ShinyHunters Hacks Clop Ransomware Leak Site

In a remarkable twist of cybercriminal karma, the notorious data breach group ShinyHunters has infiltrated and defaced the dark web leak site belonging to the Clop ransomware gang — one of the most prolific extortion operations in the world. The attackers claim to have seized server logs, source code, and even the private cryptographic keys that control Clop’s Tor hidden service, and they are now threatening to extort the extortionists.

What Happened

On the evening of September 18, ShinyHunters exploited an unauthenticated file upload vulnerability in the Grav content management system that powered Clop’s Tor-based data leak site. Grav is a flat-file CMS — it stores content as files rather than in a database — making it lightweight and easy to deploy on hidden services, but also potentially exposing more of the underlying filesystem when a file upload flaw is present.

The initial move was almost playful: ShinyHunters uploaded a small text file containing the message “THIS SITE HAS BEEN PWN3D BY SHINYHUNTERES #Skids10p — Maybe don’t threaten us next time.” Hours later, the group escalated to a full defacement, replacing the entire site with ASCII artwork of an Umbreon — the Pokémon that has served as ShinyHunters’ logo since their emergence in 2019 — along with a link to their own leak platform and the tagline “rooting your systems since ’19 ;).”

BleepingComputer confirmed the defacement was live on September 19, though Clop had not publicly responded at the time of reporting.

What ShinyHunters Claim to Have Stolen

Beyond the headline-grabbing defacement, ShinyHunters’ claims about the data they exfiltrated are far more consequential. According to the group, they obtained:

  • Source code and Grav CMS plugins — the full application stack running Clop’s leak infrastructure.
  • System logs from /var/log — potentially containing authentication records, connection timestamps, and IP addresses that could unmask Clop operators or affiliates connecting to the server.
  • Private keys for Clop’s Tor onion service — the cryptographic material that defines the .onion address. ShinyHunters stated bluntly: “We have their onion keys. So if they kick us out it wouldn’t matter at all because we control the private keys to host the same exact onion URL.”

If verified, the onion key theft is the most damaging element. Tor hidden service keys are what bind a .onion address to a specific server; whoever holds them can impersonate the service, intercept communications from victims attempting to negotiate ransoms, or simply shut the address down. ShinyHunters gave Clop a 72-hour window to make contact before they would escalate further.

It is worth noting that while the defacement has been independently confirmed by multiple outlets, the full extent of the data theft has not been independently verified. Hackread reported that ShinyHunters did not respond to requests for proof of the broader claims, and Clop itself remained silent.

A Feud Rooted in Real-World Threats

This was not a random hack. Multiple reports indicate the attack was motivated by a prior confrontation between the two groups. During Clop’s 2025 campaign exploiting vulnerabilities in Oracle E-Business Suite, a dispute arose between the gangs, reportedly culminating in violent threats from a Clop representative directed at ShinyHunters members. The defacement message — “Maybe don’t threaten us next time” — appears to be a direct reference to that incident.

Security researcher VXDB pointed out that the Umbreon ASCII artwork used in the defacement matched imagery ShinyHunters deployed during a HackForums defacement back in August 2020, highlighting the group’s consistent operational signature across years of activity.

Who Are the Players

Clop (also tracked as TA505 or FIN11 in some threat intelligence frameworks) is among the most impactful ransomware and extortion operations of the past five years. The group is best known for its mass exploitation of file transfer software — the 2023 MOVEit Transfer campaign alone compromised over 2,000 organizations and exposed data belonging to tens of millions of individuals. Clop’s leak site is central to its business model: victims who refuse to pay see their stolen data published there, and the threat of publication is the primary extortion lever.

ShinyHunters, active since at least 2019, operates primarily as a data breach and sale group rather than a ransomware operation. The group has been linked to high-profile breaches including Ticketmaster, AT&T, and Microsoft’s private GitHub repositories. In 2024, French authorities arrested Sebastien Raoult, an alleged ShinyHunters member, who was later extradited to the United States and sentenced to three years in prison. Despite law enforcement pressure, the group has continued operating.

Why This Matters

The incident is significant on several levels. First, it demonstrates that ransomware gangs, despite their technical sophistication in attacking others, are not immune to the same classes of vulnerabilities they exploit — in this case, a basic web application flaw. Running a public-facing CMS, even on a hidden service, requires the same patch management discipline that these groups fault their victims for lacking.

Second, if the server logs contain real connection metadata, they could prove valuable to law enforcement agencies that have been pursuing Clop operators for years. Even if ShinyHunters has no intention of cooperating with authorities, the mere existence of such data in adversarial hands adds pressure on Clop’s operational security.

Third, the compromise of Tor onion service keys raises questions about the reliability of ransomware negotiation channels. Victims — and the incident response firms representing them — need to trust that they are communicating with the actual threat actor holding their data. If a third party can impersonate a ransomware gang’s infrastructure, it introduces a new vector for fraud within an already fraught process.

What to Watch Next

In the short term, all eyes are on whether ShinyHunters will follow through on their extortion threat and publish whatever data they hold. Clop will likely migrate to new infrastructure with fresh onion keys — standard practice after a compromise — but any data already exfiltrated cannot be clawed back. Law enforcement agencies including the FBI and Europol, which have actively targeted both groups in recent years, may find new leads in whatever ShinyHunters chooses to release or leak.

For defenders and the broader security community, the takeaway is clear: nobody’s infrastructure is invulnerable — not even the infrastructure built by career cybercriminals. The same fundamentals that protect enterprises apply to hidden services: patch your software, restrict file uploads, and assume someone is always looking for a way in.

Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.