ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

ShinyHunters’ audacious attack on Clop ransomware gang sparks cybersecurity controversy

In a shocking turn of events, the notorious ShinyHunters extortion group has hacked into the data leak site of the Clop (aka Cl0p) ransomware operation, defacing the Tor site and allegedly stealing server data and private keys for its onion service. This brazen move is the latest development in an ongoing feud between two cybercrime groups that has been brewing since last year.

According to ShinyHunters, the attack was a direct response to threats made by a Clop representative during the dispute. The group claims that Clop had threatened to identify its members and made violent threats after ShinyHunters disrupted one of Clop’s data theft campaigns. This escalating tension is believed to have originated from Clop’s 2025 Oracle E-Business Suite data theft campaign, which saw multiple vulnerabilities exploited to steal data from organizations in extortion campaigns.

ShinyHunters has admitted to gaining “full access” to the server and stealing source code, Grav CMS plugins, system logs, and other sensitive information. The group claims that it also obtained the private keys used by Clop’s Tor onion service, which would allow them to operate a Tor site using Clop’s existing onion address on servers they control.

The attack began when ShinyHunters exploited an unauthenticated file upload vulnerability in Grav CMS, uploading a small text file to Clop’s site. The message contained a link to the ShinyHunters’ own data leak site and a warning not to threaten them again. Several hours later, ShinyHunters claimed to have “completely defaced” the Clop site, replacing it with a page displaying ASCII art of Umbreon, the Pokémon used as their logo.

Cybersecurity researchers are closely watching this development, which highlights the increasingly complex dynamics between various cybercrime groups. As VXDB noted, the Umbreon artwork displayed on Clop’s leak site is identical to what was used in ShinyHunters’ August 2020 defacement of HackForums website. This suggests a pattern of retaliation and one-upmanship between these groups.

ShinyHunters has stated that it plans to publish a message on its own leak site instructing Clop to contact them within 72 hours, implying that the group is preparing for an extortion campaign against its rival. The implications of this move are far-reaching, as it could set a precedent for future interactions between cybercrime groups.

As cybersecurity professionals and organizations navigate these complex and ever-evolving threats, one takeaway stands out: the increasing willingness among cybercrime groups to engage in brazen attacks on each other’s infrastructure. This development underscores the need for vigilant monitoring of emerging trends and the importance of staying ahead of the curve in terms of threat detection and mitigation strategies.

In light of this incident, organizations would do well to prioritize robust security measures, including regular vulnerability assessments and patches, as well as thorough incident response planning. With cybercrime groups increasingly targeting each other’s infrastructure, it is essential for businesses and individuals to remain vigilant and proactive in protecting themselves against these evolving threats.


Source: Bleeping Computer — 2026-09-19