Rival Hacker Group ShinyHunters Hijacks Clop Ransomware's Leak Site
Cybercrime group ShinyHunters has hijacked and defaced the dark web leak site used by ransomware operation Clop to publish and extort victims. The incident began on 18 September 2026 when ShinyHunters reportedly exploited an unauthenticated file-upload flaw in Grav CMS, the content management system running Clop's Tor site. What started as a small taunting text file escalated within hours into a full defacement featuring ShinyHunters branding and boastful messaging.
ShinyHunters claims it also stole Clop's source code, plugins, server logs, and Tor private keys, which could potentially let it recreate Clop's onion address on infrastructure it controls. These deeper claims have not been independently verified, but the visible defacement confirms the group gained meaningful access to Clop's infrastructure.
The clash appears linked to the 2025 mass exploitation of Oracle E-Business Suite, where Clop stole data from organisations before extorting them, later tied to critical vulnerability CVE-2025-61882. ShinyHunters, associated with the Scattered Lapsus$ Hunters channel, alleges Clop used an exploit that originally belonged to them without permission, fuelling this public feud between rival extortion groups.