The prolific Russian-speaking Clop ransomware gang claims it stole troves of sensitive information from more than 50 organizations, including General Electric (GE), Philips, and Shell.
The breach stems from the exploitation of a critical (CVSS v3 9.8) unauthenticated remote code execution (RCE) vulnerability, CVE-2026-12569, in PTC’s Windchill and FlexPLM product lifecycle management (PLM) tools via deserialization of untrusted data. Over 30,000 enterprises worldwide use Windchill and FlexPLM to design, manage, and track their products.
PTC released security fixes on June 17 and urged organizations to install the software updates immediately and assess their access logs and environments for indicators of compromise (IOCs).
The Cybersecurity and Infrastructure Security Agency (CISA) also added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on June 26 and ordered federal agencies to patch their systems within 72 hours.
Clop ransomware gang compromises over 50 organizations
The Clop ransomware gang listed approximately 50 organizations affected by the compromise of PTC’s product lifecycle management software. Targeted organizations were predominantly in the manufacturing, automotive, aerospace, and retail and apparel sectors. The ransomware gang likely chained a FlexPLM WSDL disclosure vulnerability and a Windchill login servlet flaw to gain initial access.
Clop claims it exploited the PMDLink module and stole sensitive data, including engineering plans, scans of facility testing reports, photos of the facilities, and project plans. The ransomware gang said it exfiltrated 89 GB from Shell, 391 GB from General Electric, and 13.5 GB from Philips.
The ransomware gang used its access to install hex-named JSP webshells at /Windchill/login/[0-9a-f]{16}.jsp to exfiltrate data from the compromised organizations. The group also sent extortion emails to users within the affected organizations using compromised email addresses.
Meanwhile, Shell has acknowledged the potential impact of the breach, but said it is working with its security teams and relevant cybersecurity experts to investigate the ransomware gang’s claims.
Philips also said it detected an attempted compromise of a server containing personal information, but the attack was contained, and no data was compromised.
Fiserv, another potential Clop ransomware victim, also acknowledged the incident but found no evidence that customer, banking, transaction, or personal data was compromised. GE also said it had activated its cyber incident protocols and was investigating the incident.
Clop ransomware targets enterprise solutions for maximum impact
The Clop ransomware gang has perfected the tradecraft of compromising enterprise software solutions to target high-profile organizations. The group targets popular enterprise platforms instead of individual companies to gain maximum advantage and exfiltrate troves of sensitive information.
“Cl0p’s playbook hasn’t been a mystery for years. They’ve repeatedly targeted widely used enterprise software, exploited known weaknesses, and used stolen data as leverage. Defenders have had plenty of opportunities to study how they operate,” said Pete Luban, Field CISO at AttackIQ.
First detected in February 2019, Clop ransomware is a variant of the CryptoMix ransomware. Despite six of its members being arrested in Ukraine in a massive law enforcement operation, the gang continues to operate with impunity.
The Clop ransomware gang was linked to the compromise of Accellion File Transfer Appliance, GoAnywhere Managed File Transfer, Cleo, MOVEit Transfer, and SolarWinds Serv-U FTP. Victims of the MOVEit Transfer compromise included the BBC, Boots, and British Airways.
It was also attributed to the compromise of Oracle e-Business Suite Applications that affected hundreds of organizations, including Harvard University, the University of Pennsylvania, the Washington Post, Estée Lauder, Logitech, Korean Air, and Envoy Air.

