The ShinyHunters Clop hack has turned one ransomware group’s methods against another. ShinyHunters claims it defaced Clop’s Tor leak site, stole sensitive server data and obtained the keys controlling its onion service. The group now plans to threaten its cybercrime rival with extortion.

ShinyHunters Takes Over Clop Leak Site

ShinyHunters claims it compromised Clop’s data leak platform through a security flaw in Grav CMS.

According to the group, the vulnerability allowed unauthenticated users to upload files to the server. The hackers exploited the weakness and added a message warning Clop against threatening them.

ShinyHunters also placed a link to its own data leak platform on the compromised website.

Later, the group replaced Clop’s original page with its own branding. The defaced version displayed an ASCII image of Pokémon character Umbreon, which ShinyHunters uses as its logo.

The page also directed visitors to the group’s Tor site. Reports indicated that the altered content remained online after the initial compromise.

Group Claims Full Server Access

ShinyHunters said it gained complete access to the server behind Clop’s leak platform.

The attackers allegedly extracted the website’s source code, Grav CMS plugins and other internal information. They also claimed they were still downloading and examining the stolen material.

In addition, the group says it copied every file from the server’s /var/log directory.

These files may contain system activity records, authentication logs and connection details. Therefore, they could reveal information about Clop’s infrastructure or its operators.

However, independent researchers have not publicly verified the full extent of the alleged data theft.

Tor Private Keys Allegedly Stolen

The ShinyHunters Clop hack may have exposed an especially sensitive part of Clop’s operation.

ShinyHunters claims it obtained the private keys for Clop’s Tor onion service. Those keys control the onion address associated with the ransomware gang’s website.

As a result, ShinyHunters says it could continue hosting content through the same Tor address. Removing the group’s access to the original server may not solve the problem.

Control of the keys could also make recovery much more difficult for Clop. The ransomware gang may need to abandon its established address and launch a new leak platform.

Such a move could disrupt its operations. Moreover, it could damage trust among affiliates, victims and other cybercriminals.

ShinyHunters Threatens Clop With Extortion

ShinyHunters now plans to use Clop’s own tactics against the ransomware group.

The hackers said they were reviewing the stolen data before publishing an extortion message. They intend to give Clop 72 hours to contact them.

However, ShinyHunters has not revealed what it will demand. The group also has not explained which files it may publish if Clop refuses to respond.

The threat mirrors the methods ransomware gangs regularly use against companies. Attackers typically steal internal data and threaten to release it unless the victim pays.

This time, however, another cybercrime group appears to have selected a ransomware operation as its target.

Dispute Traces Back to Oracle Campaign

ShinyHunters says the attack followed a dispute over Clop’s 2025 Oracle E-Business Suite campaign.

Clop allegedly stole data from numerous organisations by exploiting vulnerabilities in Oracle’s business software. However, ShinyHunters claims the ransomware gang also took something from its members during that operation.

According to ShinyHunters, a person representing Clop later threatened to expose and physically harm members of the rival group.

The group says those threats motivated the attack against Clop’s leak platform. Still, neither Clop nor independent investigators have publicly confirmed this account.

Cybercrime Groups Frequently Attack Rivals

Although cybercriminals sometimes cooperate, they also compete for victims, money and influence.

Rival groups may steal each other’s data, target infrastructure or publicly embarrass competing operations. Disputes can also emerge over stolen information, unpaid shares or access to compromised networks.

In March 2025, DragonForce reportedly defaced leak sites operated by BlackLock and Mamona. The attack disrupted its competitors while damaging their reputations.

Another rivalry escalated in 2026 when the 0APT and KryBit ransomware groups compromised each other. Both sides leaked operational data, which reportedly caused serious damage to the two organisations.

The ShinyHunters Clop hack follows the same pattern. However, the alleged theft of Tor keys could give ShinyHunters unusual control over its rival’s online identity.

Claims Remain Unverified

Clop had not publicly confirmed the reported server breach at the time of the latest reports.

Furthermore, independent investigators have not verified every claim concerning the stolen files or onion service keys. Cybercrime groups often exaggerate attacks to attract attention or weaken rivals.

Nevertheless, the visible defacement shows that ShinyHunters gained some level of access to Clop’s platform.

If the remaining claims prove accurate, the ShinyHunters Clop hack could expose technical details about Clop’s infrastructure. It may also reveal information about people who connected to the gang’s servers.


0 responses to “ShinyHunters Hacks Clop Ransomware Site and Threatens Extortion”