Cyber Incident Victim: Zebra
Timeline
Summary
Clop exploited a zero-day vulnerability in PTC's Windchill and FlexPLM software, gaining remote code execution and stealing data from numerous organizations. Zebra and Toast reported detecting and containing intrusions with limited impact, while other companies such as GE, Philips, and Shell were alleged victims but did not comment. Researchers noted the attackers used a custom web shell to harvest credentials, move laterally, and exfiltrate large volumes of data. The campaign added to Clop's history of mass‑exploitation extortion efforts targeting downstream customers of compromised software.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 3 techniques |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
In June 2026, PTC disclosed a critical zero‑day vulnerability affecting its Windchill and FlexPLM products, tracked as CVE‑2026‑12569, and released a patch and initial indicators of compromise the following day. The Cybersecurity and Infrastructure Security Agency added the flaw to its known exploited vulnerabilities catalog on June 25 after it was found to allow unauthenticated remote code execution. Despite the patch, threat actors believed to be linked to the Clop ransomware group began exploiting the vulnerability in early June, gaining access to PTC customer environments. By mid‑July, Clop started sending threatening emails to alleged victims, announcing data theft and demanding extortion payments. Among the companies that responded to inquiries, Zebra, a software vendor, told CyberScoop that it had detected and contained system intrusions related to the campaign. Zebra stated that the impacts of the intrusion were limited, though it did not disclose further technical details.

Researchers from ReliaQuest observed that Clop deployed a custom web shell specifically designed for Windchill environments, which facilitated credential theft, malware delivery, sustained access, network traversal and data encryption. The web shell enabled the attackers to exfiltrate data from compromised systems over an extended period, consistent with Clop’s pattern of maintaining access for weeks or months before issuing extortion notices. Zebra’s statement placed it alongside other named entities such as Toast, which also reported detecting and containing intrusions with limited impact, while companies like GE, Philips and Shell did not comment on the incident. The campaign added to Clop’s history of mass‑exploitation efforts, including a prolonged attack on Oracle E‑Business Suite customers in the summer of 2025 and the 2023 MOVEit breach that affected more than two thousand three hundred organizations. As of the article’s date in August 2026, the full scope of Zebra’s involvement remained confined to the acknowledgment of detection, containment and limited impact, with no additional public details provided.