Find notable cyber news and cases, enriched with sources, timelines, and signals.

Clop (aka Cl0p) hit by network compromise linked to ShinyHunters

Incident
First reported
Last updated
Happening score
H score 31
1 unique sources, 1 articles

Summary

Hide ▲

The Clop (aka Cl0p) data leak site was breached and defaced, with attackers claiming server data and onion-service keys were stolen, putting the gang's Tor presence at risk. The intrusion was attributed to ShinyHunters and began on Friday night. The compromised site remained reachable after the defacement, and the attackers said they were still reviewing the allegedly stolen data. The event adds a direct operational disruption to an already active feud between the groups.

Timeline

  1. 19.09.2026 16:48 1 articles · 0h ago

    ShinyHunters defaces Clop's Tor leak site through a Grav CMS upload flaw

    Exploitation Observed

    ShinyHunters is reported to have used an alleged unauthenticated file upload flaw in Grav CMS to place a text file on Clop's Tor-based leak site, then replace the page with Umbreon ASCII art and a link to its own leak site. BleepingComputer confirmed the upload and the defacement on the affected Clop infrastructure.

    Show sources
  2. 19.09.2026 16:48 2 articles · 0h ago

    ShinyHunters claims server data and onion keys after the Clop breach

    Victim Impact Update

    ShinyHunters said it had "full access" to the server and was reviewing allegedly stolen data while planning to extort Clop within 72 hours. The group claimed to have taken source code, Grav CMS plugins, system logs, /var/log files, and the private keys for Clop's onion service, but those theft claims were not independently verified.

    Show sources