A Ransomware Gang’s Data Leak Site Hacked by Extortionists Using a Critical Flaw in Grav CMS
A shocking incident has unfolded in the world of cybercrime, as the Clop ransomware gang’s data leak site was breached and defaced by the ShinyHunters extortion gang. The attackers exploited an unpatched path traversal vulnerability in the Grav CMS platform to gain unauthorized access to the site, exposing sensitive information and disrupting operations.
The Clop leak site, which serves as a repository for stolen data from organizations that have fallen victim to the ransomware gang’s attacks, was targeted by ShinyHunters earlier this month. The extortionists claimed to have stolen source code, Grav CMS plugins, server logs, and private keys used by Clop’s Tor onion service. They then issued a ransom demand, threatening to leak the stolen files if Clop didn’t pay.
However, it appears that Clop has denied any relationship or ongoing negotiations with ShinyHunters, stating that they are not in contact with each other. This raises questions about the true intentions of the extortionists and whether they have indeed obtained sensitive information from the compromised server.
The vulnerability exploited by ShinyHunters is an unauthenticated path traversal flaw in Grav CMS, which allows attackers to create upload paths outside the intended directory structure. The attackers specifically targeted the __unique_form_id__ parameter, adding directory traversal sequences to it and causing Grav to create an upload path elsewhere under the installation.
Grav CMS has since confirmed that the vulnerability is real and accurate, tracking it as CVE-2026-42608. Although the flaw was privately reported and fixed in Grav 2.0 earlier this year, the fix had not been backported to older versions like Clop’s 1.7.43 deployment, leaving them vulnerable.
The incident serves as a stark reminder of the importance of maintaining up-to-date software installations and keeping plugins patched against known vulnerabilities. Organizations relying on CMS platforms like Grav should prioritize updating their systems immediately to prevent similar attacks in the future.
In light of this incident, it’s essential for users to take proactive steps to secure their online presence. This includes regularly updating software, using strong passwords, and implementing robust security measures to protect against data breaches and extortion attempts. By staying vigilant and informed about emerging threats, we can better safeguard our digital assets from the ever-evolving landscape of cybercrime.
Source: Bleeping Computer — 2026-09-25