Clop Hits Windchill and FlexPLM in Data-Theft Push
Clop is running an active data-theft campaign against internet-exposed PTC Windchill and FlexPLM. No encryption — straight to exfiltration and extortion.
Active campaign. Confirmed. Clop is targeting internet-exposed PTC Windchill PDMLink and FlexPLM deployments in a new data-theft extortion operation. Reported July 24.
No file encryption. The model: get in, exfiltrate, extort. Same operational pattern Clop ran against GoAnywhere MFT in early 2023, then MOVEit Transfer that summer, then Cleo managed-file-transfer software in late 2024. Each time: a widely-deployed enterprise platform with instances reachable from the internet, a narrow window before patches land, mass data theft.
What’s being targeted. Windchill PDMLink and FlexPLM — both PTC products. Windchill is the PLM (product lifecycle management) system that sits between engineering design and the shop floor in manufacturing, defense, and aerospace organizations. It holds CAD files, bills of materials, and engineering release history. FlexPLM serves retail and apparel. The specific CVEs being exploited in this campaign have not been publicly disclosed at time of writing — PTC has not yet published a security advisory. Unconfirmed. Check PTC’s security advisories page and the CISA KEV catalog directly for updates.
Immediate action items, in order.
-
Find your exposure first. Neither PTC nor standard enterprise security practice recommends Windchill or FlexPLM directly internet-facing. Audit now. If any instance is publicly reachable, pull it behind a VPN or zero-trust gateway before anything else.
-
Patch. PLM systems collect patch debt because change management in manufacturing environments is slow and painful. That friction is now a direct liability. Apply current PTC patch levels.
-
Check logs. Audit the July 23–25 window for anomalous data-transfer volumes, unusual user activity, or lateral movement indicators. Clop typically stages exfiltrated data before initiating extortion contact — there may still be time to catch that activity.
-
Review third-party integrations. Windchill deployments commonly tie into ERP systems, CAD tools, and CI/CD pipelines under service accounts. Check those accounts for activity outside normal parameters.
Clop selects target categories with two properties in common: organizations that struggle to patch on a normal timeline, and data that organizations cannot afford to have leaked. Engineering IP, manufacturing specifications, defense program documentation — PLM systems hold all of it. The value proposition for extortion is straightforward.
Internet-exposed Windchill or FlexPLM right now: treat this as an active incident response situation, not a pending maintenance item.
Source: BleepingComputer, July 24, 2026
Found this useful? Share it.
