The Clop ransomware group is targeting Windchill and FlexPLM systems to steal industrial data. Instead of encrypting files, Clop is focusing on data exfiltration — stealing projects, technical specs, and IP, then threatening to leak it.
Clop is one of the oldest active ransomware groups, known for high-profile attacks. Targeting Windchill and FlexPLM is strategic: these systems hold manufacturers' most valuable IP — engineering designs, CAD drawings, product specs.
What matters isn't the attack itself, it's the target recognition: Clop understood that industrial data is worth more than financial or personal data. Manufacturing companies, which historically invest less in security than banks, are now in the crosshairs.
Source: BleepingComputer