Clop’s ransomware leak site picked up dozens of new entries this month, and the common thread running through them is not a phishing email or a stolen password. It is PTC Windchill, product lifecycle management software installed inside more than 30,000 manufacturing, aerospace, retail and industrial companies worldwide, according to BleepingComputer. The Clop extortion group is exploiting a critical flaw tracked as CVE-2026-12569 to break into internet-facing Windchill and FlexPLM servers, pull out engineering and product data, and threaten to publish it unless victims pay.
By late August 2026, Clop had listed more than 40 organizations on its leak site tied to the campaign, with SecurityWeek putting the figure at 43. The list includes General Electric, Royal Philips and Shell. GE and Philips have both confirmed they are investigating Clop’s data theft claims, while Shell says it is looking into what it calls a potential incident after Clop claimed to have taken 89 gigabytes of company data.
The Clop ransomware campaign is the latest version of a strategy the group has run for years: find one flaw in software that hundreds of companies rely on, exploit it quietly before anyone notices, then run a slower public extortion operation once the access phase winds down. This time the target is the software that tracks how products get designed, engineered and shipped.
What Is CVE-2026-12569 and How Clop Is Exploiting It
CVE-2026-12569 is a critical improper input validation and unsafe deserialization flaw in PTC Windchill PDMLink and PTC FlexPLM, the company’s product lifecycle management platforms, according to SecurityWeek and BleepingComputer. PTC’s own severity assessments range as high as 9.3 to 10.0 depending on deployment configuration, and some third-party scoring has put it as high as 9.8.
Windchill is the platform engineering teams use to manage product designs, bills of materials and manufacturing documentation. FlexPLM is a variant built for retail and apparel companies that need to track a product from sketch to store shelf. Both share the underlying flaw, and both are reachable from the open internet in many customer deployments, because suppliers and design partners need remote access to collaborate.
Researchers at ReliaQuest, who confirmed active exploitation, described a two-step attack chain. Attackers first pull information out of a pre-authentication disclosure bug in the FlexPLM WSDL endpoint, then use it to exploit a separate flaw in the Windchill login servlet. The combination produces unauthenticated remote code execution, meaning an attacker never needs a valid username or password to take over a server.
Once inside, Clop’s affiliates plant a custom Java-based webshell with a hexadecimal filename inside the /Windchill/login/ directory, where it blends in with legitimate login-related files. ReliaQuest said the implant can decrypt credentials stored in the Windchill keystore, enumerate connected file repositories, and pull data out in bulk, giving attackers a fast path from initial access to full data theft.
Timeline: From Silent Patch to Public Extortion
PTC began shipping patches for CVE-2026-12569 on June 17, 2026, initially through a private advisory sent directly to customers rather than a public bulletin, BleepingComputer reported. Vendors often try to get ahead of a bug this way before attackers notice it, but it does not always work. Researchers believe Clop or its affiliates were already exploiting the flaw as a zero-day by early June, before any patch existed.
By June 26, PTC had escalated its warning to customers, and the Cybersecurity and Infrastructure Security Agency added CVE-2026-12569 to its Known Exploited Vulnerabilities catalog, a designation reserved for flaws with confirmed active exploitation, pushing US federal civilian agencies running Windchill or FlexPLM onto an emergency patch timeline. It is the same emergency-patch playbook CISA used earlier this year after PaperCut’s zero-days landed in the KEV catalog.
The extortion phase followed. Some targets began receiving emails referencing a Windchill data leak in mid-to-late July, and ReliaQuest pinpointed the window of mass exploitation to July 20 through July 26, 2026. Clop initially listed victims with partial or redacted names on its leak site, a pressure tactic the group has used before to push companies into private contact. On August 12, Clop switched to full public disclosure of victim names, SecurityWeek reported, a move that typically signals stalled negotiations. By late August, the published PTC Windchill campaign counted well over 40 named organizations.
