Clop Ransomware Group Claims Data Theft from Over 40 Companies, Exploiting PTC Software Flaw
The Clop ransomware group has claimed responsibility for data exfiltration from more than 40 organizations, exploiting a critical vulnerability in PTC's Windchill and FlexPLM software.

The prolific Russian-speaking ransomware group Clop has announced it has stolen sensitive data from over 40 companies, including major corporations like oil giant Shell and manufacturer General Electric. This latest campaign appears to leverage a critical remote code execution (RCE) vulnerability found in PTC's product lifecycle management software, Windchill, and its FlexPLM offering.
Clop, known for its supply-chain attack methodology, specializes in identifying and exploiting unpatched vulnerabilities in widely used software to exfiltrate data and demand ransoms. While the group has not detailed the specific methods used to breach these latest victims, the attacks are strongly linked to exploitation of the PTC software flaw, tracked as CVE-2026-12569. This vulnerability allows for unauthenticated RCE and the deployment of web shells, enabling attackers to execute commands remotely and steal sensitive product data.
Several high-profile companies, including Philips, Fiserv, and ToastTab, were named on Clop's dark web leak site. However, many of these organizations have since stated that no customer data was compromised. ToastTab confirmed unauthorized access to a limited number of internal files, which were contained after isolation of affected systems. Fiserv, which Clop claimed to have stolen 874 gigabytes of data from, also reported that its comprehensive review found no customer, bank, transaction, or personal data was exfiltrated.
Shell acknowledged a cyber incident involving unauthorized access to a third-party managed cloud-based IT service for non-critical operations. The company stated the access was blocked, the platform contained, and there was no operational impact or evidence of sensitive personal data exposure. The stolen data claimed by Clop from Shell reportedly includes engineering drawings, facility photos, testing reports, and project plans.
The PTC vulnerability, CVE-2026-12569, stems from improper deserialization of untrusted data within the Windchill and FlexPLM software. Threat intelligence firm ReliaQuest first observed exploitation in the wild on July 22, noting that successful exploitation could lead to sensitive product data exfiltration. The types of files listed by Clop on its leak site include 'CAD files,' 'Database,' 'Backups,' and 'Projects,' consistent with the nature of the targeted software.
PTC released its first patch for this vulnerability on June 18, urging customers to apply updates promptly to mitigate the risk of exploitation. The ongoing activity by Clop highlights the persistent threat posed by ransomware groups leveraging zero-day or recently patched vulnerabilities in enterprise software to conduct widespread data theft and extortion campaigns.
The scale of this attack, claiming over 40 victims, underscores the significant impact that a single exploited vulnerability can have across a broad range of industries. Organizations relying on PTC's Windchill and FlexPLM software are strongly advised to ensure they have applied the latest security patches and to review their security posture for any signs of compromise.