Rival extortion group breaches Clop's dark web leak portal

The ShinyHunters extortion group compromised the data leak site operated by the Clop ransomware gang, exploiting an unauthenticated file upload flaw in Grav CMS to plant a warning message. They claim to have stolen server source code, logs, and the private keys for Clop's Tor onion service, allowing them to maintain control of the site's address. The defacement, featuring ShinyHunters' Umbreon logo, remained live on Clop's infrastructure at the time of reporting.
The breach unfolded in stages, beginning with ShinyHunters exploiting an unauthenticated file upload vulnerability in Grav CMS to drop a warning text file on Clop's server. Hours later, the site's homepage was replaced with Umbreon ASCII art, the same imagery used in the group's August 2020 defacement of HackForums. ShinyHunters claims the stolen data includes source code, Grav CMS plugins, system logs, and the private keys for Clop's Tor onion service, which would let them host the same onion address on their own infrastructure. The dispute traces back to Clop's 2025 Oracle E-Business Suite campaign, with ShinyHunters alleging Clop made violent threats after their interference. The group now says it will extort Clop, giving a 72-hour contact window.
This incident could signal a shift in how cybercriminal groups interact, with extortion tactics now being turned inward against rival operations. If ShinyHunters' claims about stolen onion keys and logs are accurate, it may undermine trust in the operational security of ransomware groups, potentially affecting victims who negotiate with these gangs. The breach may also expose sensitive data from Clop's past campaigns, which could have ripple effects for companies already impacted by their attacks.