CVE Tools

ShinyHunters Hacked Clop. Now What About Clop's Victims?

Dark ReadingBy Alexander Culafi

IncidentGrav CMSShinyHuntersOracle E-Business Suite

Our summary

ShinyHunters claims it compromised rival ransomware group Clop's leak-site server by abusing an unauthenticated file-upload flaw in Grav CMS, though the alleged theft of server data has not been independently confirmed. The group has threatened to disclose information about organizations that paid Clop, including companies targeted in the Oracle E-Business Suite campaign tied to CVE-2025-61882. If victim records were obtained, affected organizations could face further data exposure or renewed extortion even after dealing with Clop.

Read at Dark Reading

Dark Reading publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store