Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Cl0p Exploits Critical PTC Windchill Zero-Day to Steal Product Designs
July 24, 2026
JetBrains Patches Critical IntelliJ IDEA RCE and Four TeamCity Flaws
July 24, 2026
Apache Syncope Patches Critical RCE and SQL Injection Vulnerabilities
July 24, 2026
Home/Threats/Cl0p Exploits Critical PTC Windchill Zero-Day to Steal Product Designs
Threats

Cl0p Exploits Critical PTC Windchill Zero-Day to Steal Product Designs

Key Takeaways The Cl0p ransomware gang is actively exploiting a critical zero-day vulnerability (CVE-2026-12569) in PTC Windchill and FlexPLM servers. The attack chain allows for unauthenticated...

Sarah simpson
Sarah simpson
July 24, 2026 4 Min Read
4 0

Key Takeaways

  • The Cl0p ransomware gang is actively exploiting a critical zero-day vulnerability (CVE-2026-12569) in PTC Windchill and FlexPLM servers.
  • The attack chain allows for unauthenticated remote code execution, enabling threat actors to steal sensitive engineering and product design data.
  • Affected industries include manufacturing, automotive, aerospace, and retail apparel, all of which rely on Windchill for intellectual property management.
  • Cl0p is employing a double-extortion tactic, sending mass emails to employees of victim organizations to pressure them into paying a ransom.
  • A patch is available, and CISA has added CVE-2026-12569 to its Known Exploited Vulnerabilities catalog, urging immediate remediation.

Affiliates of the notorious Cl0p ransomware group are currently leveraging a critical zero-day vulnerability within PTC Windchill and FlexPLM servers to exfiltrate invaluable engineering and product-design data. This sophisticated campaign exploits a chain of software flaws to bypass authentication, establish persistent server-side access, and extract proprietary information before issuing ransom demands.

Table Of Content

  • Key Takeaways
  • Cl0p Hackers Exploit Windchill Servers
  • Extortion Campaign Raises Pressure

This malicious activity poses a severe risk to sectors heavily reliant on Windchill systems, including manufacturing, automotive, aerospace, and retail apparel companies. These organizations frequently store highly sensitive product records and intellectual property within these platforms, making them prime targets for data theft and extortion.

The attackers are employing a double-extortion model. This strategy allows them to maintain leverage over victims by threatening to release stolen data publicly, even if the affected organizations successfully restore their systems from backups. This significantly increases the pressure on compromised entities to comply with ransom demands.

Security researchers at Ransom-ISAC, in collaboration with eCrime.ch and DEFUSED, were instrumental in identifying this active exploitation. They emphasize that unpatched, internet-facing deployments of PTC Windchill and FlexPLM represent the primary entry vectors for these attacks. The campaign is attributed to Cl0p affiliates, also known by aliases such as Graceful Spider, Chubby Scorpius, FIN11, and Lace Tempest.

According to a Ransom-ISAC report shared with Cyber Security News (CSN), the initial intrusions likely began in early June. This was followed by a wave of mass extortion emails disseminated through randomly compromised accounts. These messages are designed to compel organizations to swiftly investigate potential data theft while simultaneously alerting employees to potential follow-on phishing and social engineering attempts.

Cl0p Hackers Exploit Windchill Servers

The attack sequence commences with a pre-authentication information disclosure vulnerability found in the FlexPLM WSDL endpoint. This initial compromise is then chained with a weakness in the Windchill login servlet. By combining these two flaws, attackers can achieve remote code execution without requiring valid credentials, thereby establishing a persistent foothold on the targeted server.

The primary vulnerability, identified as CVE-2026-12569, is a critical deserialization flaw. It boasts a severe CVSS score of 9.8 and impacts PTC Windchill PDMLink and FlexPLM releases prior to 11.0 M030. This vulnerability was publicly disclosed on June 17, and the Cybersecurity and Infrastructure Security Agency (CISA) promptly added it to its Known Exploited Vulnerabilities catalog on June 25, underscoring its active exploitation and severe risk.

Upon gaining unauthorized access, the threat actors deploy JSP webshells, meticulously inspect server files, and prepare stolen engineering data for exfiltration. This incident mirrors the established pattern of recent Cl0p ransomware campaigns, where publicly exposed enterprise applications serve as direct conduits for the theft of confidential data and subsequent public extortion.

The implications are particularly dire for organizations that rely on Windchill for managing critical design documents, product specifications, and development workflows. A successful breach can lead to the exposure of invaluable intellectual property, which is often irreplaceable and could provide competitors or malicious actors with critical insights into unreleased products and strategic plans.

Notably, this attack bypasses traditional initial access vectors, such as compromising employee mailboxes or tricking users with malicious attachments. Instead, the attackers directly targeted a public-facing application, highlighting the urgent need for organizations to continuously identify and secure internet-exposed systems and to apply security updates for high-impact vulnerabilities without delay.

