ShinyHunters hacks Clop leak site, threatens to extort ransomware gang
The ShinyHunters extortion group breached the Clop ransomware gang's data leak site by exploiting an unauthenticated file upload vulnerability in Grav CMS. They defaced the Tor site, uploaded a taunting message, and claim to have stolen server data including source code, Grav CMS plugins, system logs, and the private keys for Clop's Tor onion service. The stolen private keys could allow ShinyHunters to impersonate Clop's onion site. ShinyHunters intends to extort Clop using the stolen data. This attack appears to be part of an ongoing feud between the two cybercrime groups dating back to 2025.
AI Analysis
Technical Summary
ShinyHunters exploited an unauthenticated file upload vulnerability in the Grav CMS powering Clop ransomware's data leak site to gain full server access. They uploaded a text file with a message to Clop, defaced the Tor site with their logo, and claim to have stolen source code, Grav CMS plugins, system logs, and the private keys for Clop's Tor onion service. Possession of the onion private keys would allow ShinyHunters to host a site at Clop's onion address, undermining Clop's control of their leak site. ShinyHunters plans to extort Clop with the stolen data. The attack is reportedly retaliation for threats made by Clop representatives during a feud between the groups, which began after Clop exploited Oracle E-Business Suite vulnerabilities in 2025. Independent verification of the data theft claims beyond the defacement and file upload is pending.
Potential Impact
If ShinyHunters' claims are accurate, they have compromised Clop's leak site infrastructure, potentially exposing sensitive source code, system logs, and private keys. This undermines Clop's operational security and ability to control their Tor onion service, allowing ShinyHunters to impersonate Clop's site. The breach may disrupt Clop's ransomware extortion campaigns and damage their reputation. Additionally, stolen system logs could reveal information about Clop's operations and contacts. The incident highlights risks of vulnerabilities in third-party CMS software used by threat actors.
Mitigation Recommendations
No official patch or remediation is applicable to this incident as it involves a compromise of a criminal group's infrastructure. The vulnerability exploited was an unauthenticated file upload in Grav CMS, which should be patched or mitigated by legitimate users of the software. Organizations using Grav CMS should ensure they apply security updates and harden file upload mechanisms. For defenders, monitoring for similar exploitation attempts and securing CMS instances against unauthenticated uploads is recommended. Since this is a conflict between threat actors, no direct mitigation for defenders is available beyond general CMS security best practices.
ShinyHunters hacks Clop leak site, threatens to extort ransomware gang
Description
The ShinyHunters extortion group breached the Clop ransomware gang's data leak site by exploiting an unauthenticated file upload vulnerability in Grav CMS. They defaced the Tor site, uploaded a taunting message, and claim to have stolen server data including source code, Grav CMS plugins, system logs, and the private keys for Clop's Tor onion service. The stolen private keys could allow ShinyHunters to impersonate Clop's onion site. ShinyHunters intends to extort Clop using the stolen data. This attack appears to be part of an ongoing feud between the two cybercrime groups dating back to 2025.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
ShinyHunters exploited an unauthenticated file upload vulnerability in the Grav CMS powering Clop ransomware's data leak site to gain full server access. They uploaded a text file with a message to Clop, defaced the Tor site with their logo, and claim to have stolen source code, Grav CMS plugins, system logs, and the private keys for Clop's Tor onion service. Possession of the onion private keys would allow ShinyHunters to host a site at Clop's onion address, undermining Clop's control of their leak site. ShinyHunters plans to extort Clop with the stolen data. The attack is reportedly retaliation for threats made by Clop representatives during a feud between the groups, which began after Clop exploited Oracle E-Business Suite vulnerabilities in 2025. Independent verification of the data theft claims beyond the defacement and file upload is pending.
Potential Impact
If ShinyHunters' claims are accurate, they have compromised Clop's leak site infrastructure, potentially exposing sensitive source code, system logs, and private keys. This undermines Clop's operational security and ability to control their Tor onion service, allowing ShinyHunters to impersonate Clop's site. The breach may disrupt Clop's ransomware extortion campaigns and damage their reputation. Additionally, stolen system logs could reveal information about Clop's operations and contacts. The incident highlights risks of vulnerabilities in third-party CMS software used by threat actors.
Defensive Guidance
No official patch or remediation is applicable to this incident as it involves a compromise of a criminal group's infrastructure. The vulnerability exploited was an unauthenticated file upload in Grav CMS, which should be patched or mitigated by legitimate users of the software. Organizations using Grav CMS should ensure they apply security updates and harden file upload mechanisms. For defenders, monitoring for similar exploitation attempts and securing CMS instances against unauthenticated uploads is recommended. Since this is a conflict between threat actors, no direct mitigation for defenders is available beyond general CMS security best practices.
Technical Details
- Classification
- {"confidence":0.73,"severitySource":"heuristic","classifier":"rss-v2"}
Threat ID: 6aae95cb55bf5e2cf59e7824
Added to database: 09/19/2026, 14:01:47 UTC
Last enriched: 09/19/2026, 14:01:53 UTC
Last updated: 09/20/2026, 03:52:27 UTC
Views: 20
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.