ThreatPaper
Extortion & BlackmailOT & Industrial SystemsData BreachCritical

Cl0p and PTC Windchill: The Custom Implant That Turned Engineering Vaults Into an Extortion Campaign

By Sethu Satheesh · 11 Sept 2026 · 21 min read

Threat Actor: Cl0p (TA505 / FIN11 / Lace Tempest / Graceful Spider) — attributed by Ransom-ISAC and ReliaQuest at high confidence via extortion-email contact addresses and leak-site postings · Target: Organisations running internet-exposed PTC Windchill PDMLink and FlexPLM; 43 named on Cl0p's leak site across manufacturing, aerospace, automotive, energy, medtech, retail and fintech

Source: www.ptc.com


Executive Summary

Between early June and mid-August 2026, the Cl0p extortion group ran a mass data-theft campaign against organisations running PTC Windchill and FlexPLM, the product lifecycle management platforms that hold CAD models, bills of materials, engineering change records and supplier data for a large share of the world's manufacturers. The entry point was CVE-2026-12569, an unauthenticated deserialization flaw in the Windchill login servlet, chained in observed intrusions with a pre-authentication information disclosure in the FlexPLM WSDL endpoint. PTC published remediation on 17 June and confirmed exploitation the next day; CISA added the flaw to its Known Exploited Vulnerabilities catalogue on 25 June with a three-day deadline. Ransom-ISAC assesses the flaw was exploited as a zero-day in early June, before any fix existed.

What distinguishes this campaign from generic web-shell exploitation is the implant. ReliaQuest's analysis of the JSP shell, published 18 August, shows it was written for Windchill specifically: it imports the application's own MethodContext, WTConnection and WTKeyStoreUtil classes, decrypts every credential in the Windchill keystore with a single command, queries the vault database for file names, paths and sizes using Windchill's internal schema, and carries a Java class loader that runs attacker-supplied bytecode in memory. Commands arrive in a custom HTTP header, X-windchill-req, and responses are GZIP-compressed, so the traffic looks like the application's own. This is Cl0p's established pattern, DEWMODE for Accellion in 2021 and LEMURLOOT for MOVEit in 2023, applied to a platform whose contents are blueprints rather than files in transit.

Extortion emails with the subject line "Windchill PDMLink module serious data leak" began reaching hundreds of employees at affected organisations on 20 July. Between 12 and 19 August, Cl0p named 43 organisations on its leak site, among them Shell, Philips, General Electric, Fiserv, Zebra Technologies, Toast, Ingersoll Rand, Mindray and Largan Precision, with claimed data volumes from 1 GB to 8 TB per victim. Philips confirmed a contained intrusion of one server; Shell said it was investigating; Zebra and Toast reported limited impact; GE said it was assessing and was later reported removed from the leak site. No victim has confirmed the volume Cl0p claims, and no data samples have been published.

The vulnerability sits in a pattern that the coverage has not joined up. In March 2026 PTC disclosed CVE-2026-4681, another unauthenticated deserialization RCE in the same products, warning of "credible evidence of an imminent threat by a third-party group"; German federal police visited companies in person at 3:30 in the morning to make them patch. In June, the BSI phoned Windchill administrators at 2:30 AM on the 17th, hours before PTC's public advisory, citing a "partner authority" and a patch dated 15 June. On 20 August, while the extortion wave was in progress, PTC disclosed a third deserialization RCE, CVE-2026-77645, plus an SSRF. Three unauthenticated deserialization flaws in one product in five months is a statement about the product, not about any one of them. PTC has not said how CVE-2026-12569 was discovered, when exploitation began, or how many customers were affected.

Verification of Claims

  1. Claim: CVE-2026-12569 is an unauthenticated remote code execution flaw in Windchill PDMLink and FlexPLM caused by deserialization of untrusted data. → Verified → NVD record (CWE-20, CWE-502); PTC Trust Center advisory; CISA KEV entry of 25 June 2026 ("unauthenticated, remote attacker to execute arbitrary code by sending a malicious request").

