NEWS

ShinyHunters Hacked Clop's Leak Site Using a Grav CMS Path Traversal Flaw

ShinyHunters defaced Clop's Tor leak site via an unauthenticated Grav CMS flaw, claims stolen data and onion keys, and is extorting the gang for eight figures.

Dylan H.

News Desk

September 25, 2026
9 min read
ShinyHunters Hacked Clop's Leak Site Using a Grav CMS Path Traversal Flaw

ShinyHunters Hijacks Clop's Dark Web Leak Site Through an Unpatched Grav CMS Flaw

The extortion group ShinyHunters compromised and defaced the Tor-based data leak site belonging to rival ransomware operation Clop (also styled Cl0p), exploiting an unauthenticated vulnerability in Grav CMS — the content management system quietly running Clop's dark web infrastructure. The intrusion began the night of September 18, 2026, and was confirmed by BleepingComputer on September 19. ShinyHunters says it gained full server access, stole source code, server logs, and the private cryptographic keys tied to Clop's onion service, and is now demanding an eight-figure payment from Clop itself under a 72-hour deadline. Clop has not confirmed any of ShinyHunters' deeper claims, and as of this writing, control of the underlying leak-site infrastructure remains contested between the two groups.


Incident Details

AttributeValue
AttackerShinyHunters (extortion group)
VictimClop / Cl0p ransomware operation's Tor data leak site
VulnerabilityUnauthenticated file-upload flaw in Grav CMS, which ShinyHunters describes as relying on path traversal to place files outside the intended web directory
Attack StartNight of September 18, 2026
Publicly ConfirmedSeptember 19, 2026 (BleepingComputer)
Initial FootholdSmall uploaded text file taunting Clop
EscalationFull site defacement with ShinyHunters branding, hours later
Claimed Stolen DataServer source code, Grav CMS plugins, system//var/log contents, Tor onion private keys
Independently VerifiedThe uploaded file and the resulting defacement page
UnverifiedClaims of stolen source code, log contents, and private key theft
Extortion DemandEight-figure payment (framed as "2.333%" of Clop's alleged net worth), rising every 24 hours, plus a public apology
Clop ResponseBrief text message posted to the same site on September 21, 2026, asking ShinyHunters to make contact

How the Breach Unfolded

An Unpatched CMS Flaw on the Attacker's Own Infrastructure

According to ShinyHunters, the group exploited an unauthenticated file-upload vulnerability in Grav CMS — the software quietly powering Clop's Tor-hosted leak site — to plant a file in a location the application never intended to expose. The group has characterized the underlying weakness as a path traversal issue, consistent with a family of previously disclosed Grav vulnerabilities (including advisory GHSA-m7hx-hw6h-mqmc, covering file-upload path traversal that lets an attacker write or replace files with extensions such as .json, .zip, .css, and .gif) that allow unauthenticated actors to escape Grav's intended upload sandbox. Neither ShinyHunters nor BleepingComputer has cited a specific CVE identifier tied to this exact intrusion, and the precise patch level of Clop's Grav install has not been disclosed.

From a Taunting Text File to a Full Defacement

ShinyHunters first proved access by uploading a small text file readable directly from Clop's own Tor site. It read: "THIS SITE HAS BEEN PWN3D BY SHINYHUNTERES #Skids10p — Maybe don't try to threaten us next time." Hours later, the compromise escalated into a complete takeover of the homepage, replaced with ASCII art of Umbreon — the Pokémon character ShinyHunters uses as its mascot — alongside the taunt "rooting your systems since '19 ;)" and a link to the group's own Tor presence. BleepingComputer independently verified both the uploaded file and the subsequent defacement by visiting Clop's site directly.

Escalating Claims: Source Code, Logs, and Onion Keys

ShinyHunters told BleepingComputer it achieved "full access" to the underlying server and claims to have exfiltrated the site's source code, its Grav CMS plugins, and the entire contents of /var/log — which could include authentication logs and the IP addresses of anyone who connected to the leak site, including potential victims and researchers. Most significantly, ShinyHunters claims to have obtained the private keys used to operate Clop's Tor onion service, stating: "We have their onion keys. So if they kick us out it wouldn't matter at all because we control the private keys to host the same exact onion URL." If genuine, that claim matters far more than a simple defacement — Tor onion addresses are cryptographically derived from a key pair, so whoever holds the private key can serve content at that exact .onion address regardless of which physical server it runs on. None of these deeper claims — the stolen source, the log contents, or the key theft — have been independently verified by BleepingComputer or other outlets.

A Feud Rooted in the Oracle E-Business Suite Campaign

The attack appears to stem from a dispute over the CVE-2025-61882 zero-day used in Clop's 2025 mass-extortion campaign against Oracle E-Business Suite customers. ShinyHunters claims it originally discovered or owned that exploit and that Clop obtained and used it without authorization, and further alleges that a Clop-affiliated member made threats against ShinyHunters members during the resulting dispute — the stated trigger for this retaliatory hack. ShinyHunters told reporters, "We basically own them now."

