SHINYHUNTERS reportedly hijacked and defaced rival cybercrime operation Clop’s Tor-based leak site on 18 September 2026. The attackers allegedly exploited an unauthenticated file-upload vulnerability in Grav CMS, first uploading a taunting text file before replacing the site with ShinyHunters branding and an “Umbreon” ASCII mascot. By 19 September, ShinyHunters claimed to have stolen Clop’s source code, plugins, server logs and Tor private keys, potentially allowing it to reproduce the onion service elsewhere.
The visible defacement confirms that ShinyHunters gained enough access to modify the site, but the alleged theft of internal data and private keys has not been independently verified.
The takeover became a public extortion attempt. ShinyHunters initially demanded 2.333% of what it described as Clop’s eight-figure net worth, later threatening to publish alleged details of Clop’s Oracle E-Business Suite campaign, including victims that paid, ransom amounts and cryptocurrency wallets. A message attributed to Clop subsequently appeared, saying the supplied contact email did not work and proposing communication through an earlier platform; it did not publicly address the demands.
The dispute appears linked to the 2025 Oracle EBS exploitation campaign and CVE-2025-61882, which affects EBS versions 12.2.3 through 12.2.14. ShinyHunters claims Clop used an exploit that belonged to it, but Google Threat Intelligence Group reported multiple exploit chains and said there was insufficient evidence to directly connect the earlier activity to the publicly leaked exploit.