CRITICALRansomware
Global

Clop gang targets Windchill, FlexPLM in data theft attacks

·Source: DataBreaches.net

Updated:

Executive Summary

Sergiu Gatlan reports: The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. Clop has reportedly been exploiting a critical improper input validation vulnerability tracked as CVE-2026-12569, which allows attackers to execute arbitrary code on vulnerable Windchill and FlexPLM instances. As cybersecur

Analysis

Sergiu Gatlan reports: The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. Clop has reportedly been exploiting a critical improper input validation vulnerability tracked as CVE-2026-12569, which allows attackers to execute arbitrary code on vulnerable Windchill and FlexPLM instances. As cybersecurity company... Source

Indicators of Compromise (1)

CVE (1)
CVE-2026-12569
Source Attribution

Originally published by DataBreaches.net on Jul 24, 2026.

Related Threats