← Home

Clop ransomware targets Windchill and FlexPLM in new wave of industrial data attacks

The Clop ransomware group is targeting Windchill and FlexPLM systems to steal industrial data. Instead of encrypting files, Clop is focusing on data exfiltration — stealing projects, technical specs, and IP, then threatening to leak it.

Clop is one of the oldest active ransomware groups, known for high-profile attacks. Targeting Windchill and FlexPLM is strategic: these systems hold manufacturers' most valuable IP — engineering designs, CAD drawings, product specs.

What matters isn't the attack itself, it's the target recognition: Clop understood that industrial data is worth more than financial or personal data. Manufacturing companies, which historically invest less in security than banks, are now in the crosshairs.

Source: BleepingComputer