PTC said the two enterprise software platforms are widely used by high-profile companies across the aerospace, defense, automotive, heavy machinery, retail, and medtech sectors. The company said more than 30,000 customers globally use its products, including over 1,500 brand and retail customers using FlexPLM.
See also: Implementing a true approach to PLM, the cornerstone of manufacturing
In these attacks, Clop claims it stole a wide range of sensitive data from the companies’ compromised systems, including backups, project plans, photos of facilities, drawings, diagrams, blueprints, and more, belonging to Shell, GE, and Philips, according to Bleeping Computer.
The ransomware group claimed it stole it stole 89GB of data from Shell.
Warning, patches came too late to stop attacks
BleepingComputer also reported that some of the tools used by the Clop ransomware gang were specifically designed to breach PTC Windchill and FlexPLM servers, based on detailed knowledge of Windchill’s functionalities.
“First, there is evidence that attackers were exploiting these PTC environments before defenders had the full benefit of the public warning and remediation process,” said Ensar Seker, chief information security officer at cybersecurity company SOCRadar.
Second, he stressed, “a patch was released” does not necessarily mean that every version of a complex enterprise platform could immediately receive it. PTC’s remediation was released in stages across different Windchill and FlexPLM versions.
Large manufacturers also can have many instances, different versions, integrations with engineering and manufacturing systems, and strict testing and availability requirements. Knowing about a vulnerability and safely remediating every affected instance across a global enterprise are two different problems.
See also: Black Kite: Ransomware increasing across all metrics in 2026
Cyberattacks against manufacturing operations are hardly new, but AI is rapidly changing how quickly attackers can identify targets, find vulnerabilities, and exploit them.
At the same time, manufacturers are taking advantage of connectivity between IT and OT systems, adopting cloud-based tools, and enabling remote access to plant-floor assets. That connectivity exposes systems that do not have up-to-date cyber defenses to possible attack.
Click Here For The Original Source.
