ShinyHunters Claims It Hacked and Defaced Clop Ransomware’s Tor Leak Site
The ShinyHunters extortion group allegedly infiltrated the Clop (also known as Cl0p) ransomware operation’s data leak site, defaced its Tor website, and stole server data and private keys for its onion service.
The attack began Friday night when ShinyHunters exploited an unauthenticated file-upload vulnerability in Grav CMS. The group used the vulnerability to upload small text files to Clop’s site.

Source: BleepingComputer
The uploaded file contained a message aimed at the Clop ransomware gang, warning its members not to make threats and linking to the ShinyHunters data leak site.
“This site has been PWN3D by SHINYHUNTERES #Skids10p – please don’t blackmail us next time,” the message read.

Source: BleepingComputer
BleepingComputer confirmed that the files were uploaded to Clop’s servers and could be downloaded directly from the ransomware group’s Tor site.
Hours later, ShinyHunters told BleepingComputer that it had “completely defaced” Clop’s site.
When accessed, the site displayed ASCII art of Umbreon, the Pokémon character used as the ShinyHunters logo. The defaced page also included a link to the group’s Tor site and the message, “We’ve been rooting systems since ’19 ;).”

Source: BleepingComputer
According to ShinyHunters, the defaced pages continued to be served from Clop’s infrastructure at the time of reporting.
ShinyHunters claims it stole Clop’s server data
ShinyHunters told BleepingComputer that it gained “full access” to the server and stole source code, Grav CMS plugins, system logs, and other data.
“The data we stole includes source code, gravCMS plugins, etc. We are still downloading and reviewing them,” the threat actor said.
The group also claimed to have stolen all files stored in /var/log. These files may include system activity, authentication logs, and IP addresses belonging to connected users.
ShinyHunters further claimed that it obtained the private keys used by Clop’s Tor onion service.
“We have their Onion keys, so if they kick us out, that’s no problem at all, because we control the private keys to host the exact same Onion URLs,” the threat actor claimed.
If valid, the keys could allow attackers to operate Clop’s existing onion addresses from attacker-controlled servers.
BleepingComputer independently verified the defacement and the previously uploaded files. However, it has not independently verified the server logs, source code, or ShinyHunters’ claim that it stole Clop’s onion private key.
ShinyHunters said it was investigating the allegedly stolen data.
When asked what it planned to do with the information, the attacker replied, “I’m going to blackmail the information.”
The group said it would publish a message on its own leak site instructing Clop to contact it within 72 hours.
Cybersecurity researcher VXDB told BleepingComputer that the Umbreon artwork appearing on Clop’s leak site was used in an August 2020 defacement that ShinyHunters also claimed at the time.
ShinyHunters says Clop attack was retaliation
ShinyHunters said the attack was retaliation for threats allegedly made by Clop representatives during an ongoing dispute between the cybercrime groups.
According to ShinyHunters, Clop representatives threatened to identify members of the group and issued violent threats after ShinyHunters disrupted one of Clop’s data-theft campaigns.
The dispute allegedly dates back to Clop’s 2025 Oracle E-Business Suite data-theft campaign.
In October 2025, Clop exploited multiple vulnerabilities in Oracle E-Business Suite servers, including the zero-day vulnerability CVE-2025-61882, to steal data from organizations as part of extortion campaigns.
Around the same time, attackers calling themselves “Scattered Lapsus$ Hunters,” including ShinyHunters, leaked a proof-of-concept exploit. Oracle later confirmed that it matched the exploit used in the Clop campaign.
ShinyHunters told BleepingComputer that the exploit originally belonged to the group and that Clop had obtained it without permission.
ShinyHunters claims that tensions escalated after the Oracle campaign, with Clop representatives threatening members of the group.
“Last year, during the Oracle EBS campaign that they ran and stole from me, someone from cl0p privately messaged me and said, quote (translated from Russian), ‘I have more money than you and all your buddies combined. I’ll kill you right now,’” ShinyHunters told BleepingComputer.
BleepingComputer has not independently verified these claims. The publication contacted Clop about the alleged compromise and ShinyHunters’ accusations and will update the article if it receives a response.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