CVE-2026-12569 at a Glance
| Detail | Reported figure |
|---|---|
| CVE ID | CVE-2026-12569 |
| Vulnerability type | Improper input validation / unsafe deserialization, unauthenticated RCE |
| Severity | 9.3-10.0 per PTC, up to 9.8 in third-party assessments |
| Affected products | PTC Windchill PDMLink, PTC FlexPLM |
| Patch available since | June 17, 2026 (private advisory) |
| Added to CISA KEV catalog | Around June 26, 2026 |
| Mass exploitation window confirmed | July 20-26, 2026 (ReliaQuest) |
| Victims listed by Clop (late Aug. 2026) | 43 (more than 40 confirmed) |
| Claimed data volumes per victim | Roughly 1 GB to multiple terabytes |
Who’s Been Named: GE, Philips, Shell and Dozens More
Clop’s leak site names a cross-section of global industry. General Electric, Royal Philips and Shell are the highest-profile entries, alongside Fiserv, Zebra Technologies, Ingersoll Rand, Toast, Mindray and Largan Precision, according to SecurityWeek’s review of the campaign. The victim list spans manufacturing, aerospace, automotive, medical devices, payments technology and retail/apparel, reflecting how widely Windchill and FlexPLM sit inside industrial supply chains.
The amount of data Clop claims to have taken varies by target. SecurityWeek reported claimed volumes ranging from roughly 1 gigabyte up to multiple terabytes per organization, depending on how much of a company’s Windchill environment was exposed and how long attackers had access before detection. Shell said Clop claimed to have taken 89 gigabytes of its data and confirmed it is investigating what it called a potential incident, per BleepingComputer’s reporting.
GE and Philips have both acknowledged they are investigating Clop’s claims without confirming the scope of any data theft, eSecurityPlanet reported. Neither company has said which systems were affected or whether personal, employee or customer data was involved, as opposed to internal engineering and product documentation. That distinction matters: PLM systems typically hold intellectual property, technical drawings and supplier data rather than the consumer records that usually trigger breach notification laws, though that depends on what else sits on the same network segment. It’s a different exposure profile than the patient and Social Security data described in the McKesson breach disclosed earlier this month, where the stolen records were explicitly personal and medical.
The Curious Case of GE’s Disappearing Listing
One detail stands out in SecurityWeek’s tracking of the campaign: General Electric was initially listed among Clop’s Windchill victims, then later removed from the leak site without explanation. Researchers who track ransomware leak sites say an entry can disappear for several reasons, including private negotiations opening up, a dispute over the legitimacy of the stolen data, or Clop reassessing what it actually obtained. None of those explanations has been confirmed in GE’s case, and GE has not said publicly why its entry vanished.
Extortion groups routinely use leak-site listings as pressure tactics, and a removed entry does not by itself confirm a ransom was paid. It does illustrate how opaque these campaigns remain even as victim counts climb into the dozens, and why security teams are generally cautioned against reading too much into any single leak-site change without independent confirmation from the company involved.
Why PTC Windchill and FlexPLM Are High-Value Targets
PTC says its products are used by more than 30,000 customers globally, including more than 1,500 organizations running FlexPLM specifically in retail and apparel, according to the vendor’s own figures cited by BleepingComputer. That scale is exactly what makes a single unauthenticated RCE flaw so dangerous: one bug, patched or not, sits inside thousands of independent corporate networks at once.
PLM software is also unusually attractive to a data-theft-focused group like Clop. Windchill and FlexPLM environments typically store unreleased product designs, CAD files, bills of materials, supplier contracts and manufacturing specifications, the kind of intellectual property a company will pay to keep off a public leak site. Unlike consumer databases, this data does not need to be resold on criminal forums to have value. The threat of exposing pre-release product plans to competitors is often leverage enough on its own.
Many Windchill and FlexPLM deployments are internet-facing by design, because manufacturers, suppliers and design partners need remote access to collaborate across company lines. That same connectivity that makes PLM software useful for global supply chains is what gave Clop’s affiliates a direct path in, without needing to compromise an employee’s credentials first. It’s a familiar dynamic in 2026’s enterprise-software CVE wave, from an MLflow SSRF bug that exposed cloud keys to a string of VPN and firewall zero-days targeting internet-exposed management interfaces.
Clop’s Playbook: A History of Mass Zero-Day Extortion
This is not Clop’s first mass-exploitation campaign, and researchers say it follows a pattern the group has refined for years. Clop has previously exploited zero-day and freshly disclosed flaws in Accellion’s legacy file transfer appliance, Fortra’s GoAnywhere MFT, Cleo’s managed file transfer software, and Progress Software’s MOVEit Transfer, chaining each one into mass data-theft extortion rather than file-encrypting ransomware.
The MOVEit Transfer campaign in 2023 remains the group’s largest documented operation, ultimately affecting more than 2,770 organizations worldwide. In August 2025, Clop shifted to a zero-day in Oracle E-Business Suite, hitting organizations including Harvard University and The Washington Post.
