiltration and encrypte...
Storm-1175 high-velocity exploit campaign
CampaignAbout this happening: Storm-1175 is running a high-velocity exploit campaign that rapidly turns access into Medusa ransomware deployment, creating risk of data exfiltration and encrypte...
Windows .scr phishing campaign delivering JWrapper RMM access
Campaign
H score37
First: 04.02.2026 23:06
Last: 04.02.2026 23:06
Sources 1
About this happening:
The Windows .scr phishing campaign is using business-themed lures to trick users into running screensaver files that install JWrapper and hand attackers interactive...
Windows .scr phishing campaign delivering JWrapper RMM access
CampaignAbout this happening: The Windows .scr phishing campaign is using business-themed lures to trick users into running screensaver files that install JWrapper and hand attackers interactive...
Rising encryptionless extortion incidents against enterprises in 2025
Trend
H score27
First: 15.01.2026 17:45
Last: 15.01.2026 17:45
Sources 1
About this happening:
Encryptionless extortion surged in 2025 as attackers increasingly skipped ransomware encryption and instead stole data to pressure victims across enterprise environments...
Rising encryptionless extortion incidents against enterprises in 2025
TrendAbout this happening: Encryptionless extortion surged in 2025 as attackers increasingly skipped ransomware encryption and instead stole data to pressure victims across enterprise environments...
Timeline
-
24.07.2026 10:36 1 articles · 12h ago
PTC releases patches and remediation guidance for CVE-2026-12569
Mitigation Patch UpdatePTC began releasing security patches for CVE-2026-12569 affecting PTC Windchill and FlexPLM and issued private remediation guidance urging customers to review their environments for indicators of compromise.
Show sources
- Clop ransomware targets Windchill, FlexPLM in data theft attacks — www.bleepingcomputer.com — 24.07.2026 10:36
-
24.07.2026 10:36 1 articles · 12h ago
CISA adds CVE-2026-12569 to the Known Exploited Vulnerabilities catalog
Legal Policy Action UpdateAfter PTC warned customers of heightened threat activity, CISA added CVE-2026-12569 to its Known Exploited Vulnerabilities catalog and ordered U.S. federal agencies to secure affected PTC Windchill and FlexPLM instances within three days.
Show sources
- Clop ransomware targets Windchill, FlexPLM in data theft attacks — www.bleepingcomputer.com — 24.07.2026 10:36
-
24.07.2026 10:36 2 articles · 12h ago
Internet-exposed Windchill and FlexPLM instances face active exploitation and extortion emails
Initial DisclosureReliaQuest observed threat actors actively exploiting CVE-2026-12569 against Internet-exposed PTC Windchill and FlexPLM, with unauthenticated remote code execution enabling JSP web shell deployment and sensitive product data exfiltration. Companies also began receiving extortion emails from [email protected], and the observed tradecraft shares characteristics with prior Cl0p campaigns.
Show sources
- Clop ransomware targets Windchill, FlexPLM in data theft attacks — www.bleepingcomputer.com — 24.07.2026 10:36
- Clop ransomware targets Windchill, FlexPLM in data theft attacks — www.bleepingcomputer.com — 24.07.2026 10:36