  2. Claim: The flaw was exploited before the patch, as a zero-day. → Assessed, not confirmed → Ransom-ISAC: "most likely exploited … as a zero-day vulnerability in early June 2026." Censys: exploitation suspected "early to mid June." PTC has not stated an exploitation start date. The BSI's 17 June email warned of "impending" attacks, and PTC's 18 June update published six web-shell paths and a C2 address, which implies compromises had already been analysed by then.

  3. Claim: The CVSS score is 9.3 / 9.8 / 10.0. → Verified — all three, on different scales → 9.3 is PTC's CVSS 4.0 score, carried by NVD and cited by ReliaQuest. 9.8 is NVD's own CVSS 3.1 score. 10.0 is the CVSS 3.1 figure cited by heise and, for the March flaw, by the BSI. The three are not in conflict; reporting that picks one without saying which scale is incomplete.

  4. Claim: A patch existed on 15 June, two days before PTC's public advisory. → Partially verified → The BSI's email of 17 June, reproduced by heise, states "the patch released on 06/15/2026 represents a secured version of the software." PTC's public changelog begins at 2:16 PM ET on 17 June with "remediation steps now available." PTC's eSupport article CS473270 is behind a customer login and may carry the earlier date; ThreatPaper could not view it.

  5. Claim: The web shell is custom-built for Windchill and attributable to Cl0p. → Assessed, not confirmed → ReliaQuest, 18 August: "highly likely" Cl0p, on three grounds: extortion-email contact addresses match Cl0p's leak site, the X-windchill-req header matches earlier reporting, and the custom-shell-after-mass-exploit pattern matches DEWMODE and LEMURLOOT. Ransom-ISAC independently encountered the same sample (SHA-256 321e1f…98bf) in an incident. No law enforcement attribution has been published.

  6. Claim: Cl0p listed 43 victims. → Verified as a leak-site count → BleepingComputer, 17 August: "a batch of 43 new victims"; SecurityWeek, 19 August: "over 40"; CPO Magazine: "50+". Ransom-ISAC dates the listings to 14–19 August; BleepingComputer dates the first full names to 12 August. The count is of leak-site entries, not confirmed compromises.

  7. Claim: Shell, GE and Philips had data stolen. → Partially verified → Philips (to Reuters): "identified and contained an attempted cybersecurity compromise of a specific enterprise server related to internal data." Shell: "aware of a potential incident … working with our security teams." GE: "working to assess the potential issue." None has confirmed exfiltration or volume. Cl0p claims 89 GB from Shell; that figure is the group's.

  8. Claim: Fewer than 100 Windchill instances were exposed to the internet. → Verified as Censys's observation → Censys, 30 July: "fewer than 100 instances … as of June 1"; ~80 on 20 July; 80% in the US; about a quarter behind Akamai. Censys fingerprinting undercounts instances behind CDNs and on non-default paths, which may explain how 43 victims arose from fewer than 100 observed targets.

  9. Claim: CISA gave federal agencies three days. → Verified → KEV entry: dateAdded 2026-06-25, dueDate 2026-06-28, knownRansomwareCampaignUse "Known", under BOD 26-04.

  10. Claim: This was the second unauthenticated deserialization RCE in Windchill in three months. → Verified → CVE-2026-4681, published to NVD 23 March 2026 (CWE-94, CVSS 4.0 9.3), affecting the same version list; PTC then warned of an "imminent threat by a third-party group." CVE-2026-77645 followed on 20 August (CWE-502, CVSS 4.0 9.2).

  11. Claim: The US State Department is offering a $10 million reward for information linking Cl0p to a foreign government. → Superseded in framing → The reward was announced under the Rewards for Justice programme in June 2023 during the MOVEit campaign. It remains open, but it is not a response to this campaign, which is how "now offers" reads in current coverage.

