The extortion group ShinyHunters hacked a leak site operated by the Clop ransomware operation, also known as Cl0p, and replaced its content with a threatening message and links to its own site. BleepingComputer confirmed the file uploaded by the group and the defacement, but did not independently verify the theft of server logs, source code, or the site’s Tor service keys.
The attack began Friday evening, when ShinyHunters exploited what it described as a vulnerability in the Grav CMS that allows a file to be uploaded without authentication. The small text file contained a message addressed to Clop, including a warning about the group’s threat and a link to the ShinyHunters data-leak site.
Site defacement and alleged control
Hours later, ShinyHunters said it had taken full control of and defaced Clop’s site. The site later displayed ASCII art of Umbreon, used as a logo by ShinyHunters, alongside a link to the group’s site and a message saying that it had been entrenched in the systems since 2019. BleepingComputer confirmed that the defaced page was being served from infrastructure belonging to Clop.
ShinyHunters claims it stole the source code, Grav CMS plugins, system logs, and other files, including files located in /var/log, which may contain data about system activity, authentication operations, and the IP addresses of connections. It also claims to have obtained the private keys used to operate the Tor onion service. If this point is true, it could allow the group to host a copy of the site using the same onion address on servers it controls.
From hacking to extortion
ShinyHunters turned the incident into a public extortion attempt, adding daily updates to its site and threatening to publish the data it says it stole if Clop did not respond to its demands. The demand began at an eight-figure amount, accompanied by a threat to increase it every 24 hours, and a demand for a public apology was later added.
The group also threatened to expose information about companies allegedly paid by Clop during an extortion campaign linked to Oracle E-Business Suite servers, including payment amounts and the Bitcoin addresses associated with them. On September 21, Clop posted a short message on its site, which had been hacked, asking ShinyHunters to communicate through an old platform, but the group rejected this and continued to demand payment.
A previous dispute between two cybercrime groups
ShinyHunters says the attack came in response to threats attributed to a Clop representative during a dispute that began after a data-theft campaign targeting Oracle E-Business Suite in 2025. During that campaign, Clop exploited several vulnerabilities, including the CVE-2025-61882 zero-day, while groups calling themselves Scattered Lapsus$ Hunters, which includes ShinyHunters, leaked a proof-of-concept exploit that Oracle later said matched the exploit used in Clop attacks.
ShinyHunters says the exploit originally belonged to it and that Clop obtained it without permission. The group also cited claims of violent threats against its members, allegations that BleepingComputer has not independently verified.
Why does this matter?
The incident shows that ransomware gangs’ leak sites are not merely propaganda pages, but operational infrastructure that may contain logs, access keys, and data revealing visitors’ communications or enabling the site to be impersonated. At the same time, the distinction between confirmed facts and unsubstantiated claims remains important here: what is confirmed is the file upload and the site defacement, while the extent of access and the theft of keys and data still rely on ShinyHunters’ account. Therefore, the source alone does not establish whether the group can actually retain the Tor address or publish the alleged data.