Close Menu
NCIJ Network NCIJ Network
    What's Hot

    For Climate-Vulnerable Countries, Debt Costs 25 Times More Than Climate Action

    September 19, 2026

    Atletico Madrid vs Real Madrid: La Liga – preview, team news, prediction | Football

    September 19, 2026

    Tired of Cluttered Productivity Apps? This One’s Just a Text Document

    September 19, 2026
    Facebook X (Twitter) Instagram
    Trending
    • For Climate-Vulnerable Countries, Debt Costs 25 Times More Than Climate Action
    • Atletico Madrid vs Real Madrid: La Liga – preview, team news, prediction | Football
    • Tired of Cluttered Productivity Apps? This One’s Just a Text Document
    • ShinyHunters hacks Clop leak site, threatens to extort ransomware gang
    • Bastion conditionally OK for US trust bank
    • Canada shuts down corporate watchdog. Critics say its replacement lacks teeth
    • How We Uncovered That Umar Kremlev Bankrolled Donald Trump Jr.’s Wedding — ProPublica
    • Trump admin considers giving Cumberland Island National Seashore land to private owners
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, September 19
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 19, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation’s data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service.

    The attack began Friday night when ShinyHunters exploited what they claim is an unauthenticated file upload vulnerability in Grav CMS, which they used to upload a small text file to Clop’s site.

    File downloaded from Clop's data leak site
    File downloaded from Clop’s data leak site
    Source: BleepingComputer

    The small text file contained a message from the threat actors to the Clop ransomware gang, warning not to threaten them and including a link to ShinyHunter’s own data leak site.

    “THIS SITE HAS BEEN PWN3D BY SHINYHUNTERES #Skids10p – Maybe don’t try to threaten us next time,” read the uploaded file.

    File uploaded to Clop's data leak site
    File uploaded to Clop’s data leak site
    Source: BleepingComputer

    The file also contained a link to the ShinyHunters data leak site.

    BleepingComputer confirmed that the file had been uploaded to Clop’s server and could be downloaded directly from the ransomware gang’s Tor site.

    Several hours later, ShinyHunters told BleepingComputer that they had “completely defaced” the Clop site.

    Visiting the site confirmed it had been replaced with a page displaying ASCII art of Umbreon, the Pokémon used as ShinyHunters’ logo. The defacement also included a link to the group’s Tor site and the message, “rooting your systems since ’19 ;)”.

    Clop's data leak site defaced by ShinyHunters
    Clop’s data leak site defaced by ShinyHunters
    Source: BleepingComputer

    At the time of this writing, the defaced page is still being served from Clop’s infrastructure, according to ShinyHunters.

    ShinyHunters claims data theft

    ShinyHunters told BleepingComputer it gained “full access” to the server and stole source code, Grav CMS plugins, system logs, and other data.

    “The data we stole includes source codes, gravCMS plugins, and other things. We are still downloading and reviewing them,” ShinyHunters told BleepingComputer.

    The threat actors also claim to have stolen all files stored under /var/log, which could contain system activity, authentication logs, and potentially, the IP addresses of those who connected to it.

    ShinyHunters also claims to have obtained the private keys used by Clop’s Tor onion service.

    “We have their onion keys. So if they kick us out it wouldn’t matter at all because we control the private keys to host the same exact onion URL,” the threat actor claimed.

    If the keys are valid, it would allow the threat actors to operate a Tor site using Clop’s existing onion address on servers they control.

    BleepingComputer has independently confirmed the defacement and earlier uploaded file but has not independently verified ShinyHunters’ claims that it stole server logs, source code, or Clop’s onion private keys.

    ShinyHunters says it is now reviewing the allegedly stolen data.

    When asked what they planned to do with the stolen information, the threat actor responded, “Going to extort them.”

    The group says it plans to publish a message on its own leak site instructing Clop to contact them within 72 hours.

    Cybersecurity researcher VXDB told BleepingComputer the Umbreon artwork now displayed on Clop’s leak site is the same as what was used in the August 2020 defacement of the HackForums website, which ShinyHunters also claimed at the time.

    Feud between cybercrime groups

    ShinyHunters says the attack is retaliation for threats allegedly made by a Clop representative during an ongoing feud between the cybercrime groups.

    According to ShinyHunters, a Clop representative threatened to identify group members and made violent threats after ShinyHunters disrupted a Clop data theft campaign.

    ShinyHunters says the dispute dates back to Clop’s 2025 Oracle E-Business Suite data theft campaign.

    In October 2025, Clop exploited multiple vulnerabilities in Oracle E-Business Suite servers, including a zero-day flaw tracked as CVE-2025-61882, to steal data from organizations in extortion campaigns.

    Around the same time, threat actors calling themselves “Scattered Lapsus$ Hunters,” including ShinyHunters, leaked a proof-of-concept exploit that Oracle later confirmed matched an exploit used in the Clop attacks.

    At the time, ShinyHunters told BleepingComputer the exploit had originally belonged to them and that Clop obtained it without authorization.

    ShinyHunters claims that tensions escalated after the Oracle campaign, with a Clop representative allegedly threatening members of the group.

    “During the Oracle EBS campaign they ran and stole from me last year, someone from cl0p personally messaged me and said, and I quote (translated from Russian): I have more money than you and all of your people combined, I’ll kill you soon,” ShinyHunters told BleepingComputer.

    BleepingComputer has not independently verified these allegations and has contacted Clop about the breach and the allegations made by ShinyHunters and will update the story if we receive a response.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    Clop extort gang hacks leak ransomware ShinyHunters site threatens
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Calling viral AI actress Tilly Norwood? Agree to a face scan first

    Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws

    Brevo Supply Chain Attack Injects Malware Into 100,000 Websites

    Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up

    Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

    CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    For Climate-Vulnerable Countries, Debt Costs 25 Times More Than Climate Action

    September 19, 2026

    Atletico Madrid vs Real Madrid: La Liga – preview, team news, prediction | Football

    September 19, 2026

    Tired of Cluttered Productivity Apps? This One’s Just a Text Document

    September 19, 2026

    ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

    September 19, 2026
    Latest Posts

    AIPAC Spending Dominates the Michigan Democratic Senate Primary

    August 5, 2026

    Labour members ‘have tougher view on welfare than you might think’, poll suggests | Labour

    August 5, 2026

    Palantir funnels earnings to US to avoid European taxes, report finds – POLITICO

    August 5, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    For Climate-Vulnerable Countries, Debt Costs 25 Times More Than Climate Action

    September 19, 2026

    Atletico Madrid vs Real Madrid: La Liga – preview, team news, prediction | Football

    September 19, 2026

    Tired of Cluttered Productivity Apps? This One’s Just a Text Document

    September 19, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.