Skip to content
Tech News
← Back to articles

Clop moves ransomware leak site after ShinyHunters breach via Grav CMS flaw

read original more articles
GoKawiil Brief

The Clop ransomware group has relaunched its dark web leak site at a new Tor address after ShinyHunters defaced the original server, exploiting an unpatched path traversal vulnerability in Grav CMS. ShinyHunters claims to have stolen source code, plugins, server logs and Tor private keys, and demanded a ransom, but Clop denies any contact with the group and disputes that sensitive data was taken.

Why It Matters

GoKawiil's interpretation of the reporting above, not reported fact.

The incident shows that even ransomware operators running extortion infrastructure are vulnerable to the same unpatched-software risks they exploit in victims, which could undermine confidence in their operational security. The public dispute over what data was actually stolen suggests rival extortion groups may be using breach claims as leverage or reputational attacks rather than verified fact.

Key Takeaways

Source: bleepingcomputer.com, 2026-09-25

Published there as: “ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw”

Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.