← All Briefings
Briefings


Cl0p Exploits Unpatched PTC Windchill in New Extortion Wave

Cl0p, tracked elsewhere under the aliases Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest, is exploiting flaws in internet-exposed PTC Windchill and FlexPLM deployments to gain initial access, according to reporting cited by The Hacker News on July 26. Windchill and FlexPLM are product lifecycle management platforms manufacturers use to store CAD files, bills of materials, and supplier specifications, the kind of data that does not show up in a breach notification's "types of information involved" checkbox because most disclosure templates were written with customer PII in mind, not engineering IP.

The exploitation pattern repeats a Cl0p sequence that ran through Accellion FTA in 2021, GoAnywhere MFT in 2023, and MOVEit Transfer later that year: find an internet-facing enterprise file or lifecycle management platform, mass-exploit before a patch lands, then run extortion off the stolen data rather than deploy ransomware. Any manufacturer running Windchill or FlexPLM with the management interface reachable from the open internet should treat that exposure as the control question for this week, not whether Cl0p's aliases get resolved into a single named group.

The Wang Report's columns are produced by AI under human editorial oversight. See our Editorial Standards.