SHINYHUNTERS apparently breached rival ransomware group Clop’s dark-web leak site last week, defacing it with the message “DOMAIN SEIZED BY SHINYHUNTERS.” The group claimed it exploited an unauthenticated file-upload vulnerability in the Grav CMS used by the site, gaining full access to the server and stealing source code, plug-ins, system logs, Onion-service private keys and other data. Those claims have not been independently verified.
On 19 September, ShinyHunters reportedly demanded an unspecified eight-figure Bitcoin payment, later threatening to publish information about companies that allegedly paid Clop, including ransom amounts and Bitcoin addresses. The reference to Clop’s “EBS campaign” likely concerns its extortion operation involving Oracle E-Business Suite customers affected by CVE-2025-61882.
The incident could create additional risks for Clop’s victims, but there is currently no proof that ShinyHunters obtained their files or payment records. Clop’s site later removed the defacement and displayed a note apparently claiming that ShinyHunters’ email address did not work. Dark Reading also reported no apparent payment to ShinyHunters at the time of writing, while the group’s demands continued to increase every 24 hours.
Security commentators warned that data stolen by criminals may remain exposed through copies held by the original attackers, affiliates or infrastructure providers. Organisations that previously paid Clop cannot assume their data was deleted or that ransom agreements will be honoured, and could face renewed extortion if ShinyHunters’ claims are substantiated.