ShinyHunters Hacks Clop Leak Site, Threaten Ransomware Group with Extortion
ShinyHunters compromised the Clop data leak site, deploying a defacement and asserting control over critical infrastructure.
Overview of the Breach
ShinyHunters exploited an unauthenticated file upload vulnerability in Grav CMS to compromise the Clop data leak site. The threat actors deployed a message warning Clop not to threaten them, asserting control over critical infrastructure. The initial intrusion occurred on Friday night, with the uploaded file containing a directive to the ransomware group and a link to ShinyHunters’ own data leak platform.
Defacement and Symbolic Message
Several hours after the initial upload, ShinyHunters confirmed a full defacement of the Clop site, replacing its content with an ASCII art representation of Umbreon, the Pokémon associated with their brand. The altered page included a link to the group’s Tor-based site and the phrase “rooting your systems since ’19;).” The defaced content remained active on Clop’s infrastructure as of the latest report.
Key Details of the Defacement
The message stated, “THIS SITE HAS BEEN PWN3D BY SHINYHUNTERES #Skids10p – Maybe don’t try to threaten us next time,” alongside a reference to their operational site.
“THIS SITE HAS BEEN PWN3D BY SHINYHUNTERES #Skids10p – Maybe don’t try to threaten us next time,” alongside a reference to their operational site.
Data Theft and Server Access
ShinyHunters claimed to have achieved full server access, extracting source code, Grav CMS plugins, system logs, and other server data. They specifically highlighted the theft of files stored in the /var/log directory, which could include system activity records, authentication logs, and IP addresses of users interacting with the site. The group also asserted possession of the private keys for Clop’s Tor onion service, enabling them to host the same onion address on independently controlled servers.
Conflict Between Cybercrime Groups
The conflict stems from an ongoing rivalry, with ShinyHunters alleging that a Clop representative issued threats following disruptions to the ransomware gang’s operations. The dispute traces back to Clop’s 2025 exploitation of Oracle E-Business Suite servers, involving a zero-day vulnerability tracked as CVE-2025-61882. ShinyHunters claimed the exploit was originally their property and that Clop obtained it without authorization.
Alleged Threats and Escalation
A Clop representative allegedly escalated tensions by threatening ShinyHunters members, including a message translated from Russian that stated, “I have more money than you and all of your people combined, I’ll kill you soon.” BleepingComputer has not independently verified these claims and is awaiting a response from Clop regarding the breach and allegations.
Implications and Cybercrime Rivalry
The incident highlights the escalating confrontations between cybercrime groups, with technical breaches often serving as both a tactical maneuver and a public statement. The theft of cryptographic keys and server data underscores the risks of infrastructure compromise, while the defacement reflects the symbolic nature of such attacks in the underground cybercrime ecosystem.
Conclusion: Escalating Cybercrime Rivalry and Infrastructure Risks
The breach exemplifies the growing intensity of conflicts among cybercrime groups, where technical exploits and public defacements serve as both strategic tools and symbolic declarations of dominance.
