ShinyHunters hacks Clop leak site, threatens to extort ransomware gang
Reported exploitedGrav CMSShinyHuntersTorOur summary
ShinyHunters breached and defaced the Clop (Cl0p) ransomware group's Tor leak site after claiming to exploit an unauthenticated file upload flaw in Grav CMS. The group says it took server logs, source code, Grav CMS plugins, and onion-service private keys, although only the uploaded file and defacement have been independently confirmed. The incident follows a dispute tied to Clop's Oracle E-Business Suite campaign, which exploited CVE-2025-61882, and ShinyHunters says it intends to extort Clop over the alleged theft.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.