The ShinyHunters extortion group breached and defaced the Tor data leak site operated by the Clop ransomware operation, uploading a taunting message and later replacing the page with its own branding. The intrusion began Friday night, when ShinyHunters exploited what it claims is an unauthenticated file upload vulnerability in the Grav CMS used by Clop's site. The group used that flaw to place a small text file on the server warning Clop not to threaten it and linking to ShinyHunters' own leak site. BleepingComputer confirmed the file was hosted on Clop's server and downloadable directly from its Tor site.

Hours later, ShinyHunters said it had fully defaced the site. Visitors to the onion address were shown a page featuring ASCII art of Umbreon, the Pokemon used as the group's logo, along with a link to ShinyHunters' Tor site and a message claiming it has been rooting systems since 2019. ShinyHunters said the defaced page was still being served from Clop's infrastructure at the time of reporting. The group also claimed it had obtained full access to the server.

According to ShinyHunters, the data taken includes source code, Grav CMS plugins, system logs and other material that it says it is still downloading and reviewing. The group additionally claims to have taken all files stored under /var/log, a directory that can hold system activity records, authentication logs and potentially the IP addresses of users who connected to the site. ShinyHunters further asserts it obtained the private keys for Clop's Tor onion service, which it said would let it keep operating the same onion URL from servers it controls even if Clop removed its access.

BleepingComputer independently confirmed the defacement and the earlier uploaded file but has not independently verified the claims about stolen logs, source code or onion private keys. Asked what it intends to do with the data, ShinyHunters said it plans to extort Clop. The group said it will post a message on its own leak site telling Clop to make contact within 72 hours.

Cybersecurity researcher VXDB told BleepingComputer that the Umbreon artwork now on Clop's leak site matches imagery used in the August 2020 defacement of the HackForums website, an attack ShinyHunters also claimed at the time. ShinyHunters described the operation as retaliation for threats it says a Clop representative made during an ongoing feud between the two cybercrime groups, including threats to identify members and violent threats. ShinyHunters said the dispute traces back to Clop's 2025 Oracle E-Business Suite data theft campaign, in which Clop exploited multiple vulnerabilities in Oracle E-Business Suite servers, including a zero-day tracked as CVE-2025-61882, to steal data for extortion. Around that period, actors calling themselves Scattered Lapsus$ Hunters, including ShinyHunters, leaked a proof-of-concept exploit that Oracle later confirmed matched one used in the Clop attacks; ShinyHunters said the exploit had originally belonged to it and that Clop obtained it without authorization.

More cybersecurity news from TechManNews.