ShinyHunters hacks and defaces Cl0p - Will this shift the ransomware environment?
The ShinyHunters extortion group hacked and defaced the Clop (Cl0p) ransomware operation's data leak site by exploiting an unauthenticated file upload vulnerability in Grav CMS. They replaced the site content with their own messages and ASCII art, claiming to have stolen server data including source code, Grav CMS plugins, system logs, and private keys for Clop's Tor onion service. ShinyHunters threatened to extort Clop, demanding payment within 72 hours. This attack appears to be part of an ongoing feud between the two cybercrime groups, with ShinyHunters retaliating against threats made by Clop representatives. The incident raises questions about a potential shift in ransomware group dynamics toward direct attacks on rival groups. No independent verification of the full extent of data theft has been confirmed.
AI Analysis
Technical Summary
On September 19, 2026, the ShinyHunters group exploited an unauthenticated file upload vulnerability in the Grav CMS platform used by the Clop ransomware gang's data leak site. They uploaded a defacement message and subsequently replaced the site with their own content, including ASCII art and links to their own leak site. ShinyHunters claim to have gained full server access, stealing source code, plugins, system logs, and the private keys for Clop's Tor onion service, which would allow them to impersonate Clop's site. The attack is reportedly retaliation for threats made by Clop against ShinyHunters following disruptions to Clop's data theft campaigns, including a notable Oracle E-Business Suite exploitation campaign in 2025. ShinyHunters intend to extort Clop by demanding a large ransom. This event may indicate a trend toward more aggressive ransomware-on-ransomware attacks.
Potential Impact
The defacement and alleged data theft compromise the integrity and confidentiality of Clop's leak site infrastructure. If ShinyHunters' claims about stealing private keys are accurate, they could impersonate Clop's Tor site, potentially disrupting Clop's operations and reputation. The public feud and extortion demands between ransomware groups could lead to increased instability and unpredictability in the ransomware ecosystem. However, there is no evidence of direct impact on victim organizations or broader infrastructure beyond the ransomware groups themselves. Independent verification of the full scope of data theft is pending.
Mitigation Recommendations
No official patch or remediation applies as this is an attack between threat actor groups targeting each other's infrastructure. Defenders should monitor for potential fallout from this feud, but no direct mitigation steps are indicated for external organizations. The vendor advisory or authoritative source does not specify any required action. This incident highlights the importance of securing leak sites and associated infrastructure against unauthorized access and file upload vulnerabilities.
ShinyHunters hacks and defaces Cl0p - Will this shift the ransomware environment?
Description
The ShinyHunters extortion group hacked and defaced the Clop (Cl0p) ransomware operation's data leak site by exploiting an unauthenticated file upload vulnerability in Grav CMS. They replaced the site content with their own messages and ASCII art, claiming to have stolen server data including source code, Grav CMS plugins, system logs, and private keys for Clop's Tor onion service. ShinyHunters threatened to extort Clop, demanding payment within 72 hours. This attack appears to be part of an ongoing feud between the two cybercrime groups, with ShinyHunters retaliating against threats made by Clop representatives. The incident raises questions about a potential shift in ransomware group dynamics toward direct attacks on rival groups. No independent verification of the full extent of data theft has been confirmed.
Reddit Discussion
On Sept 19th the ransomware group ShinyHunters managed to hack into and deface the TOR leak site of Cl0p ransomware. After the initial defacement ShinyHunters has posted a number of messages for Cl0p to negotiate and pay them a sum of 8 figures. In the articles I have read it is said that this was happening due to a feud due to threats made by Cl0p against Shiny Hunters. It has been interesting watching this all develop.
In March of 2025 I also watched as the news that Dragonforce defaced the leak site of Mamona(Prev Blacklock) came out and everything saying it was also tied to a feud with Blacklock code being an almost exact match for Dragonforce.
Which has me curious, as even though this is not the first time we have seen this style of defacement, it is still very uncommon. Everything I have seen the groups tend to stay separate and keep things offline. My question is, are we seeing a shift in the environment from that to straight up attacks from groups, and will ShinyHunters success in this set precedent for other groups to take a more aggressive approach to solving feuds between groups?
I ask as i have seen precedent adjust the ransomware environment a lot. Ransomware as whole used to not touch hospitals, then one started hitting hospitals and then almost all were. The ransomware affiliate payment used to be not as good, then the 80/20 model started and most groups adopt that. So wanting to get peoples opinions on if you think we will see more of these ransomware on ransomware attacks in the future, or if these are one off outliers.
Source:
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
On September 19, 2026, the ShinyHunters group exploited an unauthenticated file upload vulnerability in the Grav CMS platform used by the Clop ransomware gang's data leak site. They uploaded a defacement message and subsequently replaced the site with their own content, including ASCII art and links to their own leak site. ShinyHunters claim to have gained full server access, stealing source code, plugins, system logs, and the private keys for Clop's Tor onion service, which would allow them to impersonate Clop's site. The attack is reportedly retaliation for threats made by Clop against ShinyHunters following disruptions to Clop's data theft campaigns, including a notable Oracle E-Business Suite exploitation campaign in 2025. ShinyHunters intend to extort Clop by demanding a large ransom. This event may indicate a trend toward more aggressive ransomware-on-ransomware attacks.
Potential Impact
The defacement and alleged data theft compromise the integrity and confidentiality of Clop's leak site infrastructure. If ShinyHunters' claims about stealing private keys are accurate, they could impersonate Clop's Tor site, potentially disrupting Clop's operations and reputation. The public feud and extortion demands between ransomware groups could lead to increased instability and unpredictability in the ransomware ecosystem. However, there is no evidence of direct impact on victim organizations or broader infrastructure beyond the ransomware groups themselves. Independent verification of the full scope of data theft is pending.
Defensive Guidance
No official patch or remediation applies as this is an attack between threat actor groups targeting each other's infrastructure. Defenders should monitor for potential fallout from this feud, but no direct mitigation steps are indicated for external organizations. The vendor advisory or authoritative source does not specify any required action. This incident highlights the importance of securing leak sites and associated infrastructure against unauthorized access and file upload vulnerabilities.
Technical Details
- Source Type
- Subreddit
- cybersecurity
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Newsworthiness Assessment
- {"score":30,"reasons":["external_link","newsworthy_keywords:ransomware","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":["ransomware"]}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6ab162e955bf5e2cf5335bf6
Added to database: 09/21/2026, 17:01:29 UTC
Last enriched: 09/21/2026, 17:01:38 UTC
Last updated: 09/21/2026, 19:31:23 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.