Clop moves leak site after ShinyHunters exploits Grav CMS bug

Clop moved its data leak site to a new Tor address after ShinyHunters defaced the old one through an unpatched Grav CMS path traversal bug. ShinyHunters claimed it stole source code, plugins, logs, and Tor private keys, and demanded payment; Clop denied valuable operational or financial data was taken and said it had no dealings with the group. Grav confirmed the vulnerability details.
Clop shifted its Tor leak portal after ShinyHunters replaced the original page with a defacement carrying an Umbreon logo and a link to its own site. ShinyHunters claimed it took code, add-ons, server records, and keys tied to the Tor hidden service, then asked for payment.
Grav later confirmed the exploit account. The flaw, CVE-2026-42608, is an unauthenticated traversal bug in form upload handling; a manipulated __unique_form_id__ value could write outside the intended temporary folder. A fix landed in Grav 2.0.0-beta.2, with an April 27 advisory and a sanitizeId() allowlist.
The breach may affect victims whose data is already held by Clop, as uncertainty over the leak site's integrity could complicate extortion negotiations and monitoring. Organizations running Grav CMS could face similar path traversal attacks if unpatched. Security researchers and law enforcement may find threat-actor communications harder to track if onion addresses change or are impersonated. The incident could also erode trust in underground leak portals, though its practical impact remains unclear.