Threat Intelligence

Rival Hacker Group ShinyHunters Hijacks Clop Ransomware's Leak Site

SOCRadar · 21 Sept 2026
Key Takeaway Businesses should remember that infighting among cybercriminal groups doesn't reduce the threat to victims; stolen data and leak site claims can still resurface, so continue monitoring for exposure of your organisation's data across dark web sources.

Cybercrime group ShinyHunters has hijacked and defaced the dark web leak site used by ransomware operation Clop to publish and extort victims. The incident began on 18 September 2026 when ShinyHunters reportedly exploited an unauthenticated file-upload flaw in Grav CMS, the content management system running Clop's Tor site. What started as a small taunting text file escalated within hours into a full defacement featuring ShinyHunters branding and boastful messaging.

ShinyHunters claims it also stole Clop's source code, plugins, server logs, and Tor private keys, which could potentially let it recreate Clop's onion address on infrastructure it controls. These deeper claims have not been independently verified, but the visible defacement confirms the group gained meaningful access to Clop's infrastructure.

The clash appears linked to the 2025 mass exploitation of Oracle E-Business Suite, where Clop stole data from organisations before extorting them, later tied to critical vulnerability CVE-2025-61882. ShinyHunters, associated with the Scattered Lapsus$ Hunters channel, alleges Clop used an exploit that originally belonged to them without permission, fuelling this public feud between rival extortion groups.

dark web ransomware Clop ShinyHunters data leak

Summarised by CISO AI from SOCRadar. We link back to every original so you can read it yourself.