The Windchill and FlexPLM campaign follows the same structure: identify a widely deployed enterprise platform, exploit a flaw before or immediately after a patch ships, harvest data from as many exposed instances as possible in a short window, then run a slower public extortion campaign once the initial access phase winds down. The US State Department’s Rewards for Justice program has previously offered up to $10 million for information linking Clop or its members to a foreign government, underscoring how seriously US authorities treat the group even though attribution to a specific state sponsor has not been publicly confirmed.
Windchill vs. MOVEit vs. Oracle EBS: Comparing the Scale
Measured purely by victim count, the Windchill and FlexPLM campaign is smaller than Clop’s MOVEit operation, still the group’s largest to date. But raw numbers understate the risk, because a single PLM environment can hold years of engineering work across dozens of connected suppliers, while a single MOVEit instance typically handled discrete file transfers between fewer parties.
| Campaign | Software exploited | Reported scale | Notable named victims |
|---|---|---|---|
| MOVEit Transfer (2023) | Progress Software MOVEit | 2,770+ organizations | Wide cross-industry impact |
| Oracle E-Business Suite (Aug. 2025) | Oracle EBS | Scale undisclosed | Harvard University, The Washington Post |
| PTC Windchill/FlexPLM (2026) | PTC Windchill, PTC FlexPLM | 43 listed victims | GE, Philips, Shell, Fiserv, Zebra Technologies |
Market and Industry Impact
None of Clop’s confirmed victims in this campaign have disclosed a material financial impact tied specifically to the Windchill breach as of this writing, and none of GE’s, Philips’ or Shell’s public financial guidance has been revised because of it. But the campaign adds to a mounting cybersecurity insurance and compliance bill across manufacturing, aerospace and retail, sectors that have historically underspent on the kind of internet-facing application testing needed to catch flaws like CVE-2026-12569 before attackers find them.
Security vendors that specialize in attack surface management are likely to see increased demand from manufacturing and retail buyers following this campaign, echoing what happened after MOVEit and Cleo pushed enterprise customers toward faster patch verification and exposure scanning. PTC itself faces a harder conversation with its 30,000-plus customer base about default configurations, since many of the exploited instances were reachable from the open internet in the first place.
For victim organizations, the more immediate cost is investigative: forensic review of what left the network, legal assessment of notification obligations, and, for publicly traded companies like GE and Philips, disclosure decisions under securities rules that increasingly treat material cybersecurity incidents as reportable events.
Regulatory and Legal Exposure Ahead
Publicly traded victims face layered disclosure obligations. In the United States, SEC rules adopted in 2023 require public companies to disclose material cybersecurity incidents within four business days of determining materiality, a standard that applies to GE regardless of where the underlying Windchill servers were hosted. European victims, including Philips and Shell, face separate notification duties under GDPR if personal data was among what Clop exfiltrated, though PLM systems more typically hold product and engineering data than consumer personal information.
Whether any named victim faces regulatory penalties will depend on facts that are not yet public: what data actually left each network, whether personal or employee information was mixed in with product data, and how quickly each company moved to contain and disclose the incident once it learned of Clop’s claims. Law firms have moved quickly after past Clop campaigns, including MOVEit and Oracle EBS, to file suits on behalf of affected individuals and shareholders, and a similar pattern is plausible here if any confirmed victim later discloses exposure of employee or customer personal data alongside product information.
How Manufacturers and Retailers Are Responding
PTC’s guidance to customers has focused on three steps: apply the June patches immediately if that has not already happened, rotate credentials stored in the Windchill keystore given ReliaQuest’s findings that Clop’s implant specifically targets that credential store, and review whether Windchill or FlexPLM instances need to stay reachable from the open internet at all, versus sitting behind a VPN or zero-trust access layer restricted to known suppliers and partners.
Security teams at companies running the same software but not yet named by Clop are reportedly treating the disclosure as a forcing function to audit their own external attack surface, a response pattern that mirrors what happened industry-wide after the MOVEit and Cleo campaigns. Reviewing internet-facing PLM, file-transfer and remote-access software for unpatched flaws has become close to a standard incident-response reflex whenever a Clop-linked CVE surfaces, given the group’s track record of moving from disclosure to mass exploitation within weeks, a cadence similar to what followed a recent Check Point VPN zero-day used by a separate ransomware operator.
