ZeroFox Intelligence Flash Report - Cl0p Shifts from Personal Data to Intellectual Property Theft
|by Alpha Team

ZeroFox Intelligence Flash Report - Cl0p Shifts from Personal Data to Intellectual Property Theft
Product Serial: F-2026-08-21a
TLP:CLEAR
In this Flash Report, ZeroFox researchers report on Cl0p's recent dark web leak site posts which likely indicate that the group is in the early stages of a new campaign targeting engineering-focused intellectual property on vulnerable product lifecycle management servers.
Standing Intelligence Requirements
For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- Between August 14 and August 19, 2026, Cl0p posted 43 organizations to its dark web leak site and began issuing extortion demands tied to data allegedly stolen from internet-exposed server instances of product lifecycle management platforms Windchill and FlexPLM, both of which are made by software-as-a-service (SaaS) company PTC, Inc.
- The type of data targeted and the small population of Windchill and FlexPLM users mark a significant change for Cl0p and likely suggests the threat actor is entering a new phase of operations.
- Cl0p was first observed in 2019 and has shifted its operations twice before: first from strict encryption to double extortion in 2020 and then to mass data exfiltration in 2021. Both prior significant operational changes marked a new phase of threat activity and sustained campaigns.
- Cl0p is likely in the early stages of a new campaign targeting engineering-focused intellectual property on vulnerable product lifecycle management servers.
Tags: tlp:clear, dark web, threat actor