Timeline

Date Actor Event Source
20 March 2026 PTC Discloses CVE-2026-4681, unauthenticated deserialization RCE in Windchill and FlexPLM; no patch; warns of "credible evidence of an imminent threat by a third-party group." Recommends blocking the servlet path or disconnecting from the internet. BleepingComputer, 24 Mar; NVD
22–23 March 2026 BKA / state police Officers phone and physically visit German Windchill customers overnight, at 2:45 and 3:30 AM Sunday, to demand patching. Unofficially over 1,000 German companies affected. heise, 23 Mar
Early June 2026 Cl0p (assessed) Exploitation of CVE-2026-12569 begins, before any fix. Ransom-ISAC; Censys
1 June 2026 Censys Fewer than 100 Windchill instances observed internet-exposed. Censys, 30 Jul
15 June 2026 PTC Patch date cited in the BSI's warning email. heise, 19 Jun
17 June 2026, 02:30 CEST BSI Phones Windchill administrators; emails follow. Source: "a partner authority within the National IT Situation Center." heise, 19 Jun
17 June 2026, 14:16 ET PTC Trust Center advisory: "Remediation steps now available and should be applied immediately." CVE referenced at 21:28 ET. PTC changelog
18 June 2026 PTC; NVD Patches for 13.0.2, 12.1.2, 12.0.2. First IOC set: C2 5.180.41[.]35, six 16-hex JSP web-shell paths, header X-windchill-req: ?x8Fmgow, hash 55a1eb…a30c, flst.txt. NVD publishes the CVE. PTC changelog; NVD
19 June 2026 PTC Patches for 11.2.1, 11.1 M020, 11.0 M030, 13.1.1. PTC changelog
23–25 June 2026 PTC; CISA New IOC IPs; "continued reports of heightened threat activity." CISA adds to KEV, due 28 June. PTC changelog; KEV
1–9 July 2026 PTC Further IOC batches; six-hex web-shell naming observed 8 July. PTC changelog
14 July 2026 PTC Consolidated security patches for all supported versions. PTC changelog
17 July 2026 Cl0p New extortion email infrastructure registered. Censys
20 July 2026 Cl0p Extortion emails, subject "Windchill PDMLink module serious data leak," sent to hundreds of employees per victim from compromised third-party accounts. Ransom-ISAC, 22 Jul
22 July 2026 Ransom-ISAC Unified Threat Advisory with eCrime.ch and DEFUSED attributes campaign to Cl0p affiliates. No victims yet listed. Ransom-ISAC
27 July 2026 PTC Expanded IOC set: 28 IPs, dpr_ web-shell naming, 44 MD5 hashes. PTC changelog
12–19 August 2026 Cl0p 43 organisations named on leak site; partial names first, full names from 12 August. BleepingComputer; Ransom-ISAC
14 August 2026 Ransom-ISAC C2 79.141.160[.]78 and implant hash 321e1f…98bf observed in an active incident. Ransom-ISAC
15–17 August 2026 Shell; Philips; GE Shell "aware of a potential incident"; Philips confirms contained compromise of one server; GE "assessing." BleepingComputer, 17 Aug
18 August 2026 ReliaQuest Publishes analysis of the custom implant. ReliaQuest
19 August 2026 CyberScoop; Ransom-ISAC Zebra and Toast report limited impact. PTC declines to answer how the flaw was found, when exploitation began, or how many customers were hit. Ransom-ISAC adds structural YARA rule. CyberScoop; Ransom-ISAC
20 August 2026 PTC Discloses CVE-2026-77645 (deserialization RCE, CVSS 4.0 9.2) and CVE-2026-77646 (SSRF, 7.7). PTC changelog; NVD
26 August 2026 PTC Adds IOC 23.95.238[.]5. PTC changelog

Attack Anatomy

Loading diagram...

Stage 1: reconnaissance

PTC's detection guidance includes one pre-attack signature: a GET to /Windchill/rfa/jsp/login/*.jsp?wsdl returning exactly 4,045 bytes. Ransom-ISAC describes this as a pre-authentication information disclosure in the FlexPLM WSDL endpoint, scored CVSS 7.5, which the operators chain with the RCE. The WSDL response presumably confirms product and version before the exploit is sent; PTC has not described what it leaks.

Stage 2: exploitation

CVE-2026-12569 is deserialization of untrusted data reachable without authentication through the Windchill login servlet. PTC's 29 June update refers to "the Java serialization filter related to com.ptc.wpcfg.logic.ExpressionClassMethod," which is the workaround and therefore the likely gadget path. A successful request writes a JSP file into the login directory under <WT_HOME>/codebase/login/. PTC's advisory notes that "legitimate Windchill traffic does not POST to this path," which makes any POST to /Windchill/login/*.jsp a detection.

