CSIDB logo
Incident

Clop

Incident posture

Attack window
Sep 2026
Location
-
Status
Unknown
CIA posture
Available to members
Updated
2026-09-23 17:40

Linked entities

Victim
Clop
Threat actors
2 actors
Sources
1 source

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Clop's Tor leak site was compromised when ShinyHunters exploited an unauthenticated file upload flaw in the Grav CMS, uploading a text message and later defacing the page with Umbreon ASCII art and a link to their own leak site. The attackers claimed full server access, saying they stole source code, CMS plugins, system logs and the private keys for the onion service, which would let them host the same address elsewhere. They then extorted the group, demanding an eight‑figure payment that would rise daily, and threatened to release data allegedly showing payments made during its Oracle E‑Business Suite campaign, including amounts and Bitcoin addresses. The ransomware group responded on the hijacked site, asking for contact, but ShinyHunters rejected the reply and continued the extortion attempt.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

On Friday night in September 2026, ShinyHunters exploited an unauthenticated file upload vulnerability in the Grav CMS powering Clop’s Tor‑based leak site and uploaded a small text file containing a threat message and a link to ShinyHunters’ own leak site. BleepingComputer confirmed that the file was present on the server and could be downloaded directly from Clop’s site. Several hours later ShinyHunters announced that they had completely defaced the leak site, and visitors observed a page displaying ASCII art of the Umbreon Pokémon, a link to the ShinyHunters Tor site, and the text “rooting your systems since '19 ;)”. The defaced page remained active on Clop’s infrastructure according to ShinyHunters’ statements. After the initial article was published, ShinyHunters began posting daily updates on its leak site warning Clop that it was being extorted and threatening to release allegedly stolen information if demands were not met.

ShinyHunters initially demanded an eight‑figure payment and said the amount would increase every 24 hours that Clop failed to respond, later adding a requirement for a public apology and threatening to disclose payment amounts and Bitcoin addresses linked to companies that allegedly paid Clop during its Oracle E‑Business Suite extortion campaign. On September 21, Clop posted a brief reply on its hijacked leak site stating “Shiny Hunters we trying to reach you. Your email does not work. Come online old platform no email,” which ShinyHunters rejected while reiterating its extortion demands. ShinyHunters claimed to have gained full access to the server, saying they stole source code, Grav CMS plugins, system logs, and other data, and that they had copied all files under /var/log, which could contain authentication logs and IP addresses. They also asserted they had obtained the private keys for Clop’s Tor onion service, arguing that control of those keys would allow them to host the same onion address on servers they control. BleepingComputer verified the defacement and the uploaded file but could not independently confirm the claims of data theft or key acquisition.

The actors said they were reviewing the allegedly stolen data and intended to use it to extort Clop, planning to publish a message on their own leak site giving Clop 72 hours to contact them. ShinyHunters framed the attack as retaliation for an ongoing feud, alleging that a Clop representative had threatened to identify group members and made violent threats after ShinyHunters disrupted a Clop data theft campaign, tracing the dispute back to Clop’s 2025 Oracle E‑Business Suite campaign in which Clop exploited a zero‑day flaw (CVE‑2025‑61882) and allegedly used an exploit that ShinyHunters said had originally belonged to them. BleepingComputer noted that it had contacted Clop for comment on the breach and the allegations and would update the story if a response was received.

Sources

Sources available to members: 1 source.

CSIDB