Skip to main content

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

0
High
Threat Actorransomware
Published: 09/19/2026 (09/19/2026, 13:48:32 UTC)
Source: Bleeping Computer

Description

The ShinyHunters extortion group breached the Clop ransomware gang's data leak site by exploiting an unauthenticated file upload vulnerability in Grav CMS. They defaced the Tor site, uploaded a taunting message, and claim to have stolen server data including source code, Grav CMS plugins, system logs, and the private keys for Clop's Tor onion service. The stolen private keys could allow ShinyHunters to impersonate Clop's onion site. ShinyHunters intends to extort Clop using the stolen data. This attack appears to be part of an ongoing feud between the two cybercrime groups dating back to 2025.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/19/2026, 14:01:53 UTC

Technical Analysis

ShinyHunters exploited an unauthenticated file upload vulnerability in the Grav CMS powering Clop ransomware's data leak site to gain full server access. They uploaded a text file with a message to Clop, defaced the Tor site with their logo, and claim to have stolen source code, Grav CMS plugins, system logs, and the private keys for Clop's Tor onion service. Possession of the onion private keys would allow ShinyHunters to host a site at Clop's onion address, undermining Clop's control of their leak site. ShinyHunters plans to extort Clop with the stolen data. The attack is reportedly retaliation for threats made by Clop representatives during a feud between the groups, which began after Clop exploited Oracle E-Business Suite vulnerabilities in 2025. Independent verification of the data theft claims beyond the defacement and file upload is pending.

Potential Impact

If ShinyHunters' claims are accurate, they have compromised Clop's leak site infrastructure, potentially exposing sensitive source code, system logs, and private keys. This undermines Clop's operational security and ability to control their Tor onion service, allowing ShinyHunters to impersonate Clop's site. The breach may disrupt Clop's ransomware extortion campaigns and damage their reputation. Additionally, stolen system logs could reveal information about Clop's operations and contacts. The incident highlights risks of vulnerabilities in third-party CMS software used by threat actors.

Defensive Guidance

No official patch or remediation is applicable to this incident as it involves a compromise of a criminal group's infrastructure. The vulnerability exploited was an unauthenticated file upload in Grav CMS, which should be patched or mitigated by legitimate users of the software. Organizations using Grav CMS should ensure they apply security updates and harden file upload mechanisms. For defenders, monitoring for similar exploitation attempts and securing CMS instances against unauthenticated uploads is recommended. Since this is a conflict between threat actors, no direct mitigation for defenders is available beyond general CMS security best practices.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.73,"severitySource":"heuristic","classifier":"rss-v2"}

Threat ID: 6aae95cb55bf5e2cf59e7824

Added to database: 09/19/2026, 14:01:47 UTC

Last enriched: 09/19/2026, 14:01:53 UTC

Last updated: 09/20/2026, 03:52:27 UTC

Views: 20

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses