Clop (aka Cl0p) hit by network compromise linked to ShinyHunters
Incident
Summary
Hide ▲
Show ▼
The Clop (aka Cl0p) data leak site was breached and defaced, with attackers claiming server data and onion-service keys were stolen, putting the gang's Tor presence at risk. The intrusion was attributed to ShinyHunters and began on Friday night. The compromised site remained reachable after the defacement, and the attackers said they were still reviewing the allegedly stolen data. The event adds a direct operational disruption to an already active feud between the groups.
Timeline
-
19.09.2026 16:48 1 articles · 0h ago
ShinyHunters defaces Clop's Tor leak site through a Grav CMS upload flaw
Exploitation ObservedShinyHunters is reported to have used an alleged unauthenticated file upload flaw in Grav CMS to place a text file on Clop's Tor-based leak site, then replace the page with Umbreon ASCII art and a link to its own leak site. BleepingComputer confirmed the upload and the defacement on the affected Clop infrastructure.
Show sources
- ShinyHunters hacks Clop leak site, threatens to extort ransomware gang — www.bleepingcomputer.com — 19.09.2026 16:48
-
19.09.2026 16:48 2 articles · 0h ago
ShinyHunters claims server data and onion keys after the Clop breach
Victim Impact UpdateShinyHunters said it had "full access" to the server and was reviewing allegedly stolen data while planning to extort Clop within 72 hours. The group claimed to have taken source code, Grav CMS plugins, system logs, /var/log files, and the private keys for Clop's onion service, but those theft claims were not independently verified.
Show sources
- ShinyHunters hacks Clop leak site, threatens to extort ransomware gang — www.bleepingcomputer.com — 19.09.2026 16:48
- ShinyHunters hacks Clop leak site, threatens to extort ransomware gang — www.bleepingcomputer.com — 19.09.2026 16:48