← All stories
● Covered by 2 sources · 2 reportsMedium impact2 neutral

ShinyHunters Breaches Clop Ransomware Leak Site, Claims Data and Private Key Theft

🔄 Updated 2d ago — new reporting from The Record
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • ShinyHunters defaced Clop's Tor data leak site.
  • The attack exploited an alleged unauthenticated file upload vulnerability in Grav CMS.
  • ShinyHunters claims to have stolen server data and Clop's Tor onion service private keys.
  • BleepingComputer confirmed the defacement but not the data theft claims.
  • ShinyHunters demands an eight-figure extortion payment from Clop.
  • ShinyHunters threatens to expose Clop's payment records.
  • ShinyHunters claims the demand is 2.333% of Clop's net worth.
  • ShinyHunters' demands increase every 24 hours Clop fails to respond.

Clop Leak Site Defaced by ShinyHunters

The ShinyHunters extortion group successfully breached the data leak site operated by the Clop ransomware gang. The attack, which began on a Friday night, resulted in the defacement of Clop's Tor site. ShinyHunters replaced the site's content with ASCII art of Umbreon, their group's Pokémon logo, and a message indicating their presence since 2019.

Exploiting a CMS Vulnerability

ShinyHunters claims the breach was achieved by exploiting an unauthenticated file upload vulnerability within Grav CMS, the content management system used by Clop's site. Initially, a small text file was uploaded containing a warning to Clop and a link to ShinyHunters' own data leak site. BleepingComputer independently confirmed the upload of this file to Clop's server.

Claims of Data and Private Key Theft

Following the defacement, ShinyHunters informed BleepingComputer that they had gained "full access" to Clop's server. They claim to have stolen source code, Grav CMS plugins, system logs (including those under /var/log), and other data. Crucially, ShinyHunters also asserts that they obtained the private keys for Clop's Tor onion service. If these claims are accurate, it would allow ShinyHunters to host a site using Clop's existing onion address, potentially disrupting Clop's operations.

Verification Status

While BleepingComputer confirmed the defacement of Clop's site and the initial file upload, the claims made by ShinyHunters regarding the theft of server logs, source code, and especially the Tor private keys, have not been independently verified at the time of reporting. The defaced page remains active on Clop's infrastructure, according to ShinyHunters.

Updates

🕒 2026-09-21 · new reporting from The Record
  • ShinyHunters demands an eight-figure extortion payment from Clop.
  • ShinyHunters threatens to expose Clop's payment records.
  • ShinyHunters claims the demand is 2.333% of Clop's net worth.
  • ShinyHunters' demands increase every 24 hours Clop fails to respond.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~26 min · 21 stories · Sep 23

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

The ShinyHunters cybercrime group has taken control of the Cl0p ransomware gang's dark web leak site and is demanding an eight-figure extortion payment from Cl0p. This incident represents an unusual inter-gang conflict within the cybercrime landscape, with ShinyHunters threatening to expose Cl0p's payment records.

The ShinyHunters extortion group breached the Clop ransomware operation's data leak site, defacing it and claiming to have stolen server data and the private keys for its onion service. This incident highlights the ongoing conflict between different cybercriminal groups and could impact Clop's future operations if the claims of private key theft are verified.