Clop Ransomware Group Claims Data Theft from Over 40 Companies, Exploiting PTC Software Flaw
The Clop ransomware group has claimed responsibility for data exfiltration from more than 40 organizations, exploiting a critical vulnerability in PTC's Windchill and FlexPLM software.

The prolific Russian-speaking ransomware group Clop has announced it has stolen sensitive data from over 40 companies, including major corporations like oil giant Shell and manufacturer General Electric. This latest campaign appears to leverage a critical remote code execution (RCE) vulnerability found in PTC's product lifecycle management software, Windchill, and its FlexPLM offering.
Clop, known for its supply-chain attack methodology, specializes in identifying and exploiting unpatched vulnerabilities in widely used software to exfiltrate data and demand ransoms. While the group has not detailed the specific methods used to breach these latest victims, the attacks are strongly linked to exploitation of the PTC software flaw, tracked as CVE-2026-12569. This vulnerability allows for unauthenticated RCE and the deployment of web shells, enabling attackers to execute commands remotely and steal sensitive product data.
Several high-profile companies, including Philips, Fiserv, and ToastTab, were named on Clop's dark web leak site. However, many of these organizations have since stated that no customer data was compromised. ToastTab confirmed unauthorized access to a limited number of internal files, which were contained after isolation of affected systems. Fiserv, which Clop claimed to have stolen 874 gigabytes of data from, also reported that its comprehensive review found no customer, bank, transaction, or personal data was exfiltrated.
Shell acknowledged a cyber incident involving unauthorized access to a third-party managed cloud-based IT service for non-critical operations. The company stated the access was blocked, the platform contained, and there was no operational impact or evidence of sensitive personal data exposure. The stolen data claimed by Clop from Shell reportedly includes engineering drawings, facility photos, testing reports, and project plans.
The PTC vulnerability, CVE-2026-12569, stems from improper deserialization of untrusted data within the Windchill and FlexPLM software. Threat intelligence firm ReliaQuest first observed exploitation in the wild on July 22, noting that successful exploitation could lead to sensitive product data exfiltration. The types of files listed by Clop on its leak site include 'CAD files,' 'Database,' 'Backups,' and 'Projects,' consistent with the nature of the targeted software.
PTC released its first patch for this vulnerability on June 18, urging customers to apply updates promptly to mitigate the risk of exploitation. The ongoing activity by Clop highlights the persistent threat posed by ransomware groups leveraging zero-day or recently patched vulnerabilities in enterprise software to conduct widespread data theft and extortion campaigns.
The scale of this attack, claiming over 40 victims, underscores the significant impact that a single exploited vulnerability can have across a broad range of industries. Organizations relying on PTC's Windchill and FlexPLM software are strongly advised to ensure they have applied the latest security patches and to review their security posture for any signs of compromise.
This new report details the specific technical mechanisms employed by the Cl0p threat group in their exploitation of PTC Windchill servers via CVE-2026-12569. It highlights the deployment of a custom web shell tailored to Windchill's internal structure, capable of exfiltrating credentials and engineering files, and discusses how this implant is designed to evade detection by mimicking normal application traffic.
This new report details a sophisticated, custom-built JavaServer Pages (JSP) web shell specifically tailored for PTC Windchill and FlexPLM servers, which acts as a fully-fledged extortion platform. Unlike generic shells, this implant decrypts credentials from the Windchill keystore, maps sensitive engineering data, and can execute arbitrary code via a custom Java class loader, enabling rapid data exfiltration and post-exploitation activities without requiring additional tooling.
The Cl0p ransomware group has publicly named over 40 victim organizations in connection with its exploitation of vulnerabilities in PTC's Windchill software, including major companies across energy, healthcare, and finance sectors. The group's custom implant provides full data theft capability, mapping sensitive vault data, decrypting credentials, and acting as a backdoor for further malicious activity. While some victims like GE have been removed from Cl0p's leak site, suggesting potential negotiations or ransom payments, many companies are still investigating the claims.
New details reveal that the Clop ransomware group employed a custom-built web shell designed specifically for PTC's Windchill software, which facilitated credential theft and large-scale data exfiltration. This sophisticated toolkit allows attackers to move rapidly from initial access to data theft and further post-exploitation activities without manual command execution, mimicking legitimate software functions to evade detection. The group's pattern of mass-exploiting zero-days in supply chain and product lifecycle management software continues, with this campaign highlighting their readiness to spring into action with tailored tools when opportunities for mass extortion arise.