The targeting of industrial product lifecycles
# The targeting of industrial product lifecycles
Technology is still the loudest sector on the wire, with 290 stories hitting this week. Government follows at 141, and retail sits at 111. If you're looking at those numbers, you're seeing a volume game. But the most interesting movement isn't in the noise. It's in manufacturing.
Manufacturing clocked 69 stories this week. It's a fraction of the tech volume, but the signal is different. We aren't seeing the usual "spray and pray" ransomware. We're seeing a precision strike on the crown jewels of industrial design.
Specifically, look at the activity from Clop. They've had 3 stories this week, and the focus is on Windchill and FlexPLM. For those who don't spend their weekends reading vendor documentation, these are Product Lifecycle Management (PLM) tools. They aren't just databases; they are the central repositories for every CAD drawing, bill of materials, and engineering change order a company owns.
When a group targets a PLM, they aren't looking for the HR director's password to encrypt a few laptops. They're looking for the "golden" files.
The industry loves to slap a "critical" label on these vulnerabilities. I find that the word is rarely earned. A vulnerability is only critical if the exploit is weaponized and the target is reachable. In the case of PLM software, the vulnerability is often less important than the lack of patching. PLM updates are notoriously brittle; one wrong version jump and you break the integration between your design team and your shop floor. Most firms are running versions that are three or four cycles behind the current fix because the risk of downtime outweighs the theoretical risk of a breach.
Attackers know this. They aren't fighting a sophisticated defense; they're fighting a legacy update cycle.
Then there's the noise from the Linux side. The Everest group mentioned 400 Linux kernel flaws recently. To the average CISO, that's just a big number to put in a slide deck. To someone actually looking at the shop floor, it's a problem. Manufacturing environments are littered with edge devices, gateways, and HMIs running stripped-down Linux kernels that haven't seen a patch since 2019.
It's an interesting choice.
The argument usually goes that ransomware is the primary threat here. The logic is that the goal is a quick payout. I disagree. The goal here is the blueprint.
If you want to monetize a manufacturing breach, you can encrypt the servers and ask for a few million dollars. That's the amateur move. The professional move is to steal the IP and sell it, or use it to build a competing product. When Clop hits a PLM system, they're gaining the ability to clone a product without spending a dime on R&D.
The strongest objection to this is that Clop is, by definition, a ransomware gang. They want the ransom. But the shift in their targeting suggests a pivot. They're using the threat of data leakage as a lever, but the data they're collecting is far more valuable than the ransom they're requesting.
This creates a second-order effect that most insurance providers aren't pricing in. If a competitor or a state-sponsored entity gets a hold of a company's PLM data, the damage isn't a week of downtime. The damage is the permanent loss of competitive advantage. Even worse, it opens the door for the "counterfeit part" problem. If an attacker has the exact specifications for a critical component, they can produce "grey market" parts that are functionally identical but lack the quality control of the original. These parts then flow back into the supply chain, potentially causing catastrophic failures years down the line in sectors like aerospace or energy.
We've seen this rhyme before. The 2010-era industrial espionage campaigns were about the same thing—stealing blueprints—but they were conducted via stealthy APTs that tried to remain invisible for years. The difference now is the velocity. Groups like Clop aren't trying to hide; they're using the ransomware playbook to create a window of chaos while they exfiltrate the high-value IP. They've realized that the loudest way to steal something is often the most effective, because the defenders are too busy fighting the fire to notice who's walking out the front door with the blueprints.
Consider the contrast in data volume. The Anubis group recently bragged about stealing 1TB of data from Fairlife. A terabyte of dairy unit data is a lot of spreadsheets and emails, but its value decays quickly. A 10MB PDF of a proprietary turbine design from a PLM system, however, is a permanent asset.
The defenders in manufacturing are currently fighting a war on two fronts. They're dealing with the "noisy" threats—the 400 kernel flaws and the automated scanners—while the real danger is the surgical strike on their PLM. They're patching the perimeter while the center of the house is wide open because the software is too old to update.
I'm watching to see if we see a spike in "non-ransom" leaks from the manufacturing sector. If we start seeing industrial designs appearing on specialized forums without a corresponding ransomware demand, it'll confirm that the encryption was just a distraction.
Until then, if you're running Windchill or FlexPLM and your version number is more than two cycles behind the current release, you aren't "stable." You're just waiting for the invite.
◼