ShinyHunters hacks Clop leak site, threatens to extort ransomware gang
ShinyHunters exploited a Grav CMS file upload flaw to breach and deface the Clop ransomware gang's leak site, claiming theft of source code, logs, and Tor private keys.
The ShinyHunters extortion gang exploited a claimed unauthenticated file upload vulnerability in Grav CMS to upload a taunting file and completely deface the Clop ransomware operation's Tor data leak site with Umbreon ASCII art. ShinyHunters claims it gained full server access, stealing source code, Grav CMS plugins, /var/log files, and the private keys for Clop's onion service, and plans to extort Clop with a 72-hour deadline. The feud reportedly stems from Clop's 2025 Oracle E-Business Suite extortion campaign, which used the zero-day CVE-2025-61882 and an exploit ShinyHunters says was stolen from them. BleepingComputer confirmed the defacement but could not verify the data theft or key theft claims.