The ShinyHunters cybercrime group has claimed responsibility for breaching and defacing the data leak site operated by the Clop ransomware gang. The attack, which began on a Friday night, involved defacing Clop's Tor-based site with ASCII art and a message, and ShinyHunters alleges it also stole server data and private keys for Clop's onion service.
ShinyHunters stated that the initial breach exploited an unauthenticated file upload vulnerability in Grav CMS, the content management system used by Clop. This allowed them to upload a text file containing a warning to Clop and a link to ShinyHunters' own leak site. Hours later, the Clop site was completely defaced, displaying an Umbreon Pokémon ASCII art, which is ShinyHunters' emblem, along with the message "rooting your systems since '19 ;)" and another link to their site. The defaced page was reportedly still being served from Clop's infrastructure.
ShinyHunters claims to have gained full access to the Clop server, alleging the theft of source code, Grav CMS plugins, system logs, and other data. Specifically, they mentioned downloading all files from the `/var/log` directory, which could contain sensitive information like system activity and authentication records. A significant claim made by ShinyHunters is the acquisition of Clop's Tor onion service private keys. If these keys are valid, ShinyHunters could potentially operate a Tor site using Clop's existing onion address on their own servers. While the defacement and the initial file upload have been independently confirmed, the claims of data theft, including server logs, source code, and private keys, remain unverified by independent parties.
ShinyHunters has indicated its intention to extort Clop, planning to issue a message on its own leak site instructing the ransomware group to make contact within 72 hours. The Umbreon artwork used in the defacement is consistent with previous defacements claimed by ShinyHunters, such as the HackForums website in August 2020.
This attack is reportedly a retaliatory measure stemming from an ongoing feud between the two cybercrime groups. ShinyHunters alleges that a Clop representative made threats to identify and harm their members after ShinyHunters disrupted a Clop data theft campaign. The dispute reportedly originated during Clop's 2025 Oracle E-Business Suite data theft campaign, which exploited multiple vulnerabilities, including a zero-day flaw identified as CVE-2025-61882.
During that period, a group including ShinyHunters, operating under the name "Scattered Lapsus$ Hunters," leaked a proof-of-concept exploit that Oracle later confirmed matched one used in Clop's attacks. ShinyHunters asserted that this exploit originally belonged to them and was obtained by Clop without authorization. Tensions escalated, with ShinyHunters claiming a Clop representative sent a personal message containing threats, including a translated Russian quote about having more money and intending to kill. These allegations of threats and the origin of the exploit have not been independently verified.






