SYS::ONLINE
Wasteland.
Briefs1902
Issues23
SinceFeb 2026
LIVE
█ Ransomware LARGAN-PRECISION-H 2026-08-13

Largan Precision and Honghe Tech: Clop Data Extortion Claim

"The Clop ransomware operation added Taiwanese precision optics manufacturer Largan Precision and Chinese interactive-display maker Honghe Tech to its dark web leak site on August 12, 2026, according to monitoring by…"

The Clop ransomware operation added Taiwanese precision optics manufacturer Largan Precision and Chinese interactive-display maker Honghe Tech to its dark web leak site on August 12, 2026, according to monitoring by ThreatMon relayed through UNDERCODE NEWS. ThreatMon logged LARGAN.COM.TW at approximately 18:30 UTC+3 and HONGHE-TECH.COM at approximately 18:38 UTC+3, alongside a third entry, IRCO.COM, identified as US industrial group Ingersoll Rand, at approximately 18:29 UTC+3. No record counts, data volumes, or sample files have been published in any source reviewed here. Neither company has issued a statement, and no regulator filing or national CERT advisory naming either victim exists in this source set. Every account of the listings themselves comes from a single OTHER-tier publication citing a single monitoring vendor, which is a thin evidentiary base for a claim of this size.

What Happened

Three victim entries appeared on Clop's leak infrastructure inside a nine-minute window on August 12. The two UNDERCODE NEWS reports covering that window pair the victims differently: the first frames the event as Largan Precision and Honghe Tech being added "within minutes of one another," while the second, published eight minutes later, frames it as Ingersoll Rand and Honghe Technology. Read together with the timestamps, the sequence is most plausibly IRCO.COM at 18:29, LARGAN.COM.TW at 18:30, and HONGHE-TECH.COM at 18:38, with Honghe appearing in both writeups and the two articles simply slicing the same batch differently. That reading is an inference, not something either source states.

Largan Precision is a Taichung-based optics manufacturer founded in 1987 and a key camera lens supplier to Apple. Its corporate materials describe twelve manufacturing facilities in Taiwan plus one factory in China. The Taipei Times reported on July 10 that Largan posted second-quarter revenue of NT$13.66 billion (US$424.51 million), up 17.07 percent year on year, with net profit up 352 percent to NT$4.67 billion and gross margin of 49.41 percent. Chairman Adam Lin told the earnings conference that yields on new variable-aperture smartphone lens modules were still improving and that factory utilization remained below normal for the quarter. Honghe Tech is a Chinese manufacturer in the smart education and interactive display sector with, per its own website, a broad international footprint.

The critical caveat is one the sources themselves raise. UNDERCODE NEWS states directly that the available information "represents a ransomware claim, not independent confirmation that either organization was successfully compromised." Deepstrike's Cl0p reference guide makes the same point as a standing methodological rule: a name on a criminal leak site does not independently confirm compromise, data theft, impact, attribution, or victim totals.

What Was Taken

Nothing has been substantiated. No source reviewed here reports a record count, a data category breakdown, a leak archive size, or a published sample for either Largan or Honghe. There is no company notification, no exchange filing, and no regulator disclosure to compare against Clop's claim.

What can be said is what the wider campaign has been going after. ReliaQuest, cited by BleepingComputer, describes the current Clop-linked activity as targeting "sensitive product data" held in PLM platforms. East Bay Cyber's July 24 digest frames the exposure concretely: Windchill and FlexPLM sit at the center of engineering and manufacturing workflows, making them a high-value path to intellectual property, supplier records, design documents, and internal collaboration data. For a contract optics manufacturer whose entire commercial value rests on lens design, tolerance data, and named customer programs, that category of loss is materially worse than a customer PII breach. Deepstrike notes the same concentration risk for managed file transfer platforms, which aggregate data from multiple departments, customers, vendors, and subsidiaries into one exposed system.

Absent evidence, treat the scope of any Largan or Honghe data exposure as unknown.

Why It Matters

Clop has spent 2026 running a data-theft-first extortion model rather than a mass-encryption model. Deepstrike's assessment is that encryption is not universal across Cl0p-linked campaigns, and that several of the major ones focused on stealing data from internet-facing enterprise software and applying pressure without widespread file encryption. That changes the defender's calculus: there may be no ransom note on a workstation, no halted production line, and no obvious operational signal at all. The first indication is often the leak site listing or a wave of extortion email.

The victim mix in this batch matters too. An iPhone lens supplier, a Chinese education-technology manufacturer, and a US industrial technology conglomerate listed inside nine minutes points at a common upstream software exposure rather than three separately hunted targets. That is the signature of Clop's mass-exploitation playbook, and it means the relevant question for any organization running the same software is not "were we targeted" but "were we exposed during the window."

