ShinyHunters Extortion Gang Takes Down Clop Ransomware Operation’s Data Leak Site
In a brazen move, the ShinyHunters extortion gang has breached the Clop (aka Cl0p) ransomware operation’s data leak site, defacing the Tor site and allegedly stealing sensitive information. The attack is part of an ongoing feud between the two cybercrime groups, with ShinyHunters claiming that they were retaliating against threats made by a Clop representative.
According to sources close to the investigation, ShinyHunters exploited an unauthenticated file upload vulnerability in Grav CMS, a content management system used by Clop’s site. The attackers uploaded a small text file containing a message warning Clop not to threaten them again and including a link to ShinyHunters’ own data leak site. This initial attack set the stage for the full-scale defacement that followed hours later.
By exploiting this vulnerability, ShinyHunters gained access to the server hosting Clop’s Tor onion service, which allows users to browse the internet anonymously. The attackers claim to have stolen source code, Grav CMS plugins, system logs, and other sensitive information from the server. Furthermore, they allegedly obtained the private keys used by Clop’s Tor onion service, which could enable them to operate a Tor site using Clop’s existing onion address on servers they control.
The defacement of Clop’s site is a stark reminder of the ongoing cat-and-mouse game between cybercrime groups. ShinyHunters’ message to Clop was clear: “This site has been PWN3D by ShinyHunteres #Skids10p – Maybe don’t try to threaten us next time.” The use of ASCII art featuring Umbreon, a Pokémon used as ShinyHunters’ logo, adds a touch of humor to the otherwise menacing message.
The feud between ShinyHunters and Clop dates back to 2025, when Clop exploited multiple vulnerabilities in Oracle E-Business Suite servers to steal data from organizations. Around the same time, threat actors calling themselves “Scattered Lapsus$ Hunters,” including ShinyHunters, leaked a proof-of-concept exploit that matched one used by Clop. ShinyHunters claimed that the exploit had originally belonged to them and was obtained without authorization by Clop.
The attack highlights the complexities of cybercrime operations and the ongoing power struggles within the dark web. As ShinyHunters prepares to extort Clop, it’s clear that the stakes are high for both parties involved.
In practical terms, this incident serves as a reminder of the importance of maintaining robust security measures, including regular updates and patching of content management systems like Grav CMS. Additionally, organizations should be aware of the risks associated with data leaks and ransomware attacks, and have strategies in place to mitigate these threats. As the cybercrime landscape continues to evolve, it’s essential for businesses and individuals to stay vigilant and adapt to the changing threat landscape.
Source: Bleeping Computer — 2026-09-19