CVE Tools

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

BleepingComputerBy Lawrence Abrams

Reported exploitedGrav CMSShinyHuntersTor

Our summary

ShinyHunters breached and defaced the Clop (Cl0p) ransomware group's Tor leak site after claiming to exploit an unauthenticated file upload flaw in Grav CMS. The group says it took server logs, source code, Grav CMS plugins, and onion-service private keys, although only the uploaded file and defacement have been independently confirmed. The incident follows a dispute tied to Clop's Oracle E-Business Suite campaign, which exploited CVE-2025-61882, and ShinyHunters says it intends to extort Clop over the alleged theft.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store