
ShinyHunters has reportedly compromised the leak site operated by the Clop ransomware group, defaced the site and threatened to extort the cybercrime operation, according to reports from Cybernews and BleepingComputer.
Cybernews reported on September 19, 2026, that ShinyHunters had hacked Clop’s Tor-based data-leak site and claimed to have obtained sensitive information from the infrastructure supporting the operation.
The reported incident involved the leak site being altered to display ShinyHunters branding, including an Umbreon ASCII image and the message, “rooting your systems since ’19 ;)”.
Cybernews reported that ShinyHunters claimed it gained access through an unauthenticated file-upload weakness in the Grav CMS installation used by Clop’s leak site.
According to the report, ShinyHunters first uploaded a small text file to the server before claiming to have gained broader access to the underlying infrastructure.
ShinyHunters said it obtained source code, server logs, Grav CMS plugins and the private keys associated with Clop’s Tor onion service.
The group also reportedly threatened to extort Clop itself, giving the ransomware operation a 72-hour deadline to respond.
BleepingComputer independently reported the compromise and said it verified that ShinyHunters had uploaded a file to Clop’s infrastructure and that the leak site was later defaced.
The independent observations support the reported compromise and defacement. However, the broader claims made by ShinyHunters about the material it obtained have not been independently demonstrated in the available reporting.
In particular, ShinyHunters’ claim that it obtained Clop’s Tor private keys has not been independently verified.
The claim of full or root-level access to Clop’s infrastructure also remains a claim by ShinyHunters rather than an independently established fact.
The private-key allegation has attracted attention because Tor onion services rely on cryptographic key material for their service identity.
If the keys were genuinely obtained and remained usable, the compromise could create risks involving impersonation of the existing onion service and manipulation of communications associated with it.
There is currently no independent public evidence establishing that ShinyHunters possesses usable copies of those keys.
The incident is also linked in reporting to an earlier dispute involving ShinyHunters, Clop and attacks against Oracle E-Business Suite in 2025.
In October 2025, actors calling themselves Scattered Lapsus$ Hunters, associated with ShinyHunters, released an Oracle E-Business Suite exploit and files that referenced Clop.
BleepingComputer reported that the exploit released at the time corresponded to an exploit identified in Oracle’s indicators of compromise.
Oracle later disclosed CVE-2025-61882, a critical Oracle E-Business Suite vulnerability that had been exploited in the wild.
Investigations by Mandiant and CrowdStrike subsequently showed that the 2025 Clop activity involved multiple Oracle E-Business Suite exploit chains.
ShinyHunters claimed that the Oracle exploit had originated with its members and that it had been passed to Clop.
The group later said it leaked the exploit because it believed Clop was using an exploit that belonged to its members.
Clop did not respond to questions from BleepingComputer about the relationship between the groups and the Oracle exploitation activity, according to the publication.
The latest intrusion therefore comes against the background of an existing dispute between the two cybercrime groups, although specific claims about communications, threats and motives remain attributed to the parties involved.
The reported initial access in the latest incident also differs from the Oracle vulnerability referenced in the earlier dispute.
No confirmed CVE has been identified in the available reporting for the specific Grav CMS weakness allegedly used against Clop’s leak site.
CVE-2025-61882 concerns Oracle E-Business Suite and should not be presented as the vulnerability used to compromise Clop’s Grav CMS-based leak site.
Secondary reporting has linked the current incident to the Oracle vulnerability, but the two technical issues are separate based on the information currently available.
The confrontation is notable because Clop normally uses stolen corporate data and a leak site to pressure victims into paying. In this case, ShinyHunters is reportedly attempting to use Clop’s own infrastructure and allegedly obtained information as leverage against the ransomware operation.
The incident also highlights the security risks facing criminal infrastructure itself. The reported initial access was through a weakness in the web application supporting the operation rather than through a publicly documented technique for breaking Tor’s underlying technology.
ShinyHunters has previously been associated with large-scale data theft and extortion activity.
Google Threat Intelligence has documented multiple clusters associated with ShinyHunters-branded extortion activity, including campaigns involving stolen SaaS data, phishing and subsequent extortion.
Microsoft has also reported phishing activity involving threat actors linked to ShinyHunters and other extortion groups, including campaigns using passkey and single sign-on themes to target Microsoft 365 environments.
Discover more from Aree Blog
Subscribe now to keep reading and get access to the full archive.


