← Back to Daily Briefing

The Clop ransomware group is executing a large-scale extortion campaign by mass-exploiting CVE-2026-12569, a critical unauthenticated remote code execution (RCE) vulnerability in PTC Windchill PDMLink and FlexPLM. The vulnerability, rooted in unsafe deserialization, allows attackers to bypass authentication and gain initial access to public-facing industrial software instances. Following successful exploitation, Clop moves laterally within the environment—potentially compromising integrated AI agents—to exfiltrate sensitive corporate data. The campaign has specifically targeted the energy and industrial sectors, with the group claiming to have stolen 89GB of data from Shell. This highlights a significant risk to organizations utilizing PTC product suites for product lifecycle management.

  • Incident/Breach Overview

    • Targeting high-value organizations in the Energy and Industrial sectors, including Shell, GE, and Philips.
    • Utilization of a "leak-site" extortion model, where stolen data is used as leverage for ransom payments.
    • Large-scale data exfiltration confirmed, including a claimed 89GB theft from Shell.
  • Attack Vector/Campaign Mechanics

    • Primary vector: Mass exploitation of public-facing PTC Windchill and FlexPLM instances.
    • Vulnerability Mechanics: Exploitation of unauthenticated RCE via unsafe deserialization processes.
    • Post-exploitation: Lateral movement and potential compromise of integrated AI agents within the target environment.
  • Vulnerability Deep Dive

    • Affected Software: PTC Windchill PDMLink and PTC FlexPLM.
    • Vulnerability Identifier: CVE-2026-12569.
    • CVSS Severity: 9.8 (NVD) to 10.0 (PTC), classified as Critical.
    • Affected Versions: All versions prior to 11.0 M030 and subsequent iterations.
  • Threat Group Profile & Impact

    • Perpetrator: Clop ransomware group, specializing in large-scale data theft and zero-day exploitation.
    • Tactical Shift: Focus on data exfiltration and extortion rather than traditional high-encryption ransomware.
    • Sectoral Risk: Heavy focus on critical infrastructure, specifically energy and manufacturing industrial giants.
  • Mitigation & Defensive Actions

    • Patching: Immediately upgrade PTC software to version 11.0 M030 or later.
    • Network Defense: Restrict access to public-facing PLM instances and implement strict network segmentation.
    • Monitoring: Audit logs for deserialization anomalies and unauthorized RCE attempt patterns.

Related posts

  1. techjacksolutions.com — Clop Claims 89GB Shell Data Theft While Extortion Campaign Targets Energy and Industrial Sectors
  2. computerweekly.com — Multiple organisations investigating fresh wave of Cl0p breaches
  3. forkast.news — CLOP Is Mass-Exploiting PTC Windchill at Scale. Every AI Agent Connected to It Inherits the Breach.
  4. Pcrisk
  5. Inspenet
  6. Pravda
  7. Facebook
  8. Computing
  9. Socradar
  10. Sentinelone
  11. Ebuildersecurity
  12. Deepstrike
  13. Unit42

LINK COPIED TO CLIPBOARD