THE ShinyHunters extortion group reportedly breached the Clop (also known as Cl0p) ransomware operation’s data-leak website, defacing its Tor-based site and allegedly stealing server data and the private keys for its onion service. The incident began on Friday night, according to the report, when ShinyHunters claimed to have exploited an unauthenticated file-upload vulnerability in Grav CMS.
The attackers used the alleged flaw to upload a small text file to Clop’s site. The file contained a message warning the ransomware group not to threaten ShinyHunters and linked to ShinyHunters’ own data-leak site.
The message read: “THIS SITE HAS BEEN PWN3D BY SHINYHUNTERES #Skids10p – Maybe don’t try to threaten us next time.” The report describes the theft of server data and onion-service private keys as alleged; it provides no independent confirmation of the claims or further details about the vulnerability, affected Grav CMS version, or the extent of any data access.