What Happens Next: Predictions
Based on how Clop’s previous mass-extortion campaigns played out, a few outcomes look likely over the coming weeks:
- Clop’s victim count on the Windchill/FlexPLM leak site will keep climbing through September as forensic reviews at named and unnamed customers conclude, though it is unlikely to approach MOVEit’s 2,770-plus tally given how much narrower the Windchill/FlexPLM install base is.
- At least one of GE, Philips or Shell will likely issue a more detailed public statement or regulatory filing about the scope of exposure within the next reporting cycle, given US and European disclosure timelines.
- PTC will face pressure to publish a more detailed technical post-mortem, and may face pointed questions from enterprise customers about default internet exposure, echoing what Progress Software faced after MOVEit.
- Expect copy-cat scanning activity: once a flaw this severe is public and tied to real extortion, opportunistic actors beyond Clop typically start probing for unpatched Windchill and FlexPLM instances, a pattern seen after both the MOVEit and GoAnywhere disclosures.
- Attack-surface-management and PLM-security vendors will lean on this campaign in sales pitches to manufacturing and retail buyers through the rest of 2026, the same commercial pattern that followed MOVEit and Oracle EBS.
What Windchill and FlexPLM Customers Should Do Now
Security teams running either platform have a fairly narrow, well-defined checklist to work through immediately:
- Confirm the June 2026 PTC patches for CVE-2026-12569 are applied across every Windchill PDMLink and FlexPLM instance, not just primary production servers.
- Check for the hex-named JSP webshells ReliaQuest documented under /Windchill/login/, and treat any unexplained file in that directory as a compromise indicator.
- Rotate all credentials stored in the Windchill keystore, since Clop’s implant specifically targets that store.
- Restrict internet exposure of Windchill and FlexPLM login portals to known IP ranges or a VPN/zero-trust gateway where business needs allow.
- Review outbound network logs for unusual data transfers during the confirmed exploitation window of July 20-26, 2026, and the weeks before it.
- Loop in legal and compliance teams early, given the disclosure timelines described above, rather than waiting for a forensic review to fully conclude.
This campaign is the latest addition to shattered.io’s ongoing security coverage of the CVE-2026 wave hitting internet-facing enterprise software this year.
Frequently Asked Questions
What is CVE-2026-12569?
It is a critical improper input validation and unsafe deserialization flaw in PTC Windchill PDMLink and FlexPLM that lets an attacker execute code on a vulnerable server without valid login credentials, according to SecurityWeek and BleepingComputer.
Who is exploiting the PTC Windchill flaw?
The Clop ransomware and extortion group. Researchers at ReliaQuest confirmed active exploitation and documented a custom webshell the group’s affiliates use to steal data from compromised servers.
Which companies has Clop named as victims?
General Electric, Royal Philips, Shell, Fiserv, Zebra Technologies, Ingersoll Rand, Toast, Mindray and Largan Precision are among the more than 40 organizations Clop has listed, per SecurityWeek’s reporting.
Has PTC released a patch for CVE-2026-12569?
Yes. PTC began shipping patches on June 17, 2026, initially through a private customer advisory, according to BleepingComputer.
Is this a ransomware attack that encrypts files?
No. Consistent with its recent campaigns against MOVEit and Oracle E-Business Suite, Clop is running a data-theft extortion operation rather than deploying file-encrypting ransomware in this campaign.
How much data did Clop steal?
Claimed volumes vary by victim, from roughly 1 gigabyte to multiple terabytes, according to SecurityWeek. Shell said Clop claimed to have taken 89 gigabytes of its data.
Is CVE-2026-12569 on CISA’s Known Exploited Vulnerabilities catalog?
Yes. CISA added it around June 26, 2026, requiring US federal civilian agencies to patch on an emergency timeline.
What should Windchill and FlexPLM customers do right now?
Apply PTC’s June 2026 patches immediately, rotate Windchill keystore credentials, check for unexplained files under /Windchill/login/, and restrict internet exposure of login portals where business needs allow.
Related Coverage
- Ransomware Groups Up 49%: 8,159 Victims Hit in 2025 [2026]
- Foxconn Hit by Nitrogen Ransomware: 8TB Stolen, Apple and Nvidia Data Exposed [2026]
- Check Point VPN Zero-Day: CVSS 9.3, Qilin Ransomware [2026]
- PaperCut Zero-Days Hit CISA KEV, CVSS 9.4, 70K Orgs [2026]
- McKesson Breach: ShinyHunters Claim 284M Records [2026]