For Taiwan's technology supply chain specifically, a confirmed compromise at Largan would carry downstream consequences for the customers whose unreleased camera module specifications sit inside its engineering systems. Development of next year's lens modules is already under way, per Lin's July remarks, with customers typically starting product development one to two years in advance. Stolen roadmap data at that stage has a long shelf life.

The Attack Technique

No source connects the August 12 listings to a specific intrusion vector. The plausible link, and it is unconfirmed, is Clop's ongoing campaign against PTC's product lifecycle management stack.

PTC disclosed a critical remote code execution vulnerability in Windchill and its FlexPLM add-on on June 17, 2026, per Censys, proposing remediation steps the same day and shipping a patch on June 18, when it confirmed in-the-wild exploitation. Patches for additional versions followed. The flaw is tracked as CVE-2026-12569, and the sources characterize it two different ways: Help Net Security and BleepingComputer's own narration both call it an improper input validation vulnerability enabling unauthenticated remote code execution, while ReliaQuest's quoted statement inside the same BleepingComputer report calls it "a critical unsafe deserialization vulnerability (CVSS 9.3)." Those descriptions are not mutually exclusive, since unsafe deserialization is a form of improper input validation, but the discrepancy is worth noting for anyone matching the CVE against internal records.

CISA added CVE-2026-12569 to its Known Exploited Vulnerabilities catalog and set a June 28 remediation deadline for federal civilian agencies. PTC's advisory has been repeatedly updated with indicators of compromise, confirming that attackers are dropping JSP webshells on vulnerable systems. Help Net Security also relays Heise Online reporting that Germany's BSI began notifying German companies of "impending cyberattacks on vulnerable Windchill instances" around June 17, following an earlier BKA warning issued on the BSI's behalf in late March.

On the post-exploitation side, ReliaQuest observed JSP webshell deployment for remote command execution and product data exfiltration. ReliaQuest itself stopped short of attribution, stating that "the actor behind these attacks remains unconfirmed" while noting tradecraft consistent with prior Cl0p campaigns against enterprise applications and high-value data repositories. The Ransomware Information Sharing and Analysis Centre went further, confirming Clop's involvement to BleepingComputer on July 23. Ransom-ISAC's Brandon Parsons of Ascent Solutions described the extortion phase: messages sent from apparently compromised third-party email accounts to hundreds of users inside a victim organization, carrying Clop's current contact details, an approach Parsons said matches what was observed in the Oracle EBS campaign.

Roughly eight weeks separate the June 17 disclosure from the August 12 listings, which is consistent with Clop's historical pattern of exploiting in bulk first and monetizing victims in batches months later.

What Organizations Should Do

  1. Inventory every internet-reachable Windchill and FlexPLM instance, then patch. Apply PTC's June 18 fix or the subsequent version-specific patches. If an instance was exposed at any point between late March and the patch date, assume potential access and investigate rather than assume safety. As Deepstrike puts it, a current patch does not rule out access before remediation.
  2. Hunt for JSP webshells using PTC's published IOCs. PTC's advisory is being actively updated with indicators. Search web application directories for unexpected JSP files, review web server and application logs for anomalous POST activity, and check for outbound transfers from PLM servers to unfamiliar destinations.
  3. Cut the exposure. Put Windchill and FlexPLM behind a VPN, reverse proxy with access control, or IP allowlist. There is no good reason for a PLM platform holding design IP to answer requests from the open internet.
  4. Rotate credentials and audit integrations. Reset accounts tied to the PLM platform, including service accounts, and review the API keys, SSO trusts, and system-to-system connections that a webshell operator could have harvested from a compromised host.
  5. Preserve evidence before remediating. Snapshot disks, export logs, and capture memory where feasible. Rebuilding first destroys the record needed to scope the intrusion and to answer supplier and regulator questions later.
  6. Prepare for extortion contact that bypasses IT. Clop is emailing hundreds of employees from compromised third-party accounts. Brief staff to route any such message to security without replying, and have legal, communications, and executive escalation paths agreed in advance rather than improvised.
  7. Push the question upstream. If your product data sits inside a supplier's PLM environment, ask that supplier directly whether they ran an exposed Windchill or FlexPLM instance during the window. Third-party design data is exactly what this campaign is built to take.

Sources: Clop Expands Its Pressure Campaign, Adding Largan Precision and Hon... | Clop ransomware targets Windchill, FlexPLM in data theft attacks | JSP webshells being dropped on unpatched PTC Windchill instances -... | Clop Ransomware Claims Two New Victims: Ingersoll Rand and Honghe T... | Cl0p Ransomware: Attacks, Tactics & Defense | A Chill in the Air: Cl0p Targets Windchill, Another Enterprise Soft... | Clop Hits Windchill and FlexPLM as Zimbra Zero-Click Abuse and AI-S... | Largan lens yields to shape margins - Taipei Times