Protect.Computer
NEWS

ShinyHunters Hacks Clop Ransomware Leak Site, Threatens Extortion

· 1 min read · Got hacked
ShinyHunters Hacks Clop Ransomware Leak Site, Threatens Extortion

The ShinyHunters hacking group has turned the tables on one of the most prolific ransomware operations in recent years: it breached Clop’s own Tor data leak site, defaced it, and is now threatening to extort the gang that extorts others. ShinyHunters exploited what they describe as an unauthenticated file upload flaw in Grav CMS — the software running Clop’s leak site — to first upload a taunting message, then replace the entire site with ASCII art of Umbreon, the Pokémon that serves as their group logo, along with the line “rooting your systems since ‘19 ;)”. BleepingComputer confirmed the defacement was live on Clop’s Tor infrastructure at the time of reporting.

The group claims to have gone far beyond mere defacement. ShinyHunters says it exfiltrated Clop’s source code, CMS plugins, system logs (including authentication records under /var/log), and — most consequentially — the private keys for Clop’s Tor onion service. Those keys, if genuine, would let ShinyHunters operate a site at Clop’s existing dark-web address even if Clop shuts its servers down. The group has given Clop a 72-hour window to make contact before it begins publishing the stolen data. The backstory is a slow-burning feud: ShinyHunters claims that during Clop’s October 2025 Oracle E-Business Suite campaign (CVE-2025-61882), Clop used an exploit that originally belonged to them. Tensions reportedly escalated to the point where a Clop representative allegedly threatened a ShinyHunters member’s life. BleepingComputer has not independently verified the private-key theft or the alleged threats.

Sources

Related reading