// 1 ZERO-DAY · 4 CVE · 2 EXPLOIT · 1 ADVISORY IN THE LAST 24H
ShinyHunters breached the Clop ransomware gang's Tor leak site on September 18, 2026, uploading a text file and replacing the homepage with a defacement. BleepingComputer independently confirmed the defacement and file upload, but could not verify ShinyHunters' claims of data theft or control over the onion private keys.

ShinyHunters compromised the Tor leak site of the Clop ransomware gang on the evening of September 18, 2026, uploading a text file and replacing the homepage with a defacement. The attack, claimed as retaliation for alleged threats from a Clop representative, exposes a rare fracture in the cybercrime underground: an extortion group attacking the infrastructure of a rival ransomware operator. BleepingComputer independently verified the defacement and the file upload, but could not confirm ShinyHunters' claims of data theft and control over the onion keys.

Key Takeaways
  • BleepingComputer confirmed that a text file was uploaded to Clop's server and was downloadable from the Tor site, containing the message: "THIS SITE HAS BEEN PWN3D BY SHINYHUNTERES #Skids10p - Maybe don't try to threaten us next time"
  • The site was defaced with Umbreon ASCII art, ShinyHunters' historic logo, and the message "rooting your systems since '19 ;)"
  • ShinyHunters claims to have exploited an unauthenticated file upload vulnerability in Grav CMS, but the precise technical nature of the exploit has not been independently verified
  • The group states it intends to extort Clop with a 72-hour deadline, but BleepingComputer has not verified claims regarding theft of source code, system logs, or the onion service's private keys

How ShinyHunters Got In: File Upload and Defacement Verified

The attack began on Friday, September 18, 2026, with the upload of a text file to the server hosting Clop's Tor leak site. BleepingComputer downloaded and verified the file, confirming it contained a claim message and a link to ShinyHunters' site.

Subsequently, the Tor site's homepage was replaced with Umbreon ASCII art, the same figure used in the HackForums defacement in August 2020 according to researcher VXDB. The defacement includes the message "rooting your systems since '19 ;)".

ShinyHunters told BleepingComputer it had obtained "full access" to the server, but provided no verifiable technical proof of this assertion. Independent verification stopped at the file upload and the web page modification.

The Feud: Oracle EBS and CVE-2025-61882 as the Origin of the Conflict

ShinyHunters' stated motivation traces back to Clop's 2025 campaign against Oracle E-Business Suite systems, which exploited CVE-2025-61882. According to the group, Clop obtained an exploit that originally belonged to them without authorization.

The dispute escalated when a Clop representative allegedly verbally threatened ShinyHunters members with phrases translated from Russian such as "I have more money than you and all of your people combined, I'll kill you soon".

CVE-2025-61882 is cataloged by CISA in the Known Exploited Vulnerabilities list with the flag "Known To Be Used in Ransomware Campaigns". The dossier does not establish a direct technical nexus between this CVE and the attack on Clop's leak site. The feud remains in the realm of unverifiable mutual claims.

What ShinyHunters Claims to Have Stolen: The Limits of Verification

The group declared it had stolen source code, Grav CMS plugins, system logs from /var/log, and the private keys for Clop's Tor onion service. In the statement reported by BleepingComputer, it asserts: "We have their onion keys. So if they kick us out it wouldn't matter at all because we control the private keys to host the same exact onion URL".

BleepingComputer explicitly stated it has not independently verified any of these claims. The distinction is significant: control of the onion keys, if real, would allow ShinyHunters to maintain control over the Tor address regardless of the compromised server, but the dossier contains no technical evidence of this acquisition.

"BleepingComputer has independently confirmed the defacement and earlier uploaded file but has not independently verified ShinyHunters' claims that it stole server logs, source code, or Clop's onion private keys"

Why Attacking Leak Sites Changes the Threat Intelligence Game

The compromise of a ransomware leak site introduces an authenticity problem that has so far primarily affected legitimate victims. When ShinyHunters controls or claims to control Clop's infrastructure, every data point published on that Tor site becomes potentially unreliable: files could be manipulated, exfiltration claims inflated, and proof of compromise inserted retroactively.

For enterprises monitoring leak sites to assess their data exposure, this means the source itself has become a disinformation vector. The dossier does not specify if or how organizations should adapt their threat intelligence processes to this scenario.

What Changes

The operation reveals that ransomware groups depend on conventional web infrastructure — servers, CMS, network configurations — beyond the Tor layer. The leak site is not an ethereal entity in the dark web: it is a web application hosted on physical hardware, with writable directories and system logs.

The dossier does not specify the reasoning behind Clop's technological choice of Grav CMS. ShinyHunters gave the group 72 hours to respond before potential publications, but the brief does not report calendars or absolute deadlines.

Uncertainty over the future contents of the compromised site remains the primary informational limit: until ShinyHunters' claims are independently verified, every data point published on Clop's leak site requires double validation.

Questions and Answers

Why would Clop use Grav CMS?

The dossier does not specify the reasoning behind the technological choice.

Is the stolen data real?

BleepingComputer has not independently verified claims regarding source code, system logs, or onion keys. Only the defacement and file upload are confirmed.

What does Clop risk?

ShinyHunters threatens to extort the group, but the brief reports no evidence that Clop's ransomware operation has been disrupted or that victim data has already been published.

Who is right in the feud?

The brief contains no elements to verify the mutual accusations regarding possession of the Oracle exploit or the threats from the Clop representative.

Information has been verified against cited sources and is current as of publication.

Sources


Sources and references
  1. bleepingcomputer.com
  2. daily.dev
  3. cisa.gov
  4. resecurity.com
  5. deals.bleepingcomputer.com