Skip to content

Clop Ransomware Targets PTC Windchill and FlexPLM

The Bottom Line: Clop ransomware group extorts companies through infiltration and data theft from internet-exposed PTC Windchill and FlexPLM installations.

The Clop ransomware group is conducting a campaign against internet-exposed instances of PTC Windchill and FlexPLM. The goal is data theft and extortion.

The Clop ransomware group (also known as Cl0p) is deliberately targeting internet-exposed instances of PTC Windchill and FlexPLM. Both products are software solutions from PTC for managing product data and manufacturing processes, which are widely used in industry.

The attacks follow the classic extortion model: attackers infiltrate systems, exfiltrate sensitive data, and threaten to publish it unless a ransom is paid. The risk is particularly critical with Windchill and FlexPLM, as these systems often contain product drawings, manufacturing data, and technical specifications – information of high financial value to competitors or other threat actors.

As a CISO, you should immediately verify whether your Windchill or FlexPLM instances are reachable on the Internet. The central defensive measure is to isolate these systems from the public network: they should only be accessible via VPN and authentication. Additionally, you should review access logs for suspicious activity and immediately deploy PTC security updates and hardened configurations.


Source: www.bleepingcomputer.com · Published 24 July 2026
Lumi AI News — AI-assisted curation according to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: