CYBERSECURITYTRACKER
TRACKING6,528 stories in this site build1,321 vulnerability news stories in this site build
Permanent story citation

The long tail of Clop’s PTC hack is just beginning to emerge

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4706

As cited

Copy frozen at (site build).

ransomware

The long tail of Clop’s PTC hack is just beginning to emerge

Clop, a prolific data theft extortion group, exploited a critical zero-day vulnerability (CVE-2026-12569) in PTC's Windchill and FlexPLM software products to compromise dozens of organizations across manufacturing, aerospace, and retail sectors. The group deployed custom web shells designed specifically for Windchill that automate credential theft, malware delivery, and data exfiltration while evading detection. PTC patched the vulnerability on June 18, but exploitation occurred in early June, and the full scope of compromise remains unclear as companies continue investigating and Clop sends extortion demands.

Why it matters: Manufacturers, retailers, and enterprises using PTC Windchill or FlexPLM need to verify patching status, hunt for indicators of compromise, and review access logs from June 2026 onward, as this campaign mirrors Clop's pattern of prolonged, widespread exploitation that can take weeks or months to fully discover.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

The long tail of Clop’s PTC hack is just beginning to emerge

Clop, a prolific data theft extortion group, exploited a critical zero-day vulnerability (CVE-2026-12569) in PTC's Windchill and FlexPLM software products to compromise dozens of organizations across manufacturing, aerospace, and retail sectors. The group deployed custom web shells designed specifically for Windchill that automate credential theft, malware delivery, and data exfiltration while evading detection. PTC patched the vulnerability on June 18, but exploitation occurred in early June, and the full scope of compromise remains unclear as companies continue investigating and Clop sends extortion demands.

Why it matters: Manufacturers, retailers, and enterprises using PTC Windchill or FlexPLM need to verify patching status, hunt for indicators of compromise, and review access logs from June 2026 onward, as this campaign mirrors Clop's pattern of prolonged, widespread exploitation that can take weeks or months to fully discover.

VendorsOracleProgress Software
Actorsclop
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary