Skip to main content

Tag: clop ransomware

6 articles

ShinyHunters Breaches Clop Ransomware Site, Threatens Extortion

In a stunning turn of events, the ShinyHunters group has breached the Clop ransomware gang's Tor leak site, leaving a cheeky message and ASCII art of Umbreon in its wake. The hackers boldly declared they'd been rooting the gang's systems since 2019.

Analyst 207
Brightly-lit industrial control system terminal on a rack in a factory setting.

Clop Ransomware Operation Exploits Windchill Flaw with Custom Web Shell

The Clop ransomware operation has exploited a critical flaw in PTC Windchill and FlexPLM servers, deploying a custom web shell that allows for easy credential theft and massive data exfiltration. This sneaky move gives attackers a direct path to sensitive data, with no extra tools needed.

Analyst 207
Server room with computer equipment and a monitor displaying lines of code in the foreground.

Clop Ransomware Gang Crafts Custom Web Shell for Windchill Attacks

The Clop ransomware gang has taken its attacks to the next level by crafting a custom Java web shell that specifically targets PTC Windchill and FlexPLM servers, allowing them to harvest sensitive data with ease. This tailored tool is a significant evolution of their mass-exploitation tactics, making it a major concern for businesses using these applications.

Analyst 207
Rows of computer servers and storage equipment in a brightly-lit data center with concerned businesspeople in the background.

Clop Ransomware Targets GE, Philips in Data Theft Attacks

Major companies like Philips, General Electric, and Shell are investigating claims by the Clop ransomware gang that their systems were breached, with Philips confirming a contained breach of an internal server that didn't affect customers. The incidents are a stark reminder of the growing threat of ransomware attacks on businesses.

Analyst 207
Modern office building exterior with subtle tech features and Shell fuel station.

Shell Probes Data Breach After Clop Ransomware Gang Claims Theft

Shell is investigating a potential data breach after the notorious Clop ransomware gang claimed to have stolen 89GB of sensitive information from the energy giant. The company is working closely with its security teams and experts to get to the bottom of the incident.

Analyst 207
Industrial facility interior with computer workstations, machinery, and a laptop screen, with daylight through large windows.

Clop Ransomware Targets PTC Windchill in Data Theft Attacks

A critical vulnerability, CVE-2026-12569, with a near-perfect CVSS score of 9.3 is being exploited by Clop ransomware attackers to breach PTC Windchill and FlexPLM systems, putting sensitive data at risk. Security patches are available, but urgent action is needed to prevent data theft.

Analyst 207