Published · 4d agoSecurity3 min read
Clop's PTC victim list keeps growing because the extortion email is the alert
The group exploited a Windchill zero-day in early June, PTC patched a day after disclosing it on June 17, and threat mail landed in mid-July. PTC has not said how many customers were hit.
Not a builder's beat, but builders have a standing stake in it.See today for builders
What happened
- Clop claims it stole data from dozens of organizations, including some of the world's largest publicly traded companies, after exploiting a critical zero-day at large scale.
- Clop is a prolific but calculated data theft extortion group that has been active since 2020.
- Clop began sending threatening emails to its alleged victims in mid-July, according to researchers.
- The vulnerability affects PTC's Windchill and FlexPLM products, which manufacturers and retailers, particularly in manufacturing, aerospace and automotive, use to automate supply chain systems and manage product lifecycles.
- PTC disclosed the vulnerability, CVE-2026-12569, on June 17 and issued a patch and initial indicators of compromise the following day.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Clop was inside PTC Windchill and FlexPLM environments in early June, and many of the manufacturers it robbed did not learn that until mid-July, when the extortion mail arrived [6][3]. The gap is the story: roughly six weeks in which the compromise existed only in the attacker's records [2].
The vulnerability, CVE-2026-12569, was disclosed by PTC on June 17, with a patch and initial indicators of compromise the following day [5][1]. CISA added it to the known exploited vulnerabilities catalog on June 25, eight days after disclosure, describing a defect that lets unauthenticated attackers execute code remotely [7][3]. According to Ransom-ISAC, that timeline was already too late for some of Clop's known victims [6]. Windchill and FlexPLM sit in manufacturing, aerospace and automotive shops, where they automate supply chain systems and manage product lifecycles [4]. That is the target profile Clop keeps returning to. "This continues Clop's trend of targeting SaaS logistics companies' platforms with zero-days and carrying out mass-exploitation campaigns," Allan Liska, field CISO at Recorded Future, told CyberScoop [16].
The group, active since 2020, claims data from dozens of organisations, including some of the world's largest publicly traded companies [2][1]. Toast and Zebra both told CyberScoop they detected and contained intrusions with limited impact [10]. GE, Philips and Shell did not respond to requests for comment [11]. Neither did PTC [9]. The vendor has kept adding indicators of compromise as researchers found them, but has not said how it first learned of the attacks, when the earliest exploitation occurred, or how many customers are known to be compromised [8]. Without that last number, every affected manufacturer is running its own investigation blind, and the fallout is still evolving as companies hunt for signs of compromise [19].
The tooling explains why detection lagged. ReliaQuest, in a report published Tuesday, describes a custom web shell purpose-built for Windchill that decrypts credentials, delivers malware, and bundles tools for sustained access, network traversal and data encryption [12][13]. It moves from initial access to bulk data theft without the operator typing manual commands, and it mimics Windchill's standard functions, which is precisely what defeats behavioural detection on an application server [14]. "Clop remains a sleeping dragon, always looking and preparing to mass exploit vulnerabilities in software that holds sensitive data," the ReliaQuest researchers wrote, noting the group goes quiet between campaigns and returns with a new custom web shell when the next mass-extortion opportunity appears [15].
This is a rerun, not a surprise. Clop worked dozens of Oracle E-Business Suite customers for more than three months starting in the summer of 2025 before it began sending extortion mail [17], and its 2023 MOVEit campaign exposed data from more than 2,300 organisations, the largest and most significant cyberattack of that year [18]. Across vendors, the pattern holds: exploit one platform, harvest downstream customers for weeks or months, then monetise [20].
Watch the victim count rather than the patch count. The disclosed set will keep expanding as extortion emails reach companies that never saw an alert, and the useful signal will be whether PTC eventually publishes a number of known-compromised customers. Anyone running Windchill should be treating early June, not June 17, as the start of the search window [6][5].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Clop claims it stole data from dozens of organizations, including some of the world's largest publicly traded companies, after exploiting a critical zero-day at large scale.
ReportedView cited source - [2]
Clop is a prolific but calculated data theft extortion group that has been active since 2020.
ReportedView cited source - [3]
Clop began sending threatening emails to its alleged victims in mid-July, according to researchers.
ReportedView cited source - [4]
The vulnerability affects PTC's Windchill and FlexPLM products, which manufacturers and retailers, particularly in manufacturing, aerospace and automotive, use to automate supply chain systems and manage product lifecycles.
ReportedView cited source - [5]
PTC disclosed the vulnerability, CVE-2026-12569, on June 17 and issued a patch and initial indicators of compromise the following day.
ReportedView cited source - [6]
According to Ransom-ISAC, the patch came too late for some of Clop's known victims, who were likely compromised by exploitation of the zero-day in early June.
ReportedView cited source
Sources & coverage · 2 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- cyberscoop.comMatt Kapko4d agoThe long tail of Clop’s PTC hack is just beginning to emerge
- cyberscoop.com3d agoThe long tail of Clop’s PTC hack is just beginning to emerge | CyberScoop
- securityaffairs.comPierluigi Paganini2d agoCl0p Targets 40+ Organizations Through PTC Windchill Flaw



