supply-chaintrade-pressNewsThe Broadside2 min read

Clop exploits PTC Windchill zero-day in supply-chain attack

The playbook is familiar (zero-day in supply-chain SaaS, mass exploitation, extortion) but PTC still won't say how many customers were compromised or when exploitation began.


TL;DR

Clop exploited CVE-2026-12569, a zero-day in PTC's Windchill and FlexPLM platforms, stealing data from manufacturers across aerospace, automotive, and other industries. PTC disclosed the flaw June 17 and patched June 18, but Ransom-ISAC says victims were likely compromised by early June. CISA added it to KEV June 25 with a June 28 BOD 26-04 deadline. Toast and Zebra confirmed limited intrusions; GE, Philips, and Shell are among claimed victims. PTC still hasn't disclosed how it discovered the breach, and it won't say when exploitation began or how many customers were affected.

Clop exploits PTC Windchill zero-day in supply-chain attack
Editorial illustration · drawn by The Broadside

Clop's latest campaign follows a pattern the group has now run three times in as many years: find a zero-day in a widely deployed supply-chain SaaS platform, then exploit it silently for weeks or months before demanding payment from downstream customers. MOVEit in 2023. Oracle E-Business Suite in 2025. Now PTC Windchill and FlexPLM. Each time the group goes quiet between campaigns, then springs back with custom tooling purpose-built for the target platform.

The scope PTC won't disclose

PTC disclosed CVE-2026-12569 on June 17 and shipped a patch the next day. It has steadily released new indicators of compromise as researchers uncovered them. But it hasn't said how it first learned of the vulnerability, when exploitation began, or how many of its customers are compromised. Ransom-ISAC pegs the earliest likely compromise to early June, meaning Clop had at least two weeks of access before PTC acted. For downstream manufacturers now hunting for signs of compromise, the absence of a timeline from the vendor makes incident scoping harder, not easier.

Custom web shell, custom evasion

ReliaQuest found Clop deployed a web shell built specifically for Windchill. The tool decrypts credentials, delivers malware, and mimics Windchill's standard operations to evade detection. It also gives attackers sustained access for network traversal and data encryption, capabilities that required pre-compromise development work against the platform. That isn't opportunistic exploitation. It means Clop identified Windchill as a high-value target well before the campaign started.

CISA's clock and the long tail

CISA added CVE-2026-12569 to its Known Exploited Vulnerabilities catalog on June 25, giving federal agencies until June 28 to patch or disconnect under BOD 26-04. The SSVC assessment tagged it as actively exploited and automatable with total technical impact. But for manufacturers using Windchill or FlexPLM to manage product lifecycles and supplier data, the operational question isn't whether the patch was applied. It's whether sensitive data already left their environment weeks earlier, a question PTC's silence makes harder to answer.


Published ·Deep Fathom