Extortion Campaign Raises Pressure

Beginning July 20, Ransom-ISAC observed a new phase of the campaign: extortion emails with the subject line “Windchill PDMLink module serious data leak” were sent to hundreds of employees across affected organizations. This tactic aims to disseminate news of the breach internally, thereby increasing pressure on executives and incident response teams before the victim organization is publicly named.

This approach is reminiscent of last year’s Oracle EBS campaign, though the current operation utilizes fresh email addresses. Organizations receiving such communications are advised to preserve the emails and their headers, thoroughly validate the claims through internal investigations, and reinforce employee training on reporting suspicious communications, mirroring best practices from reported Oracle EBS breach investigations.

Organizations that have received these matching emails should initiate a comprehensive hunt for compromise, tracing back to early June. They should utilize published indicators of compromise (IoCs), apply all available fixed builds, and rigorously follow vendor-specific remediation guidance. Security teams should prioritize securing externally accessible Windchill and FlexPLM servers, searching for unexpected JSP files and unusual outbound network activity, and reviewing access logs for the specific reconnaissance request observed in these attacks. Actively monitoring CISA KEV catalog alerts can further assist teams in prioritizing patching efforts for known exploited vulnerabilities.

This incident underscores the critical danger posed by unauthenticated code execution flaws in business-critical systems. Past instances of similar <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/401351a4-3a09-4e1b-a8a3-d2ded263c489/Cl0p-Hackers-Exploit-Windchill-Servers-to-Steal-Companies-Secret-Product-Designs.pdf?AWSAccessKeyId=ASIA2F3EMEYE3HSH2TK5&Signature=Owj4Tsypgr%2BiCSRioBj4IK%2Fwx5M%3D&x-amz-security-token=IQoJb3JpZ2luX2VjED0aCXVzLWVhc3QtMSJHMEUCIQC5O6iiBr3exXjMZqoZ81zQLVOxvz5qQeybx1x3orpuMAIgdomGElzL3yRdf5hLUYZBHit262yJ6AiAk4%2F%2Fs%2Bczk8Qq8wQIBRABGgw2OTk3NTMzMDk3MDUiDJ5tPNKOd8t89qWWGSrQBFDQisD4adVQ8cht2yjStwc2Gxti2WtkDyCh7Kx4Z89TI2q%2B5vsjfOgPPDhnb6d9k6V8jsZUcKfbDytyx43KoqcP7J8ceYTgR8GQ%2F0I0Q5pwjc5t80rHYcBndcMaD0L2wW061uHFMh%2Fuqbd4TiELGR%2Fr4RFBIMlCZNGZpgA9ZQnY1R%2FGim9wKubSxBjBFEVfZs4dwdf%2BF9qPQEPCOKBmzX%2Fs%2BXLVKMHgsGNfpmJi3tLHwHm0LWFGJ0mrik6Yixg54QGH6%2FWyxo64MQ80mFlUhiO0bcZytnroOmRHtA%2FF7EBxbG5WdpbqhcXmFj2j3W0BUOMK0o8RWr8%2BjiasobVheLulC7Q3RoFKaVx01drGmts%2Bls%2BNaT3WVjgyXSRfD8RkSYHUpnY1nNjVGrxnHP%2FZKVy7cVrxxzm9mcKPMDH3YX2lrKLZONeHehIa0sURs609EwTq%2F20a7QdUwXKYvtMiIO8VoKjd8qW3w4B6SHAQ7E5OAxWPUtd8sKcbZDZhHOjwglJngMRqochw9r1Hx2YhdfINZU7O26WByotr0kxMkHJQ8eci6GRLGhN1jDmNRrQdTFmL4Lw2zk9%2BcnMwl7G7k385wmOTyl13jqK00VXmZMDx4aqDNYEiq8OvIFbrtZCWcYy6nc0z4paKriTSRbacNYEa7Qigi0bNG1rv%2FGiPBJPvYD8Gvf6gvX8%2BDOCIifRTOYYRLKMTJXkXdLFFgH2IAe9tbH3BXZpNMhvnKwiZqJapVdHGvLIScoUPgeGY%2F5fqf0Oi0pNjzR%2FMUSoQ83y4MKgwr66N0wY6mAHv3ZU06Dk%2F0WZCXgzl6VW1tdFfo56Zm8LigYEn5v5ZCPSLiN2uDgtojGf1aMhduJI

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

BreachCVEExploitHackerPatchphishingransomwareSecurityVulnerabilityzero-day

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

JetBrains Patches Critical IntelliJ IDEA RCE and Four TeamCity Flaws

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Microsoft Confirms No Ads in Windows 11, LG Disables McAfee Pop-ups
July 24, 2026
SourTrade Malvertising Builds Unique Malware in Browsers to Evade Detection
July 24, 2026
ChonkyChicken Malware Steals Chrome Credentials and Spies on Victims
July 24, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us