The web shells were named with 16 lowercase hex characters at first (7c0a0a34c9d8d53b.jsp and five others published on 18 June), then six hex characters from early July, sometimes with ?cmd=whoami appended, then dpr_ plus eight hex characters by late July. The rotation is why Ransom-ISAC's YARA rule keys on structure, the eight-character password check, defineClass, ZipInputStream and GZIPOutputStream together, rather than file names.

Stage 3: the implant

ReliaQuest's analysis of the shell (SHA-256 321e1fb0…98bf) is the technical core of this incident. Commands are carried in the X-windchill-req header; PTC's IOC gives the format as ?x8Fmgow with "first character = command selector." Three functions matter:

  • gs / the S command. Reads ieStructProperties.txt, decrypts the LDAP manager password from the application keystore via WTKeyStoreUtil, then iterates every stored encrypted property: administrative accounts, object-storage credentials, site administrator keys. One request returns all of it in plaintext. ReliaQuest's point is that the LDAP manager credential "typically govern[s] access to Active Directory, email systems, VPN," so a PLM compromise becomes a directory compromise.
  • fl / Flst1. Connects to the Windchill database through the application's own MethodContext and WTConnection, so queries run under the application's identity, and enumerates vault stream IDs, file names, storage paths and sizes into flst.txt. The queries reference internal column names such as IDA3A4. This is the map of what to steal.
  • Cldr. A class loader that takes a Base64-encoded ZIP of compiled Java, loads it into memory and executes it. Nothing is written to disk. ReliaQuest reads this as the path to lateral movement or encryption if extortion fails; no such follow-on has been reported.

Responses are GZIP-compressed. Detection therefore needs header logging, response decompression and TLS inspection together; any one alone misses either the commands or the data.

Stage 4: exfiltration and extortion

Cl0p's claimed volumes, 89 GB from Shell and 8 TB from Zebra, are consistent with vault-level theft rather than database dumps. The extortion phase followed the group's Oracle EBS playbook of 2025: on 20 July, emails from compromised third-party accounts went to hundreds of employees per organisation, naming Windchill as the source and giving new contact addresses that were simultaneously posted to the leak site. Listing began three weeks later, first as partial names, then full names from 12 August. GE's reported disappearance from the site would, in Cl0p's pattern, indicate negotiation; that is inference, and GE has not commented.

The scanner's paradox

Censys observed fewer than 100 exposed Windchill instances on 1 June and about 80 on 20 July, a decline of roughly 20% after the advisory. Cl0p named 43 victims. If both figures are right, either the exploitation rate against exposed instances approached half, or a substantial share of victims were reachable in ways passive scanning does not fingerprint: behind Akamai, which fronted about a quarter of observed hosts, on non-standard paths, or through FlexPLM endpoints Censys does not classify as Windchill. ThreatPaper cannot resolve this; PTC could, and has not.

Threat Actor Profile

  • Name / Alias: Cl0p (Clop). Tracked as TA505 (ATT&CK G0092), FIN11, Lace Tempest (Microsoft), Graceful Spider (CrowdStrike), Chubby Scorpius, Hive0065. ATT&CK software entry S0611.
  • Attribution basis: Ransom-ISAC (with eCrime.ch and DEFUSED), 22 July: extortion emails carry the contact addresses posted on Cl0p's leak site. ReliaQuest, 18 August: "highly likely," on the email match, the header, and the custom-implant pattern. Ransom-ISAC and ReliaQuest hold the same sample from separate incidents. No government attribution for this campaign; the June 2023 Rewards for Justice offer for Cl0p remains open.
  • Motivation: Financial. Data theft and extortion without encryption, the group's mode since Accellion (2021).
  • Prior mass-exploitation campaigns: Accellion FTA (2021, DEWMODE), SolarWinds Serv-U (2021), GoAnywhere MFT (2023), MOVEit Transfer (2023, LEMURLOOT, 2,770+ organisations), Cleo (2024), Oracle E-Business Suite (2025).
  • What changed: ZeroFox characterises this as a shift "from personal data to intellectual property theft." The targets are engineering vaults; the leverage is design data, supplier terms and regulatory submissions rather than PII.
  • Sophistication: High in tooling. The implant required source-level knowledge of Windchill's keystore utilities and database schema.
  • MITRE ATT&CK techniques (verified on attack.mitre.org, 11 September 2026):
    • T1190 Exploit Public-Facing Application
    • T1505.003 Server Software Component: Web Shell
    • T1555 Credentials from Password Stores; T1552.001 Unsecured Credentials: Credentials In Files (keystore, ieStructProperties.txt)
    • T1213 Data from Information Repositories (vault enumeration)
    • T1620 Reflective Code Loading (Cldr)
    • T1071.001 Application Layer Protocol: Web Protocols; T1560 Archive Collected Data (GZIP)
    • T1041 Exfiltration Over C2 Channel
    • T1657 Financial Theft (extortion)

