The Clop ransomware group has relaunched its dark web leak site at a new Tor address after ShinyHunters defaced the original server, exploiting an unpatched path traversal vulnerability in Grav CMS. ShinyHunters claims to have stolen source code, plugins, server logs and Tor private keys, and demanded a ransom, but Clop denies any contact with the group and disputes that sensitive data was taken.
bleepingcomputer.com
· 2026-09-25
ShinyHunters, a data-theft and extortion group, defaced rival ransomware gang Clop's dark web leak portal over the weekend, claiming to have exploited an unpatched file-upload flaw in the site's Grav CMS. The attackers say they stole Clop's source code, plugins, system logs and private encryption keys, and are now demanding an unspecified eight-figure Bitcoin payment from Clop while threatening to expose details of victims who paid ransoms.
darkreading.com
· 2026-09-21
The extortion group ShinyHunters says it exploited an unauthenticated file upload flaw in Grav CMS to compromise the Tor-based data leak site run by the Clop ransomware operation. The attackers uploaded a taunting message, later fully defaced the site with Pokémon-themed ASCII art, and claim to have exfiltrated source code, CMS plugins, system logs and other server files. BleepingComputer confirmed the defacement was live on Clop's infrastructure and that the uploaded file could be downloaded from the site.
bleepingcomputer.com
· 2026-09-19