ShinyHunters Hacked Clop. Now What About Clop's Victims?
IncidentGrav CMSShinyHuntersOracle E-Business SuiteOur summary
ShinyHunters claims it compromised rival ransomware group Clop's leak-site server by abusing an unauthenticated file-upload flaw in Grav CMS, though the alleged theft of server data has not been independently confirmed. The group has threatened to disclose information about organizations that paid Clop, including companies targeted in the Oracle E-Business Suite campaign tied to CVE-2025-61882. If victim records were obtained, affected organizations could face further data exposure or renewed extortion even after dealing with Clop.
Dark Reading publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.