LmCast :: Stay tuned in

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

Recorded: Sept. 19, 2026, 2 p.m.

Original Summarized

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

News

Featured
Latest

OpenAI details more cases of AI agents taking unauthorized actions

Brevo supply-chain attack injected ClickFix scripts on customer sites

Cisco warns of max severity ISE zero-day exploited in attacks

Microsoft shares workaround for Windows domain login issues

North Korean WaterPlum hackers infected 30,000 devices worldwide

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

Get 25 hours of ChatGPT & AI training for just $19.99

Calling viral AI actress Tilly Norwood? Agree to a face scan first

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityShinyHunters hacks Clop leak site, threatens to extort ransomware gang

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

By Lawrence Abrams

September 19, 2026
09:48 AM
0

The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation's data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service.
The attack began Friday night when ShinyHunters exploited what they claim is an unauthenticated file upload vulnerability in Grav CMS, which they used to upload a small text file to Clop's site.

File downloaded from Clop's data leak siteSource: BleepingComputer
The small text file contained a message from the threat actors to the Clop ransomware gang, warning not to threaten them and including a link to ShinyHunter's own data leak site.
"THIS SITE HAS BEEN PWN3D BY SHINYHUNTERES #Skids10p - Maybe don't try to threaten us next time," read the uploaded file.

File uploaded to Clop's data leak siteSource: BleepingComputer
The file also contained a link to the ShinyHunters data leak site.
BleepingComputer confirmed that the file had been uploaded to Clop's server and could be downloaded directly from the ransomware gang's Tor site.
Several hours later, ShinyHunters told BleepingComputer that they had "completely defaced" the Clop site.
Visiting the site confirmed it had been replaced with a page displaying ASCII art of Umbreon, the Pokémon used as ShinyHunters' logo. The defacement also included a link to the group's Tor site and the message, "rooting your systems since '19 ;)".

Clop's data leak site defaced by ShinyHuntersSource: BleepingComputer
At the time of this writing, the defaced page is still being served from Clop's infrastructure, according to ShinyHunters.
ShinyHunters claims data theft
ShinyHunters told BleepingComputer it gained "full access" to the server and stole source code, Grav CMS plugins, system logs, and other data.
"The data we stole includes source codes, gravCMS plugins, and other things. We are still downloading and reviewing them," ShinyHunters told BleepingComputer.
The threat actors also claim to have stolen all files stored under /var/log, which could contain system activity, authentication logs, and potentially, the IP addresses of those who connected to it.
ShinyHunters also claims to have obtained the private keys used by Clop's Tor onion service.
"We have their onion keys. So if they kick us out it wouldn't matter at all because we control the private keys to host the same exact onion URL," the threat actor claimed.
If the keys are valid, it would allow the threat actors to operate a Tor site using Clop's existing onion address on servers they control.
BleepingComputer has independently confirmed the defacement and earlier uploaded file but has not independently verified ShinyHunters' claims that it stole server logs, source code, or Clop's onion private keys.
ShinyHunters says it is now reviewing the allegedly stolen data.
When asked what they planned to do with the stolen information, the threat actor responded, "Going to extort them."
The group says it plans to publish a message on its own leak site instructing Clop to contact them within 72 hours.
Cybersecurity researcher VXDB told BleepingComputer the Umbreon artwork now displayed on Clop's leak site is the same as what was used in the August 2020 defacement of the HackForums website, which ShinyHunters also claimed at the time.
Feud between cybercrime groups
ShinyHunters says the attack is retaliation for threats allegedly made by a Clop representative during an ongoing feud between the cybercrime groups.
According to ShinyHunters, a Clop representative threatened to identify group members and made violent threats after ShinyHunters disrupted a Clop data theft campaign.
ShinyHunters says the dispute dates back to Clop's 2025 Oracle E-Business Suite data theft campaign.
In October 2025, Clop exploited multiple vulnerabilities in Oracle E-Business Suite servers, including a zero-day flaw tracked as CVE-2025-61882, to steal data from organizations in extortion campaigns.
Around the same time, threat actors calling themselves "Scattered Lapsus$ Hunters," including ShinyHunters, leaked a proof-of-concept exploit that Oracle later confirmed matched an exploit used in the Clop attacks.
At the time, ShinyHunters told BleepingComputer the exploit had originally belonged to them and that Clop obtained it without authorization.
ShinyHunters claims that tensions escalated after the Oracle campaign, with a Clop representative allegedly threatening members of the group.
"During the Oracle EBS campaign they ran and stole from me last year, someone from cl0p personally messaged me and said, and I quote (translated from Russian): I have more money than you and all of your people combined, I'll kill you soon," ShinyHunters told BleepingComputer.
BleepingComputer has not independently verified these allegations and has contacted Clop about the breach and the allegations made by ShinyHunters and will update the story if we receive a response.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seat