Technical Indicators

# Sources: PTC CS473270 changelog (18 Jun–26 Aug 2026), Ransom-ISAC (22 Jul, 14 Aug),
# ReliaQuest (18 Aug). Defanged. PTC notes some IPs may be shared or ephemeral hosting.
c2_priority_block:
  - 5.180.41[.]35        # PTC, 18 Jun
  - 79.141.160[.]78      # Ransom-ISAC, active incident, 14 Aug
c2_and_exploitation_ips:
  - 23.95.238[.]5        # PTC, 26 Aug
  - 23.206.251[.]247     # Ransom-ISAC
  - 38.60.157[.]212
  - 64.177.69[.]57
  - 64.177.86[.]200
  - 65.20.79[.]73
  - 66.163.122[.]78
  - 74.50.76[.]146
  - 78.128.113[.]10
  - 79.141.163[.]103
  - 81.27.103[.]18
  - 81.27.103[.]68
  - 85.9.211[.]83
  - 87.58.193[.]42
  - 104.194.9[.]14
  - 104.238.145[.]147
  - 104.243.35[.]0/24
  - 104.243.35[.]63
  - 104.243.35[.]131
  - 111.194.46[.]135
  - 137.184.184[.]209
  - 138.68.51[.]132
  - 144.172.101[.]13
  - 162.243.242[.]176
  - 172.111.38[.]31
  - 185.227.83[.]236
  - 204.194.51[.]30
  - 206.189.199[.]39
  - 209.222.98[.]44
  - 212.147.249[.]110
  - 216.152.148[.]54
  - 216.152.151[.]204
file_hashes:
  sha256:
    - 55a1eb4c2d3da04376df39d7ba832569c6af1a37a0cf2b95f754ac898023a30c   # JSP shell, PTC 18 Jun
    - 321e1fb01eb3462b48ff6ccdef132acc1182e3f7456548439f0d4ead12fd98bf   # custom implant, ReliaQuest / Ransom-ISAC
  sha1:
    - 05af84bfa569366700d826313cdfde44b5efca48
    - 8be6f433b443545932821058952916d3c066a8e0
  md5: 44 hashes published by PTC on 27 Jul; see Ransom-ISAC advisory §7
web_shell_paths:
  known:
    - /Windchill/login/7c0a0a34c9d8d53b.jsp
    - /Windchill/login/46b158b8607a4c00.jsp
    - /Windchill/login/64652883d9de3299.jsp
    - /Windchill/login/56c9be44a436c4a2.jsp
    - /Windchill/login/4b57d0652345d383.jsp
    - /Windchill/login/ec6ba805a076e709.jsp
  patterns:
    - ^/Windchill/login/[0-9a-f]{16}\.jsp$
    - ^/Windchill/login/[0-9a-fA-F]{6}\.jsp(\?cmd=.*)?$
    - ^/Windchill/login/dpr_[0-9a-fA-F]{8}\.jsp$
  filesystem: <WT_HOME>/codebase/login/*.jsp
http:
  command_header: "X-windchill-req: ?x8Fmgow"   # first char = command selector; no legitimate use
  recon: GET /Windchill/rfa/jsp/login/*.jsp?wsdl with response_bytes == 4045
  behaviour: POST to /Windchill/login/*.jsp; multi-MB GZIP responses from .jsp
host_artifacts:
  - flst.txt in /tmp or the Windchill working directory
  - implant references MethodContext, WTConnection, WTKeyStoreUtil, IDA3A4
extortion_email_subject: "Windchill PDMLink module serious data leak"

