socradar.io 21 Sept 2026, 13:28 UTC

ShinyHunters Hijacks Clop’s Leak Site in Extortion Bid

ShinyHunters Hijacks Clop’s Leak Site in Extortion Bid
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Status Unknown
Threat Actor

SHINYHUNTERS reportedly hijacked and defaced rival cybercrime operation Clop’s Tor-based leak site on 18 September 2026. The attackers allegedly exploited an unauthenticated file-upload vulnerability in Grav CMS, first uploading a taunting text file before replacing the site with ShinyHunters branding and an “Umbreon” ASCII mascot. By 19 September, ShinyHunters claimed to have stolen Clop’s source code, plugins, server logs and Tor private keys, potentially allowing it to reproduce the onion service elsewhere.

The visible defacement confirms that ShinyHunters gained enough access to modify the site, but the alleged theft of internal data and private keys has not been independently verified.

The takeover became a public extortion attempt. ShinyHunters initially demanded 2.333% of what it described as Clop’s eight-figure net worth, later threatening to publish alleged details of Clop’s Oracle E-Business Suite campaign, including victims that paid, ransom amounts and cryptocurrency wallets. A message attributed to Clop subsequently appeared, saying the supplied contact email did not work and proposing communication through an earlier platform; it did not publicly address the demands.

The dispute appears linked to the 2025 Oracle EBS exploitation campaign and CVE-2025-61882, which affects EBS versions 12.2.3 through 12.2.14. ShinyHunters claims Clop used an exploit that belonged to it, but Google Threat Intelligence Group reported multiple exploit chains and said there was insufficient evidence to directly connect the earlier activity to the publicly leaked exploit.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline