The Russian-speaking cybercriminal group Clop has launched a large-scale exploit campaign against enterprise software, breaching nearly 50 organisations worldwide. Among the victims are global heavyweights Shell, Philips, GE and Fiserv, with attackers allegedly exfiltrating hundreds of gigabytes of sensitive engineering and project data.
Targeting High-Value Infrastructure
Clop's campaign exploited internet-exposed instances of PTC Windchill and FlexPLM, two Product Lifecycle Management (PLM) platforms widely used across corporate IT environments. The attackers leveraged a critical zero-day remote code execution flaw, tracked as CVE-2026-12569, which stems from improper input validation when the platform processes serialised objects — allowing attackers to trick the system into executing malicious code without authentication.
Cybersecurity firm ReliaQuest detailed the impact, noting that the vulnerability allowed unauthenticated remote code execution and the deployment of JSP web shells, giving attackers a persistent channel to remotely inspect, manipulate and exfiltrate high-value corporate data. The firm added that while the identity of the actor behind the attacks remains unconfirmed, the tactics closely resemble previous Clop campaigns against enterprise applications and large data repositories.
"Attackers no longer need to breach 50 companies 50 times"— Anup Kumar, CEO, Optiv Consulting
Mitigation Steps for Affected Users
Recommended mitigations include applying PTC's vendor patch CS473270 and placing Windchill and FlexPLM instances behind VPNs or other trusted access gateways. Security teams that suspect exploitation are advised to isolate affected servers and preserve forensic artifacts to support formal investigations, while enterprises should rotate all exposed credentials before restoring services.
Despite the technical sophistication of the exploit, the group's overarching approach to breaching organisations has remained largely consistent with its earlier campaigns.
A Shifting Policy Landscape
Governments are also adjusting policy in response to persistent threats against key industry sectors. A recent executive order from Washington authorises private organisations to hack foreign transnational criminal groups. Kumar views the move as a meaningful step toward letting private-sector speed and expertise be used directly against threat groups.