Related Articles:
Passkey-themed phishing attacks lead to Microsoft 365 data theftShinyHunters hackers claim breach of Florida "DAVID" DMV databaseNovocure data breach affects more than 1,400 cancer patientsClop created custom web shell for Windchill data theft attacksErnst & Young data breach claimed by ShinyHunters extortion gang

Clop
Data Leak Site
Data Theft
Exploit
Extortion
Gravity CMS
Ransomware
ShinyHunters

Lawrence Abrams
Lawrence Abrams is the owner and Editor in Chief of BleepingComputer.com. Lawrence's area of expertise includes Windows, malware removal, and computer forensics. Lawrence Abrams is a co-author of the Winternals Defragmentation, Recovery, and Administration Field Guide and the technical editor for Rootkits for Dummies.

Previous Article
Next Article

Post a Comment Community Rules

You need to login in order to post a comment
Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

Windows 11 KB5124008 update breaks domain trust for some users

Cisco warns of max severity ISE zero-day exploited in attacks

Microsoft shares workaround for Windows domain login issues

Sponsor Posts

Find out how long recovery really takes — and what it costs. Read the 2025 BCDR Report.

Patch automation needs more than speed. Action1 brings control into every stage of deployment.

Overdue a password health-check? Audit your Active Directory for free

Automate Onboarding and Access Reviews with No-Code IGA: See how it works

Watch a working exploit hit live controls and see exactly what blocks, detects, or misses

  Upcoming Webinar

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

The ShinyHunters extortion gang executed a breach of the Clop ransomware operation's data leak site, defacing it and allegedly stealing sensitive server data and private keys associated with the Clop onion service. The incident commenced when ShinyHunters exploited what they claimed was an unauthenticated file upload vulnerability within the Grav CMS to upload a text file to Clop's website. This file served as a warning to the Clop ransomware gang, instructing them not to pursue extortion and providing a link to ShinyHunters' own data leak site. Following this upload, ShinyHunters asserted that they had completely defaced the site, replacing the content with an image displaying ASCII art of the Pokémon Umbreon, which also included a message referencing the group's history.

ShinyHunters further claimed that they gained full access to the server, alleging the theft of source codes, Grav CMS plugins, system logs, and other data. Furthermore, the threat actors claimed to have obtained the private keys necessary to operate Clop's Tor onion service, asserting that they could host the same onion URL on their own infrastructure. ShinyHunters stated their intent was to extort the ransomware group, planning to publish a message demanding contact from Clop within seventy-two hours. While BleepingComputer independently confirmed the defacement and the initial uploaded file, they have not independently verified the extensive claims made by ShinyHunters regarding the theft of server logs, source code, or the private keys themselves, information which ShinyHunters stated they are currently reviewing.

The conflict between the groups is framed as retaliation arising from an ongoing feud over cybercrime activities, specifically related to Clop's prior data theft campaigns. ShinyHunters alleged that a Clop representative made explicit violent threats against group members following ShinyHunters' disruption of a data theft operation. This dispute reportedly stems from Clop's 2025 Oracle E-Business Suite data theft campaign, which involved exploiting vulnerabilities such as the zero-day flaw tracked as CVE-2025-61882. ShinyHunters contended that they possessed a proof-of-concept exploit related to the Oracle attacks, which they claimed Clop obtained without authorization. The escalation of tensions is attributed to direct threats made by a Clop representative during this period. Although BleepingComputer has contacted Clop regarding these allegations, they have yet to receive an official response.