ZeroHour
DataBreaches.netpublished ()ingested Dissent
Part of a story covered by 5 sources: “Oracle September 2026 Critical Patch Update Fixes 800+ Vulnerabilities; ShinyHunters Defaces Clop Leak Site in Feud Tied to Oracle E-Business Suite Extortion” — merged summary and timeline →

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

mediumData breach exploited in the wildimportance 62
AI summary · glm-5.3-flash

Extortion group ShinyHunters hacked the Clop ransomware gang's leak site, defacing it and stealing server data and onion service private keys.

ShinyHunters breached the Clop (Cl0p) ransomware operation's Tor data leak site on Friday night, defacing it and allegedly stealing server data plus the private keys for its onion service. The attackers claim they exploited an unauthenticated file upload vulnerability in Grav CMS. ShinyHunters is reportedly threatening to extort the ransomware gang itself.

  • Clop leak site defaced on Tor; server data and onion service keys allegedly stolen.
  • Attack used a claimed unauthenticated file upload vulnerability in Grav CMS.
  • ShinyHunters threatens to extort the Clop ransomware operation.
VendorsGrav CMS
Threat actorsShinyHuntersClop
Full article

Lawrence Abrams reports: The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation’s data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service. The attack began Friday night when ShinyHunters exploited what they claim is an unauthenticated file upload vulnerability in Grav CMS, which... Source

The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at databreaches.net.