// 5 ZERO-DAY · 7 CVE · 4 EXPLOIT IN THE LAST 24H
The Clop group stole technical data from 43 organizations by exploiting CVE-2026-12569 in PTC Windchill. Shell is investigating a potential incident; Philips contained the compromise of an internal enterprise server.

The Clop group has claimed the theft of technical data from 43 organizations by exploiting the vulnerability CVE-2026-12569 in PTC Windchill and FlexPLM, a PLM platform used by more than 30,000 global customers. Shell confirmed it is investigating a "potential incident." Philips confirmed it contained the compromise of an internal enterprise server. GE has not commented. This analysis is based primarily on TechTimes, with corroborating elements from secondary sources; Clop's claims regarding data volumes are not independently verified.

Key Takeaways
  • CVE-2026-12569 carries a CVSS score of 9.8 (v3.1) and 9.3 (v4.0): unauthenticated deserialization leading to RCE on PTC Windchill and FlexPLM.
  • Clop claims 43 victims, including Shell, GE, and Philips; Shell is investigating a potential incident, Philips confirmed the compromise of an internal server, GE has not commented.
  • ReliaQuest confirms active exploitation and JSP webshell deployment, but attribution to Clop remains unconfirmed: "The actor behind these attacks remains unconfirmed."
  • The current campaign does not include file encryption: technical data theft occurs without the typical traces of traditional ransomware.

How the Attack Chain Works on Windchill

The exploit unfolds in two phases. Attackers first probe an information disclosure vulnerability in FlexPLM WSDL endpoints, rated CVSS 7.5, for pre-authentication reconnaissance. The source does not specify the exact path or the size of the files involved.

The second phase exploits CVE-2026-12569, an untrusted data deserialization in the Windchill login servlet. The vulnerability allows unauthenticated remote code execution. According to the NVD record, the CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H: network, low complexity, no privileges required, no user interaction, maximum impact on confidentiality, integrity, and availability.

Once execution is achieved, operators install JSP webshells under /Windchill/login/ with hexadecimal names matching the pattern [0-9a-f]{16}.jsp or dpr_<8hex>.jsp. The file flst.txt handles enumeration, while the header X-windchill-req: ?x8Fmgow characterizes C2 communications. The IP address 79.141.160.78 was active as of August 14, 2026, according to Ransom-ISAC.

"ReliaQuest has observed threat actors actively exploiting CVE-2026-12569, a critical unsafe deserialization vulnerability (CVSS 9.3) affecting PTC Windchill and FlexPLM. Exploitation enables unauthenticated remote code execution and JSP web shell deployment for remote command execution and sensitive product data exfiltration."

ReliaQuest adds, however: "The actor behind these attacks remains unconfirmed. However, the observed tradecraft shares characteristics with previous Cl0p campaigns targeting enterprise applications and high-value data repositories."

Why the Absence of Encryption Changes the Paradigm

Clop has removed encryption from its current campaigns. This operational choice deprives defenders of the most obvious signal of traditional ransomware: the mass writing of encrypted files. Without this signature, the exfiltration of technical data proceeds with lower visibility for traditional monitoring tools.

The stolen data — blueprints, plant test reports, project plans — has a distinctive characteristic: it does not expire. A credit card can be cancelled, a digital identity can be replaced, but the design of an industrial component retains value over time. Clop has structured its extortion on this differential, turning PLM systems into vectors for intellectual property theft.

The Victims: Shell Investigates, Philips Confirms, GE Silent

Shell confirmed via a spokesperson to BleepingComputer: "We are aware of a potential incident. We are working with our security teams and relevant experts to investigate." Clop claims to have stolen 89 GB of data from the oil company. It is not independently verified that the actual volume is 89 GB or that the files contain the described types.

Philips issued a statement reported by Reuters and The News: it "identified and contained an attempted compromise of a specific enterprise server tied to internal data, with no impact on customer environments." Clop claims roughly 13.5 GB from the Dutch company, including technical schematics. This figure is a claim by the group, not independently verified.

GE has not commented publicly at the time of publication. Reuters reports that GE "invoked its cybersecurity response processes," but it was not possible to independently verify the details of the alleged breach.

The total of 43 organizations claimed by Clop carries a margin of uncertainty. The News cites "close to 50 companies" as an alternative figure. It is unclear whether these counts include only organizations actually compromised or also targets of extortion notices.

What to Do Now

  • Apply the PTC patch released on June 17, 2026 immediately: CISA has mandated a June 28 deadline via BOD 26-04 for U.S. federal agencies.
  • Hunt for known IOCs on Windchill/FlexPLM systems: JSP webshells in /Windchill/login/ with hexadecimal patterns, the file flst.txt, anomalous X-windchill-req header, traffic to 79.141.160.78.
  • Check for exposed, unauthenticated FlexPLM WSDL endpoints and restrict access.
  • Review Windchill access logs for suspicious activity in the June–August 2026 period, given the estimated age of the intrusions.

Context and Source Limitations

The narrative structure of this article is based primarily on TechTimes as the primary structured source, with partial corroboration from BleepingComputer, The News/Reuters, and Help Net Security. Clop's claims regarding data volumes (89 GB Shell, 13.5 GB Philips) and the number of victims are not independently verified. Attribution to Clop is an assessment by Ransom-ISAC with "high confidence," not a public forensic proof; ReliaQuest expresses explicit caution on attribution.

The campaign presumably began in early June 2026 according to Ransom-ISAC. Extortion emails were sent around July 20, suggesting an estimated intrusion age of over six weeks at the time of discovery. Censys reported approximately 80 internet-exposed Windchill instances as of July 20, 2026, 80% in the U.S.; the source does not specify the primary exposure vector.

The C2 was active as of August 14, suggesting possible persistence. The German BSI contacted PTC customers by phone and email on the night of June 17. Extortion emails bear the subject "Windchill PDMLink module serious data leak" and originate from compromised accounts.

Information has been verified against cited sources and updated at the time of publication.

Sources


Sources and references
  1. techtimes.com
  2. thenews.com.pk
  3. tech-insider.org
  4. nvd.nist.gov
  5. cisa.gov
  6. helpnetsecurity.com
  7. bleepingcomputer.com