ShinyHunters hacks Clop leak site, threatens to extort ransomware gang
Recorded: Sept. 19, 2026, 2 p.m.
| Original | Summarized |
ShinyHunters hacks Clop leak site, threatens to extort ransomware gang News Featured OpenAI details more cases of AI agents taking unauthorized actions Brevo supply-chain attack injected ClickFix scripts on customer sites Cisco warns of max severity ISE zero-day exploited in attacks Microsoft shares workaround for Windows domain login issues North Korean WaterPlum hackers infected 30,000 devices worldwide ShinyHunters hacks Clop leak site, threatens to extort ransomware gang Get 25 hours of ChatGPT & AI training for just $19.99 Calling viral AI actress Tilly Norwood? Agree to a face scan first Tutorials Latest How to access the Dark Web using the Tor Browser How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to use the Windows Registry Editor How to backup and restore the Windows Registry How to start Windows in Safe Mode How to remove a Trojan, Virus, Worm, or other Malware How to show hidden files in Windows 7 How to see hidden files in Windows Webinars Latest Qualys BrowserCheck STOPDecrypter AuroraDecrypter FilesLockerDecrypter AdwCleaner ComboFix RKill Junkware Removal Tool Deals Categories eLearning IT Certification Courses Gear + Gadgets Security VPNs Popular Best VPNs How to change IP address Access the dark web safely Best VPN for YouTube Forums Virus Removal Guides HomeNewsSecurityShinyHunters hacks Clop leak site, threatens to extort ransomware gang ShinyHunters hacks Clop leak site, threatens to extort ransomware gang By Lawrence Abrams September 19, 2026 The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation's data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service. File downloaded from Clop's data leak siteSource: BleepingComputer File uploaded to Clop's data leak siteSource: BleepingComputer Clop's data leak site defaced by ShinyHuntersSource: BleepingComputer Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Related Articles: Clop Lawrence Abrams Previous Article Post a Comment Community Rules You need to login in order to post a comment You may also like: Upcoming Webinar Popular Stories Windows 11 KB5124008 update breaks domain trust for some users Cisco warns of max severity ISE zero-day exploited in attacks Microsoft shares workaround for Windows domain login issues Sponsor Posts Find out how long recovery really takes — and what it costs. Read the 2025 BCDR Report. Patch automation needs more than speed. Action1 brings control into every stage of deployment. Overdue a password health-check? Audit your Active Directory for free Automate Onboarding and Access Reviews with No-Code IGA: See how it works Watch a working exploit hit live controls and see exactly what blocks, detects, or misses Upcoming Webinar Follow us: Main Sections News Community Forums Useful Resources Welcome Guide Company About BleepingComputer Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved Login Username Password Remember Me Sign in anonymously Sign in with Twitter Not a member yet? Register Now Help us understand the problem. What is going on with this comment? Spam Abusive or Harmful Inappropriate content Strong language Other Read our posting guidelinese to learn what content is prohibited. Submitting... |
The ShinyHunters extortion gang executed a breach of the Clop ransomware operation's data leak site, defacing it and allegedly stealing sensitive server data and private keys associated with the Clop onion service. The incident commenced when ShinyHunters exploited what they claimed was an unauthenticated file upload vulnerability within the Grav CMS to upload a text file to Clop's website. This file served as a warning to the Clop ransomware gang, instructing them not to pursue extortion and providing a link to ShinyHunters' own data leak site. Following this upload, ShinyHunters asserted that they had completely defaced the site, replacing the content with an image displaying ASCII art of the Pokémon Umbreon, which also included a message referencing the group's history. ShinyHunters further claimed that they gained full access to the server, alleging the theft of source codes, Grav CMS plugins, system logs, and other data. Furthermore, the threat actors claimed to have obtained the private keys necessary to operate Clop's Tor onion service, asserting that they could host the same onion URL on their own infrastructure. ShinyHunters stated their intent was to extort the ransomware group, planning to publish a message demanding contact from Clop within seventy-two hours. While BleepingComputer independently confirmed the defacement and the initial uploaded file, they have not independently verified the extensive claims made by ShinyHunters regarding the theft of server logs, source code, or the private keys themselves, information which ShinyHunters stated they are currently reviewing. The conflict between the groups is framed as retaliation arising from an ongoing feud over cybercrime activities, specifically related to Clop's prior data theft campaigns. ShinyHunters alleged that a Clop representative made explicit violent threats against group members following ShinyHunters' disruption of a data theft operation. This dispute reportedly stems from Clop's 2025 Oracle E-Business Suite data theft campaign, which involved exploiting vulnerabilities such as the zero-day flaw tracked as CVE-2025-61882. ShinyHunters contended that they possessed a proof-of-concept exploit related to the Oracle attacks, which they claimed Clop obtained without authorization. The escalation of tensions is attributed to direct threats made by a Clop representative during this period. Although BleepingComputer has contacted Clop regarding these allegations, they have yet to receive an official response. |