Extortion, Counter-Message, and Unresolved Control

ShinyHunters is now demanding an eight-figure payment from Clop — which it describes as roughly "2.333%" of Clop's estimated criminal proceeds — plus a public apology, with the sum increasing every 24 hours Clop fails to respond. The group has also threatened to publish which companies paid Clop ransoms during the Oracle E-Business Suite campaign, including payment amounts and the Bitcoin addresses used. On September 21, 2026, the same leak site began displaying a different, plain-text message apparently posted by Clop: "Shiny Hunters we trying to reach you. Your email does not work. Come online old platform no email." That change shows someone — either Clop regaining partial control or ShinyHunters altering the page further — replaced the original defacement, but it does not resolve who actually controls the server or the onion identity going forward. As of this writing, there is no confirmed report of Clop standing up a genuinely new Tor address; security researchers note that if the private-key theft claim holds up, relocating to a new server would not be enough — Clop would need to abandon the exposed .onion identity entirely and persuade its audience to trust a replacement address.


Impact Assessment

Impact AreaDescription
Ransomware Ecosystem StabilityA public gang-on-gang feud undermines the operational secrecy both extortion crews depend on, and hands defenders unusual visibility into Clop's infrastructure and internal disputes
Prior Victim ExposureIf ShinyHunters' threat to publish Oracle E-Business Suite ransom payments and Bitcoin addresses is carried out, organizations that paid Clop could see that fact — and the amount — made public
Data Exposure RiskAlleged theft of /var/log contents could expose the IP addresses of prior site visitors, including researchers, journalists, and possibly victim-side negotiators
Operational Continuity for ClopLoss of the Tor private keys, if real, would let ShinyHunters impersonate Clop's leak site indefinitely at the same address, complicating any attempt by Clop to reassert control
Irony and Reputational DamageClop built a multi-million-dollar extortion business on unpatched software (Accellion, GoAnywhere, MOVEit, Cleo, Oracle EBS) and was itself compromised through an unpatched CMS flaw on its own server
Third-Party Exposure PatternReinforces that any public-facing CMS — including one run by a criminal enterprise — is only as strong as its patch level; the same lesson applies directly to legitimate organizations running Grav

Recommendations

For Organizations Running Grav CMS

  1. Update to the latest Grav CMS release immediately and confirm the version in production is not affected by known file-upload or path-traversal advisories, including GHSA-m7hx-hw6h-mqmc and the broader 2026 batch of path-traversal disclosures affecting versions prior to 2.0.16
  2. Restrict media/upload functionality to authenticated, trusted accounts only, and remove or disable upload-capable plugins that are not actively required
  3. Audit web-server configuration to ensure uploaded content cannot be written to or executed from directories outside the designated media sandbox
  4. Review server logs for anomalous file writes to .json, .zip, .css, or similar extensions in unexpected locations, which can indicate exploitation of this vulnerability class

For Security Teams Tracking the Ransomware Ecosystem

  • Monitor for leaked ransom-payment data tied to Clop's Oracle E-Business Suite campaign, in case ShinyHunters follows through on publishing victim names, amounts, or wallet addresses
  • Treat unverified extortion-group claims with appropriate skepticism — BleepingComputer confirmed the defacement itself but could not verify the deeper data-theft and key-theft claims, and inflated or fabricated claims are common in gang-on-gang disputes
  • Track Clop's onion address status closely; if the private-key theft claim is genuine, any future Clop leak-site communications may originate from an address no longer controlled by Clop's actual operators

For Prior Clop/Oracle EBS Extortion Victims

  • Assume payment details (amounts, timing, wallet addresses) may become public if ShinyHunters carries out its threat, and prepare internal and external communications accordingly
  • Coordinate with legal counsel and incident-response retainers now rather than reactively, given the compressed and escalating extortion timeline ShinyHunters has set for Clop

Key Takeaways

  1. ShinyHunters compromised and defaced Clop's Tor-based data leak site starting September 18, 2026, exploiting an unauthenticated Grav CMS vulnerability the group describes as a path-traversal flaw.
  2. The attack escalated from a small taunting text file to a full defacement featuring ShinyHunters' Umbreon mascot within hours.
  3. ShinyHunters claims — but BleepingComputer has not independently verified — that it stole Clop's source code, server logs, and the private keys to Clop's Tor onion service.
  4. The feud traces back to a dispute over the CVE-2025-61882 Oracle E-Business Suite zero-day used in Clop's 2025 extortion campaign.
  5. ShinyHunters is demanding an eight-figure payment from Clop within 72 hours and has threatened to publish Oracle EBS ransom-payment details, including amounts and Bitcoin addresses.
  6. As of this writing, control of Clop's leak-site infrastructure remains contested, with no confirmed move to a genuinely new Tor address — underscoring that even ransomware operators are vulnerable to the same unpatched-software risks they routinely exploit against victims.

Sources