Clop Hackers Strike Again, Targeting PTC Software Used by Major Manufacturers
Clop exploits Windchill flaw to hack major firms like GE and Shell, using a custom web shell for swift data theft. Impact still unfolding.
By
Content Team
ON THIS PAGE
Want more insights like this?
Subscribe to our newsletter to get the latest software protection strategies delivered to your inbox.
By submitting your email, you consent to Codekeeper contacting you and agree to our privacy policy.
The Clop cybercrime group is at it again — this time exploiting a zero-day vulnerability in PTC's Windchill and FlexPLM software, tools widely used in manufacturing, aerospace, and automotive industries. The group began sending extortion emails to victims in mid-July, claiming it stole data from dozens of organizations, potentially including GE, Philips, and Shell.
PTC disclosed the flaw (CVE-2026-12569) on June 17, but companies were likely compromised weeks earlier. Clop deployed a custom web shell purpose-built for Windchill, enabling rapid credential theft and data exfiltration with minimal detection. Toast and Zebra confirmed intrusions but say impacts were limited. The fallout is still unfolding.
Source: CyberScoop
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo