Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Sep 22, 2026 · 7 min read

ShinyHunters Hijacks Clop's Leak Site and Onion Keys

On September 19, 2026, ShinyHunters defaced Clop's Tor data leak site through an unauthenticated file upload flaw in Grav CMS, then demanded an eight figure payment and threatened to publish which companies paid Clop during the Oracle E-Business Suite campaign. Clop answered publicly two days later.

The site Clop has used since 2020 to name companies and squeeze them went down Friday night and came back up showing ASCII art of Umbreon, the Pokemon ShinyHunters uses as a logo, above the line "THIS SITE HAS BEEN PWN3D BY SHINYHUNTERS". The extortion infrastructure got extorted. That part is funny. What gets published next is not.

Key Takeaways

  • ShinyHunters defaced Clop's Tor data leak site on September 19, 2026 by abusing an unauthenticated file upload flaw in its Grav CMS, according to BleepingComputer.
  • ShinyHunters claims it took the site source code, the Grav plugins, the contents of /var/log and the private keys to Clop's .onion service, but BleepingComputer has not independently verified any of those claims.
  • The demand is an eight figure payment that rises every 24 hours plus a public apology, a sum ShinyHunters calls 2.333% of Clop's net worth.
  • ShinyHunters threatened to publish which companies paid Clop during the October 2025 Oracle E-Business Suite campaign, including amounts and Bitcoin addresses.
  • Clop replied on September 21, 2026 through the hijacked site: "Shiny Hunters we trying to reach you. Your email does not work. Come online old platform no email."

What Happened to Clop's Leak Site?

A rival crew took it over through a web application bug, not anything exotic. Clop's leak site runs on Grav, a flat file CMS, and ShinyHunters found an unauthenticated upload path that let it write files to the server without credentials. A plain text warning landed first, then the full defacement, signed off with "rooting your systems since '19".

A gang that earned hundreds of millions from unpatched Accellion, GoAnywhere, MOVEit, Cleo and Oracle servers lost its own site to an unpatched CMS. The Register and Infosecurity Magazine both confirmed the takeover. ShinyHunters defaced HackForums back in August 2020; what is new is doing it to another extortion operation and then running the extortion playbook against it.

What Did ShinyHunters Actually Take?

Nobody outside the two gangs knows, and that distinction matters. ShinyHunters claims four things: the leak site source code, the Grav plugins, the system logs under /var/log and the private keys for Clop's .onion hidden service. BleepingComputer confirmed the defacement and the uploaded file directly, but has not verified the source code, log or onion key claims. Treat all four as claims.

The log claim is the quiet one. Logs on a Tor hidden service can hold connection metadata, authentication records and operator mistakes, which is precisely what a deanonymization effort wants. The US State Department has offered up to $10 million through Rewards for Justice for information tying actors who hit US critical infrastructure, Clop named among them, to a foreign government. There is a standing market for that file.

Why Do the Onion Keys Matter?

Whoever holds the private key to a .onion address controls that address permanently, and there is no registrar to appeal to. A Tor v3 address is derived directly from an ed25519 public key under the Tor rendezvous specification. The name is the key. No ICANN, no transfer process, no takedown that moves it.

ShinyHunters spelled out the consequence: "We have their onion keys. So if they kick us out it wouldn't matter at all because we control the private keys to host the same exact onion URL." If that holds, Clop cannot evict its way out. It either abandons the address every victim and negotiator has bookmarked, or it shares that address with a hostile party and no visitor can know which gang they are talking to.

A dim server room aisle at night with one rack cabinet door standing ajar and keys left hanging in its lock, lit by blue equipment status lights

Why Is the "Who Paid" List the Real Threat?

Because it moves the damage onto companies that were already victims. Clop ran the Oracle campaign on CVE-2025-61882, a CVSS 9.8 unauthenticated remote code execution flaw that CISA added to its Known Exploited Vulnerabilities catalog on October 6, 2025 and the UK's NCSC flagged as actively exploited. Google's threat intelligence team put the compromised count above 100 organizations; Clop listed 29, among them Harvard University, The Washington Post, Logitech and Envoy Air. We covered it when Michelin turned up as a victim and again when MSG notified 131,000 people months later.

Now the regulatory arithmetic. SEC staff guidance from June 2024 is explicit that a registrant must still assess materiality and file under Item 1.05 of Form 8-K even when it pays and the incident ends before disclosure. Paying does not switch the obligation off. The SEC's compliance and disclosure interpretations say so at question 104B.06. An itemized payer list with amounts and wallet addresses would work as an external audit of who filed and who did not, cross checkable on chain by anyone with a browser.

Most coverage frames this as gang drama. The exposure is not evenly distributed: Clop risks embarrassment and a new address, while a public company that quietly paid and never filed risks an enforcement inquiry, a securities class action and a permanent slot on every crew's "pays quickly" list. One more figure. ShinyHunters told The Record the demand equals 2.333% of Clop's net worth, which puts implied Clop holdings between roughly $429 million and $4.3 billion depending on where in the eight figure range the number sits. That is the first time one of these groups has publicly priced another's balance sheet.

Why Email Users Should Care

Both gangs reach victims the way you get reached: through a message. Clop paired server side exploitation with extortion mail sent straight to named executives starting September 29, 2025. ShinyHunters barely uses exploits at all. Its Salesforce run through 2025 and 2026 was built on phished and vished credentials, which is how it walked into Brinks Home through a single phone call and ended up claiming 284 million McKesson patient records.

The output end matters more if you are not defending a network. Every one of these breaches converts into the same commodity: a verified email address attached to a real name, an employer and a purchase history. That file gets sold, merged with older dumps and loaded into automated campaigns, which is how ShinyHunters leaks began feeding a $2,000 sextortion email scam earlier this year. You never had an account with Clop. You still get the mail. And data held for negotiated deletion by one crew is now data held by two.

What Should Security and Legal Teams Do Now?

If you ran Oracle E-Business Suite in late 2025, treat this week as a disclosure readiness drill:

  • Reconstruct the file. Pull the incident timeline, the materiality determination and any payment records for the Oracle EBS window. If a payer list drops, you want your own version first.
  • Verify the patch state. Confirm CVE-2025-61882 remediation across every instance from 12.2.3 through 12.2.14, including forgotten test and vendor managed ones. Oracle's security alert is the authoritative patch reference.
  • Re examine anything negotiated with Clop. Deletion assurances are worth less than they were a week ago. Talk to counsel before assuming an old agreement still constrains the data.
  • Harden identity, not just the perimeter. The ShinyHunters half of this story is help desk social engineering, the pattern behind the Oracle PeopleSoft zero day campaign. Require callback verification for credential and MFA resets, and warn executives to expect impersonation of both gangs while this runs.

Looking Ahead

The likeliest outcome is that no payment happens and ShinyHunters publishes something. Whether that is a real payer ledger or a padded one is the open question, and the padded version may be worse for victims: a fabricated entry does the same damage in a headline and is harder to refute. Watch whether Clop's site returns at the same .onion address, whether the /var/log material surfaces in a law enforcement action, and whether the payer list appears at all. That last one turns a squabble between two criminal groups into a compliance event for a hundred real companies. BleepingComputer's Clop coverage will confirm it first.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.