ShinyHunters has breached and defaced the Clop ransomware gang's dark-web leak site, claiming to have stolen sensitive server data and threatening to extort its rival. The attack exposes vulnerabilities even among top cybercrime groups.
ShinyHunters has turned the tables in the ransomware world by breaking into Clop's leak site and threatening to extort the rival gang with data allegedly taken from its own servers. This time, the target isn't a business-it's another cybercriminal group, and the fight is playing out on Clop's own dark-web extortion site.
The breach happened after ShinyHunters found and exploited a serious file-upload flaw in the Grav CMS running Clop's Tor site. This vulnerability, which lets anyone upload files without logging in, is a known risk in poorly configured or outdated Grav setups. ShinyHunters first posted a warning message, then replaced the entire site with its own branding, including the Umbreon logo and a link to their own Tor service. BleepingComputer independently confirmed both the warning and the defacement, showing the attackers' technical skill.
Clop's anonymity threatened by server breach
ShinyHunters claims it got "full access" to Clop's server, copying source code, Grav CMS plugins, system logs, and other internal files. The group points to logs from the /var/log directory, which could reveal details about system activity and connections-information ransomware gangs rely on to stay hidden. Using Grav CMS is unusual for major ransomware groups, who usually prefer custom or hardened platforms to reduce risk.
ShinyHunters also says it stole the private keys for Clop's Tor onion service. If true, this could let them impersonate Clop's leak site or disrupt its operations by recreating the same onion address elsewhere. However, BleepingComputer has not confirmed the theft of these keys or the internal data, so these claims remain unverified beyond ShinyHunters' statements. So far, no other major outlet has backed up the claims of stolen Clop server data or onion-service keys. The only confirmed facts are the defacement and the unverified data-theft claims.
Old grudges and new tactics in cybercrime
This feud goes back to Clop's 2025 campaign against Oracle E-Business Suite systems, where the gang exploited vulnerabilities like CVE-2025-61882 to steal data and pressure organizations. ShinyHunters claims Clop used an exploit they originally developed, and that a Clop member later made personal threats. These claims have not been independently confirmed, and Clop has not commented. In September 2026, a new Oracle E-Business Suite vulnerability, CVE-2026-87166, was published, affecting Oracle Purchasing in versions 12.2.3-12.2.15 with a CVSS 3.1 base score of 8.1. This highlights the ongoing risk to enterprise platforms from skilled attackers.
What makes this incident unusual is the reversal of the usual extortion playbook. Instead of threatening a business, ShinyHunters is now threatening another ransomware group with data allegedly taken from its own infrastructure. The group has given Clop 72 hours to respond, but it's unclear if this will lead to payment, retaliation, or more leaks.
Criminal infrastructure under attack
Ransomware gangs usually use leak sites to pressure victims by threatening to publish stolen data. Now, the infrastructure itself is the target. This escalation shows that even well-known cybercriminals are vulnerable to the same tactics they use against others. Both ShinyHunters and Clop have been linked to major data-theft campaigns-ShinyHunters has targeted Salesforce customers and global organizations, while Clop has focused on exploiting enterprise software and file-transfer systems.
For organizations, the lesson is clear: data stolen in one breach can circulate among multiple criminal groups, long after the original attack. The fact that ransomware gangs are now attacking each other's infrastructure shows how fragile their own security can be. As reported earlier, Clop's extortion tactics have already put major companies on edge, but this latest breach shows that no one in the cybercrime world is untouchable.
ShinyHunters' move to use Clop's own leak site against them exposes the limits of operational secrecy among ransomware gangs. For defenders, it's a rare look at the weaknesses behind criminal infrastructure-and a reminder that the threat landscape is unpredictable for attackers as well as their victims.