MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-19 · via BleepingComputer

Rival extortion group breaches Clop's dark web leak portal

Image via BleepingComputer
Image via BleepingComputer

The ShinyHunters extortion group compromised the data leak site operated by the Clop ransomware gang, exploiting an unauthenticated file upload flaw in Grav CMS to plant a warning message. They claim to have stolen server source code, logs, and the private keys for Clop's Tor onion service, allowing them to maintain control of the site's address. The defacement, featuring ShinyHunters' Umbreon logo, remained live on Clop's infrastructure at the time of reporting.

Expanded Detail

The breach unfolded in stages, beginning with ShinyHunters exploiting an unauthenticated file upload vulnerability in Grav CMS to drop a warning text file on Clop's server. Hours later, the site's homepage was replaced with Umbreon ASCII art, the same imagery used in the group's August 2020 defacement of HackForums. ShinyHunters claims the stolen data includes source code, Grav CMS plugins, system logs, and the private keys for Clop's Tor onion service, which would let them host the same onion address on their own infrastructure. The dispute traces back to Clop's 2025 Oracle E-Business Suite campaign, with ShinyHunters alleging Clop made violent threats after their interference. The group now says it will extort Clop, giving a 72-hour contact window.

Context

This incident could signal a shift in how cybercriminal groups interact, with extortion tactics now being turned inward against rival operations. If ShinyHunters' claims about stolen onion keys and logs are accurate, it may undermine trust in the operational security of ransomware groups, potentially affecting victims who negotiate with these gangs. The breach may also expose sensitive data from Clop's past campaigns, which could have ripple effects for companies already impacted by their attacks.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “ShinyHunters hacks Clop leak site, threatens to extort ransomware gang.” Browse more stories.