ShinyHunters Hijacks Clop Dark Web Leak Site

ShinyHunters defaced Clop’s dark web leak site and demanded an eight-figure payment while threatening to expose the ransomware group.
ShinyHunters has compromised and defaced the dark web leak site operated by the Clop cybercrime group, turning a dispute between two major data-extortion operations into a public confrontation.
The incident began on September 18, when Clop’s Tor-based leak site was defaced. Visitors were shown ShinyHunters branding, Pokémon artwork and a message declaring that the site had been compromised. The page also directed visitors to ShinyHunters’ own leak platform. BleepingComputer confirmed that a file had been uploaded to Clop’s infrastructure.
The site later displayed a message reading “Domain Seized By ShinyHunters.” By September 21, the Clop site was no longer accessible when Reuters attempted to visit it. Two cybersecurity experts who spoke to Reuters said the confrontation appeared genuine.
ShinyHunters claims that the initial compromise went considerably further than simply defacing Clop’s website.
The group says it exploited an unauthenticated file-upload vulnerability in Grav, the content management system used by the leak site. It claims this provided access to Clop’s source code, plugins and system logs.
ShinyHunters has also claimed that it obtained the private keys associated with Clop’s Tor onion service. If true, those keys could allow the group to maintain or impersonate the same onion address even if Clop moved the website to another server.
However, these claims have not been independently verified.
The confirmed portion of the incident is that Clop’s leak site was compromised, defaced and had a file uploaded to its infrastructure. The extent of any additional access claimed by ShinyHunters remains unclear.
ShinyHunters has now turned Clop’s own extortion model against the group.
On September 19, ShinyHunters posted an eight-figure demand and gave Clop a deadline to respond. The demand was subsequently increased, with the group calling for money allegedly made from Clop’s Oracle E-Business Suite campaign, along with additional payment and a public apology.
ShinyHunters has also threatened to release information about companies that allegedly paid Clop during the campaign, including how much they paid and the Bitcoin addresses involved.
The group warned that its demands would increase every 24 hours if Clop failed to respond.
The confrontation is therefore unusual even by dark web standards: a cybercrime group that normally uses data theft and extortion against companies is now being targeted with the same tactics by another criminal operation.
The conflict appears to have its origins in the 2025 exploitation of Oracle E-Business Suite.
ShinyHunters claims that it originally discovered the zero-day vulnerability later used by Clop during its Oracle EBS campaign. According to ShinyHunters, Clop obtained the exploit and used it to compromise organizations.
Google analyst Austin Larsen estimated that the resulting Clop campaign affected more than 100 companies.
Reuters reported that ShinyHunters’ account of the dispute could not be independently verified. Clop has also not publicly responded to Reuters’ requests for comment.
As the dispute escalated, ShinyHunters claimed that Clop had threatened to expose members of the rival group. ShinyHunters then threatened to reveal information about Clop’s own operations.
Both groups have extensive histories of data theft and extortion.
Clop has been responsible for major campaigns exploiting vulnerabilities in enterprise software and file-transfer platforms, including the 2023 MOVEit campaign, which affected thousands of organizations.
ShinyHunters has also conducted numerous large-scale data theft and extortion campaigns, targeting organizations across multiple sectors.
What makes the latest incident unusual is that the target is not a company, government agency or ordinary victim. ShinyHunters has instead targeted another established cybercrime operation and turned its own leak infrastructure into a platform for demanding money from it.
For now, the public evidence establishes that Clop’s dark web leak site was compromised and defaced by ShinyHunters. The claims that ShinyHunters obtained Clop’s source code, internal logs and Tor private keys remain unverified.
Clop has not publicly confirmed the extent of the compromise, leaving the full impact of the attack unclear as the confrontation continues.
Source: BleepingComputer and The Next Web
References in this story
- BleepingComputer www.bleepingcomputer.com BleepingComputer is a premier destination for cybersecurity news for over 20 years, delivering breaking stories on the latest hacks, malware threats, and how to protect your devices.
- ShinyHunters hacks Clop leak site, threatens to extort ransomware gang www.bleepingcomputer.com The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation's data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service.
- ShinyHunters says it hijacked Cl0p’s dark web leak site thenextweb.com ShinyHunters defaced the Cl0p ransomware gang’s Tor leak site and set a 72-hour deadline. Only the defacement itself can be independently verified.



