Menu
Browse

Cyber Incident Victim: Zebra

Date

Jun 2026

Location

Status

Unknown

Updated

2026-08-23 20:55

Timeline
Occurred
Jun 2026
Discovered
Jul 2026
Disclosed
Aug 2026
Resolved
Pending
Summary

Clop exploited a zero-day vulnerability in PTC's Windchill and FlexPLM software, gaining remote code execution and stealing data from numerous organizations. Zebra and Toast reported detecting and containing intrusions with limited impact, while other companies such as GE, Philips, and Shell were alleged victims but did not comment. Researchers noted the attackers used a custom web shell to harvest credentials, move laterally, and exfiltrate large volumes of data. The campaign added to Clop's history of mass‑exploitation extortion efforts targeting downstream customers of compromised software.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 3 techniques
Threat Actor Type Location
1 actor Available to members Available to members

Description

In June 2026, PTC disclosed a critical zero‑day vulnerability affecting its Windchill and FlexPLM products, tracked as CVE‑2026‑12569, and released a patch and initial indicators of compromise the following day. The Cybersecurity and Infrastructure Security Agency added the flaw to its known exploited vulnerabilities catalog on June 25 after it was found to allow unauthenticated remote code execution. Despite the patch, threat actors believed to be linked to the Clop ransomware group began exploiting the vulnerability in early June, gaining access to PTC customer environments. By mid‑July, Clop started sending threatening emails to alleged victims, announcing data theft and demanding extortion payments. Among the companies that responded to inquiries, Zebra, a software vendor, told CyberScoop that it had detected and contained system intrusions related to the campaign. Zebra stated that the impacts of the intrusion were limited, though it did not disclose further technical details.

Cyber Incident Image

Researchers from ReliaQuest observed that Clop deployed a custom web shell specifically designed for Windchill environments, which facilitated credential theft, malware delivery, sustained access, network traversal and data encryption. The web shell enabled the attackers to exfiltrate data from compromised systems over an extended period, consistent with Clop’s pattern of maintaining access for weeks or months before issuing extortion notices. Zebra’s statement placed it alongside other named entities such as Toast, which also reported detecting and containing intrusions with limited impact, while companies like GE, Philips and Shell did not comment on the incident. The campaign added to Clop’s history of mass‑exploitation efforts, including a prolonged attack on Oracle E‑Business Suite customers in the summer of 2025 and the 2023 MOVEit breach that affected more than two thousand three hundred organizations. As of the article’s date in August 2026, the full scope of Zebra’s involvement remained confined to the acknowledgment of detection, containment and limited impact, with no additional public details provided.

Sources
Sources available to members
1 source