United States. CISA added CVE-2026-12569 to KEV on 25 June with a 28 June due date under BOD 26-04, flagged "knownRansomwareCampaignUse: Known." No CISA advisory beyond the KEV entry has been issued. No named victim has filed an SEC Form 8-K referencing the incident that ThreatPaper could locate; Zebra, Toast and Fiserv are SEC registrants and have characterised impact as limited or absent, which is consistent with a no-materiality determination. The Rewards for Justice offer of up to $10 million for information tying Cl0p to a foreign government dates from June 2023.

Germany. The response is without precedent in either episode. For CVE-2026-4681 in March, the BKA coordinated state criminal police offices to phone and visit companies overnight; LKA Thuringia said "the companies reached had already been informed by PTC Inc. and had taken security measures." For CVE-2026-12569 the BSI phoned administrators at 2:30 AM on 17 June and emailed the same morning, citing "trustworthy and reliable sources of impending cyberattacks" received through "a partner authority within the National IT Situation Center." The BSI has not identified the partner. The BKA referred questions to the BSI. That a national agency had actionable warning of impending attacks hours before the vendor's public advisory is the clearest evidence in the record that this was a zero-day.

European Union. ENISA's EU Vulnerability Database lists the flaw as EUVD-2026-37831.

Vendor. PTC's Trust Center changelog runs from 17 June to 26 August with twenty entries. PTC has published IOCs, patches, workarounds and detection rules, and states that hosted customers are remediated on their behalf. It has not published how the vulnerability was discovered, whether it was reported or found in exploitation, when the first compromise occurred, or a count of affected customers, and declined CyberScoop's request on all three. The eSupport article CS473270 and the workaround article CS473493 are behind a customer login.

Victims. No regulator has announced an investigation. Philips' statement to Reuters is the only victim confirmation of an intrusion; the rest are investigations or limited-impact statements.

Impact Assessment

  • Organisations named on leak siteConfirmed as listings. 43 between 12 and 19 August (BleepingComputer, Ransom-ISAC); "over 40" (SecurityWeek); "50+" (CPO Magazine).
  • Confirmed intrusionsConfirmed, partial. Philips (one server, contained); Zebra and Toast (limited impact). Shell, GE investigating.
  • Data stolenReported. Cl0p claims backups, project plans, facility photographs, drawings, diagrams, blueprints, CAD files and databases; 89 GB (Shell), ~8 TB (Zebra). No samples published; no victim has confirmed a volume.
  • Credential exposureEstimated, high. The implant's S command returns the LDAP manager password and all keystore secrets. ReliaQuest advises assuming the full set is exfiltrated on any compromised server.
  • SectorsConfirmed. Manufacturing, automotive, aerospace, retail/apparel (Ransom-ISAC); energy, medtech, fintech, point-of-sale among named victims.
  • Exposed attack surfaceReported. Fewer than 100 internet-exposed instances (Censys, 1 June), against PTC's stated 30,000 customers and 1,500 FlexPLM brand and retail customers.
  • Ransom demandsUnknown. No figures reported. GE's reported delisting is the only hint of negotiation.
  • Follow-on attacksNot observed. ReliaQuest assesses the class loader enables them; none reported as of 11 September.
  • Exploitation startUnknown. Early June (assessed); not stated by PTC.

Lessons and Defensive Recommendations

For Windchill and FlexPLM administrators

  • Patch to the 14 July consolidated builds or later, then patch again for CVE-2026-77645 and -77646 (20 August). Three deserialization flaws in five months means the next one is likely; treat the login servlet as untrusted-input surface and keep the serialization filter workaround in place even when patched.
  • Hunt back to early June, not to the advisory date. Search for POSTs to /Windchill/login/*.jsp, the X-windchill-req header, flst.txt, and JSP files in codebase/login/. Run Ransom-ISAC's structural YARA rule; file names rotate, structure does not.
  • If a shell is found, the keystore is gone. Rotate the LDAP manager password and every secret in ieStructProperties.txt, then rotate wherever those credentials were reused, and revoke sessions, because rotated passwords do not invalidate existing tokens.

