ShinyHunters allegedly breached and defaced the Tor-based data-leak site of the Clop/Cl0p ransomware operation following a dispute between the cybercrime groups. The group said it exploited an unauthenticated file-upload flaw in Grav CMS, first placing a taunting text file on the site and then replacing it with an Umbreon-themed defacement page.
ShinyHunters claimed it obtained full server access and stole Clop source code, Grav CMS plugins, logs, server data, and private keys for the operation's onion service. It has threatened to extort Clop using the purportedly stolen material; however, the asserted access and data theft have not been independently verified. The conflict is reportedly tied to Clop's alleged threats and its 2025 Oracle E-Business Suite extortion campaign involving CVE-2025-61882.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
ShinyHunters allegedly began compromising Clop/Cl0p's Tor-hosted data-leak site by exploiting an unauthenticated file-upload vulnerability in Grav CMS.
Clop exploited multiple Oracle E-Business Suite vulnerabilities, including zero-day CVE-2025-61882, to steal organizational data as part of an extortion campaign.
ShinyHunters previously claimed responsibility for a HackForums defacement whose Umbreon-themed artwork was later reported to match the artwork used on Clop's leak-site defacement.
ShinyHunters said it was reviewing the allegedly stolen data and intended to extort Clop, reportedly in retaliation for alleged identification and violent threats by a Clop representative. The group said it would direct Clop to make contact within 72 hours through a message on its own leak site.
ShinyHunters claimed it obtained full server access and stole source code, Grav CMS plugins, logs, other server data, and private keys for Clop's onion service. These theft claims were not independently verified.
ShinyHunters replaced Clop's leak site with an Umbreon-themed ASCII-art defacement page linking to its own Tor site. The defacement was independently verified.
ShinyHunters uploaded a text file warning Clop not to threaten the group and linking to ShinyHunters' leak site. The file was independently confirmed as downloadable from Clop's Tor site.
Threat actors calling themselves Scattered Lapsus$ Hunters, including ShinyHunters, released a proof-of-concept exploit that Oracle later confirmed matched one used in Clop's Oracle E-Business Suite attacks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.