The Russia-linked Clop extortion group has initiated another large-scale data theft campaign, claiming to have breached 43 new multinational corporations. High-profile victims listed on the group's dark web leak site include industrial giants Shell, Philips, and General Electric (GE). The attack vector is suspected to be the mass exploitation of CVE-2026-12569, a critical vulnerability in PTC's Windchill and FlexPLM product lifecycle management (PLM) platforms. This incident continues Clop's highly effective strategy of leveraging zero-day or recently patched vulnerabilities in enterprise file transfer and management solutions to execute widespread, simultaneous data breaches for extortion purposes.
Following a pattern established with the MOVEit and GoAnywhere campaigns, Clop has once again targeted a specialized enterprise software solution to gain access to a multitude of its customers. The group claims to have exfiltrated 89GB of data from Shell, including engineering drawings and project plans, and 13.5GB from Philips, consisting of diagrams and blueprints. The suspected vulnerability, CVE-2026-12569, is a critical improper input validation flaw in PTC Windchill and FlexPLM. PTC had released patches on June 17, and CISA confirmed active exploitation by June 26. Several named victims, including Shell and Philips, have acknowledged they are investigating the claims, with Philips stating it detected and contained an attempted breach.
The campaign is a classic example of exploiting a public-facing application at scale.
Attack Chain:
T1190 - Exploit Public-Facing Application.T1567 - Exfiltration Over Web Service.T1657 - Financial Theft.The impact of this campaign is severe and multi-faceted. The stolen data includes highly sensitive intellectual property, such as engineering drawings, project plans, and product blueprints. The public release of this data could lead to loss of competitive advantage, industrial espionage, and significant financial damage. For the affected companies, the immediate impacts include the cost of incident response, forensic investigation, and potential ransom payments. Reputational damage is also significant, as the breach raises questions about their supply chain security management. This attack underscores the systemic risk posed by vulnerabilities in niche, but critical, enterprise software platforms that are deeply integrated into core business operations.
No specific Indicators of Compromise (IOCs) such as IP addresses, domains, or file hashes were mentioned in the source articles.
Security teams may want to hunt for the following patterns to identify vulnerable systems or active exploitation:
url_pattern*/Windchill/ or */FlexPLM/log_sourceWeb Server Logs (e.g., IIS, Apache)network_traffic_patternAnomalous outbound traffic from PTC serversprocess_nameUnusual child processes of PTC application servicescmd.exe or powershell.exe is a strong indicator of compromise.Network Traffic Analysis (D3-NTA).M1051 - Update Software.M1035 - Limit Access to Resource Over Network.M1030 - Network Segmentation.The most effective mitigation is to promptly apply the security updates provided by PTC to patch the vulnerability.
Mapped D3FEND Techniques:
Restrict network access to PTC application servers. They should not be directly exposed to the internet if possible.
Mapped D3FEND Techniques:
Use a Web Application Firewall (WAF) or IPS with virtual patching capabilities to block exploit attempts against the vulnerability.
PTC releases patches for CVE-2026-12569.
CISA confirms active exploitation of the vulnerability.
Clop begins listing dozens of new victims on its leak site, including Shell and Philips.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.