For SOC and detection engineering

  • This implant is invisible to URL- and body-based inspection. Log non-standard request headers, decompress responses before inspection, and inspect TLS at the application tier. All three, or coverage is partial.
  • Alert on the recon signature: GET …/login/*.jsp?wsdl returning 4,045 bytes. It precedes deployment.
  • Database telemetry will attribute vault enumeration to the application's own service identity. Alert on vault-table queries and multi-MB responses from JSP paths instead of on new accounts.

For manufacturers and their boards

  • PLM is the crown-jewel store, and it has been treated as an internal engineering tool. It is now a Cl0p target class alongside file-transfer appliances and ERP. Take it off the internet where the business allows; put it behind a WAF with the PTC rules where it does not.
  • Extortion emails will reach hundreds of your employees before any leak-site listing. Brief them.

For PTC and the research community

  • Two national police forces have twice woken administrators in the night over this product. The vendor has not said how the flaws were found or how many customers were hit. Disclosure of discovery source and exploitation timeline is the norm after MOVEit; its absence here leaves customers unable to date their own hunting windows.

Sources

  1. PTC. "Customer & Partner Updates: Remote Code Execution Vulnerability in PTC's Windchill and FlexPLM Solutions". Trust Center, changelog 17 June – 26 August 2026.
  2. NIST NVD. CVE-2026-12569; CVE-2026-4681; CVE-2026-77645; CVE-2026-77646.
  3. CISA. Known Exploited Vulnerabilities Catalog, entry for CVE-2026-12569, added 25 June 2026.
  4. ReliaQuest Threat Research (John Dilgen, Connor Short). "Clop Returns with Custom Implant in Mass-Extortion Campaign". 18 August 2026.
  5. Ransom-ISAC (Brandon Parsons; Corsin Camichel, Simo Kohonen). "Cl0p Exploitation of PTC Windchill & FlexPLM (CVE-2026-12569)". 22 July 2026, updated 19 August 2026.
  6. Emily Austin, Censys. "A Chill in the Air: Cl0p Targets Windchill, Another Enterprise Software Product". 30 July 2026.
  7. Christopher Kunz, heise online. "PTC Windchill: BSI calls admins at night due to critical security vulnerability". 19 June 2026.
  8. heise online. "WTF: Police responded on Saturday night due to a zero-day". 23 March 2026.
  9. BleepingComputer. "PTC warns of imminent threat from critical Windchill, FlexPLM RCE bug". 24 March 2026.
  10. Sergiu Gatlan, BleepingComputer. "Philips and GE investigating Clop ransomware data theft claims". 17 August 2026.
  11. SecurityWeek. "Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign". 19 August 2026.
  12. CyberScoop. "The long tail of Clop's PTC hack is just beginning to emerge". 19 August 2026.
  13. Help Net Security. "JSP webshells being dropped on unpatched PTC Windchill instances". 29 June 2026.
  14. ZeroFox. "Flash Report: Cl0p Shifts from Personal Data to Intellectual Property Theft". August 2026.
  15. MITRE ATT&CK. TA505, G0092; Clop, S0611; T1505.003; T1620. Accessed 11 September 2026.
Original Incident Report →

Related Research

ShinyHunters says it vished McKesson employees, took over Okta sessions, and pulled a terabyte from Salesforce and Snowflake between 20 and 25 August 2026. McKesson has confirmed exfiltration of patient data and nothing about how.

Data BreachExtortion & BlackmailSocial Engineering

Three men who worked in incident response ran BlackCat attacks. One of them was simultaneously negotiating on behalf of ransomware victims — and passing the attackers his own clients' insurance limits.

RansomwareInsider ThreatExtortion & Blackmail

Between mid-2025 and August 2026, a cybercriminal collective operating primarily under the ShinyHunters brand—alongside associated activity clusters tracked as UNC6040, UNC6240, UNC6395, UNC6661, and...

Data BreachSupply Chain Attack