Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2922+ Articles
167+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. ShinyHunters Hacks Clop Leak Site, Threatens to Extort Ransomware Gang
ShinyHunters Hacks Clop Leak Site, Threatens to Extort Ransomware Gang
NEWS

ShinyHunters Hacks Clop Leak Site, Threatens to Extort Ransomware Gang

ShinyHunters defaced Clop's Tor leak site and claims to have stolen its onion service private keys, threatening to extort the ransomware gang.

Dylan H.

News Desk

September 19, 2026
5 min read

Overview

In an extraordinary case of cybercriminal-on-cybercriminal violence, the extortion gang ShinyHunters breached and defaced the Tor-based data leak site belonging to the Clop (also styled Cl0p) ransomware operation late Friday night. ShinyHunters says it also stole server data, including the private cryptographic keys for Clop's onion service, and is now threatening to extort the ransomware gang the same way Clop extorts its own victims.

BleepingComputer, which corresponded directly with ShinyHunters, independently confirmed the defacement and an initial file upload used in the attack, but has not independently verified ShinyHunters' broader claims about stolen source code, server logs, or the onion service private keys.

What Happened

According to BleepingComputer's reporting, the intrusion began when ShinyHunters exploited what they describe as an unauthenticated file upload vulnerability in Grav CMS, the content management system reportedly running Clop's leak site. The group used the flaw to upload a small taunting text file that read:

"THIS SITE HAS BEEN PWN3D BY SHINYHUNTERES #Skids10p - Maybe don't try to threaten us next time."

Hours later, ShinyHunters told BleepingComputer they had "completely defaced" the site, and a visit to the page confirmed it had been replaced with ASCII art of Umbreon, the Pokémon character ShinyHunters uses as its group logo. A researcher cited in coverage noted the same Umbreon artwork was used by ShinyHunters in its August 2020 defacement of the HackForums website — a signature the group appears to be reusing deliberately.

How Clop's infrastructure was actually configured, and whether the CMS flaw was the sole entry point, has not been independently confirmed — the account above comes from ShinyHunters' own description of the attack.

What Was Allegedly Stolen

ShinyHunters claims the breach yielded:

  • Source code and Grav CMS plugins running on Clop's leak site
  • System logs from /var/log, which could contain IP addresses and authentication records tied to whoever administers the site
  • Private cryptographic keys for Clop's Tor onion service

The onion keys are the most consequential claim: if genuine, they would let ShinyHunters host their own copy of the site at Clop's existing .onion address, effectively letting them impersonate or hijack Clop's presence on the dark web regardless of whether Clop tries to lock them out. ShinyHunters put it bluntly: "We have their onion keys. So if they kick us out it wouldn't matter at all because we control the private keys."

The Extortion Threat

ShinyHunters says it is reviewing the stolen data and, when asked what it planned to do next, replied simply: "Going to extort them." The group says it intends to post a message on its own leak site giving Clop 72 hours to make contact — mirroring the ultimatum-and-leak-site playbook that ransomware groups, including Clop itself, routinely use against corporate victims.

As of publication, Clop has not issued any public statement in response to the breach or the extortion demand.

Background: The Roots of the Feud

The conflict traces back to Clop's October 2025 Oracle E-Business Suite data-theft campaign, which exploited a zero-day vulnerability tracked as CVE-2025-61882. ShinyHunters alleges that Clop obtained an exploit that originally belonged to ShinyHunters without authorization. According to reporting on the dispute, tensions escalated when a Clop representative allegedly sent a threatening message, translated from Russian, to ShinyHunters members: "I have more money than you and all of your people combined, I'll kill you soon." ShinyHunters is framing this weekend's hack as retaliation for that threat.

ShinyHunters itself — tracked by Google as UNC6040 — has spent much of 2026 running a broad extortion campaign built on stolen Salesforce data, and has been preparing to launch its own dedicated leak site to pressure victim companies into paying. Clop, meanwhile, is one of the most prolific and financially successful ransomware brands in recent memory, having reportedly earned an estimated $75-100 million from its 2023 MOVEit Transfer mass-exploitation campaign alone.

Why This Matters

Extortion groups attacking each other's infrastructure is rare, but it is a useful signal for defenders and researchers for several reasons:

  • It shows even "professional" ransomware crews run vulnerable infrastructure. Clop's own leak site — the tool it uses to pressure victims into paying — was reportedly taken down by a garden-variety unauthenticated file upload bug in a CMS, the same class of flaw ransomware crews routinely exploit against their victims.
  • Stolen onion keys undercut operational trust. If ShinyHunters truly holds Clop's private keys, Clop's control over its own leak site — and therefore its ability to credibly threaten victims — is in question until it can stand up new infrastructure.
  • Inter-gang conflict can spill artifacts into public view. Feuds like this one sometimes leak internal tooling, victim data, or infrastructure details that researchers and law enforcement would not otherwise see.
  • It does not make either group less dangerous. ShinyHunters remains an active threat running its own extortion operations against real victims, and Clop's core ransomware business is not reported to be disrupted by this incident.

What We Don't Know Yet

Several key details remain unconfirmed pending further reporting:

  • Whether the Grav CMS vulnerability ShinyHunters describes has a public CVE identifier or was previously known
  • Whether the stolen onion service keys and server logs are genuine, or how ShinyHunters obtained them beyond the initial file upload
  • Whether Clop will respond publicly, attempt to migrate its leak site to a new address, or ignore the 72-hour ultimatum entirely
  • Whether any of the "stolen" data will actually be published, and if so, what it contains

CosmicBytez Labs will follow up if Clop responds or if further technical detail on the Grav CMS exploitation emerges.

#ShinyHunters#Clop#Ransomware#Cybercrime#Data Breach#Dark Web

Related Articles

Shell Investigates 'Potential Incident' After Clop Data Theft Claims

Oil giant Shell is investigating after Clop ransomware gang claimed to have stolen 89GB of data from the company.

3 min read

Clop Ransomware Targets PTC Windchill and FlexPLM in Mass Data Theft Campaign

The Clop ransomware gang is exploiting CVE-2026-12569, a critical unauthenticated RCE flaw (CVSS 9.8) in PTC Windchill and FlexPLM, deploying webshells to...

4 min read

Ransomware Gang Claims Nutex Health Data Breach

The Gentlemen ransomware gang claims it stole patient, employee, and financial data from hospital operator Nutex Health, threatening a leak.

3 min read
Back to all News