The ShinyHunters extortion gang says it breached the Clop, also known as Cl0p, ransomware operation’s data leak site and stole server data and the private keys for its Tor onion service.
BleepingComputer confirmed that ShinyHunters uploaded a text file to Clop’s site after allegedly exploiting an unauthenticated file-upload vulnerability in Grav CMS. The file warned Clop not to threaten the group and linked to ShinyHunters’ own leak site. ShinyHunters later said it had completely defaced the site. The page displayed ASCII art of Umbreon, the Pokémon used as ShinyHunters’ logo, along with a link to the group’s Tor site.
ShinyHunters claims it obtained source code, Grav CMS plugins, system logs, files under /var/log, and Clop’s Tor onion private keys. If the keys are valid, they could allow the group to operate a site using Clop’s existing onion address. BleepingComputer independently confirmed the defacement and uploaded file, but not the alleged theft of logs, source code, or private keys.
ShinyHunters told BleepingComputer it plans to extort Clop and publish a message instructing the group to make contact within 72 hours. The group says the breach was retaliation for threats linked to Clop’s 2025 Oracle E-Business Suite data-theft campaign, including an attack involving the zero-day vulnerability CVE-2025-61882 in October 2025. BleepingComputer said it had contacted Clop for a response.
Comments
0No comments yet. Be the first to comment.