ShinyHunters defaces Clop leak site; claims Grav CMS upload + onion keys stolen
BleepingComputer (Lawrence Abrams; 19 September 2026) reports the ShinyHunters extortion group breached the Clop (Cl0p) ransomware data-leak Tor site: they claim an unauthenticated Grav CMS file-upload flaw let them plant a taunting text file Friday night, then fully deface the site with Umbreon ASCII art and a link to their own leak site. ShinyHunters told BC they gained full server access and stole source code, Grav plugins, /var/log contents, and Tor onion private keys — claiming they could keep hosting the same onion URL if kicked out. BC independently confirmed the uploaded file was downloadable from Clop’s Tor site and that the defacement was being served at write-up time. Crime-on-crime / TA infrastructure compromise — not a victim org breach notice. No ACSC/CISA primary. Primary wire: BleepingComputer.
- Product
- Clop/Cl0p ransomware data-leak site (Grav CMS on Tor); ShinyHunters TA infrastructure dispute
- Versions
- n/a (threat-actor infrastructure; alleged Grav CMS unauthenticated upload)
- Exploited in Australia?
- unknown
- Patch to
- Defenders: no Clop-site patch action. Continue Clop/Oracle EBS extortion monitoring separately; treat TA DLS claims and stolen onion keys as threat-intel colour only.
Primary: BleepingComputer — ShinyHunters hacks Clop leak site (19 Sep 2026) · Vendor: BleepingComputer (wire; no vendor/gov primary) · BleepingComputer — Grav CMS upload claim / onion-key claim (19 Sep 2026)
