Get Your Free Report
Start for Free
SOCRadar® Cyber Intelligence Inc. | Clop Hack: ShinyHunters Hijacks Data Leak Site
Sep 21, 2026
7 Mins Read
Moon
Summarize with:

Clop Hack: ShinyHunters Hijacks Data Leak Site

ShinyHunters has turned the tables on rival cybercrime operation Clop (a.k.a. Cl0p), hijacking and defacing the ransomware gang’s own Dark Web leak site (DLS).

The Clop hack began on September 18, 2026, and quickly escalated from a small defacement into a public extortion attempt. ShinyHunters claims it also stole Clop’s source code, server logs, and Tor private keys, potentially giving it continued control over the gang’s onion address.

Clop's Dark Web leak site after ShinyHunters' defacement, showing the “Domain Seized” banner above Clop's original list of extortion targets.

Clop’s Dark Web leak site after ShinyHunters’ defacement, showing the “Domain Seized” banner above Clop’s original list of extortion targets.

How ShinyHunters Hacked Clop’s Leak Site

The intrusion reportedly began on September 18 when ShinyHunters exploited what it described as an unauthenticated file-upload vulnerability in Grav CMS, the content management system running Clop’s Tor site.

The group initially demonstrated its access by uploading a small text file containing a taunting message. Hours later, the compromise had developed into a full defacement displaying ShinyHunters branding, its Umbreon ASCII mascot, and a message boasting about its hacking activity.

ShinyHunters Claims It Stole Clop’s Tor Keys

ShinyHunters went further, claiming it obtained Clop’s source code, plugins, server logs, and private keys for the onion service. Possession of the relevant keys could potentially allow the group to reproduce the Tor address on infrastructure it controls.

The claimed theft of Clop’s internal data and keys has not been independently verified. Still, the visible defacement demonstrated that ShinyHunters had gained enough access to alter a site Clop normally uses to publish victims and apply extortion pressure.

Timeline of the ShinyHunters-Clop Dispute and Clop Hack

Date Event / Activity
July–September 2025 Researchers observe exploitation targeting Oracle EBS environments. By late September, organizations begin receiving extortion emails associated with Clop.
October 3–4, 2025 A Scattered Lapsus$ Hunters channel associated with ShinyHunters releases an Oracle EBS exploit while criticizing Clop. Oracle issues an emergency patch for CVE-2025-61882 on October 4. The exact relationship between the leaked exploit and the Oracle EBS exploit chains observed in the wild remains unclear.
September 18, 2026 ShinyHunters allegedly exploits the Grav CMS installation behind Clop’s leak site and uploads a taunting file.
September 19, 2026 The site is fully defaced. ShinyHunters claims it stole internal data and Tor private keys and gives Clop 72 hours to make contact.
September 20–21, 2026 ShinyHunters repeatedly updates the compromised page, adding new demands and a public countdown.
September 21, 2026 A message attributed to Clop appears on the site, reportedly attempting to reopen communications rather than addressing the demands publicly.

Why Did ShinyHunters Target Clop? The Oracle EBS Dispute

The recent Clop hack, as well as the broader conflict, appears to center on the mass exploitation of Oracle E-Business Suite in 2025.

Clop used previously unknown vulnerabilities to steal data from organizations running Oracle EBS before attempting to extort victims. Oracle subsequently disclosed CVE-2025-61882, a critical pre-authentication Remote Code Execution (RCE) vulnerability affecting EBS versions 12.2.3 through 12.2.14.

Around the same period, a channel associated with Scattered Lapsus$ Hunters released an Oracle EBS exploit and criticized Clop. ShinyHunters has since claimed that the exploit behind Clop’s campaign originally belonged to them and that the rival operation used it without permission.

That account remains ShinyHunters’ version of events rather than an established technical finding. Google Threat Intelligence Group reported that multiple exploit chains were involved in the Oracle campaign and said it lacked sufficient evidence to directly connect earlier observed activity with the publicly leaked exploit.

ShinyHunters also claims that someone associated with Clop later threatened its members, presenting the September 2026 takeover as retaliation.

The Takeover Turns Into an Extortion Attempt

After taking control of the site, ShinyHunters began posting increasingly aggressive messages directed at Clop. It initially demanded a payment described as 2.333% of its own claimed net worth, which it valued at an eight-figure sum, and imposed a 72-hour deadline.

The demands later expanded. ShinyHunters threatened to reveal information it claims to possess about Clop’s Oracle EBS campaign, including which victims paid ransoms, the amounts involved, and cryptocurrency wallets allegedly used to receive payments. These claims have not been independently substantiated.

ShinyHunters' September 21 update to Cl0p, escalating its demands on the hijacked leak site.

ShinyHunters’ September 21 update to Cl0p, escalating its demands on the hijacked leak site.

A subsequent message attributed to Clop appeared on the hijacked page, stating that the contact email supplied by ShinyHunters was not working and suggesting that communication resume through a previously used platform. The message did not publicly address the payment demands or the claims about stolen internal information.

The Clop leak site now only displays this message, with all prior content removed.

The Clop leak site now only displays this message, with all prior content removed.

Two Major Extortion Operations Turn on Each Other

ShinyHunters has operated since around 2019 and built its reputation through large-scale data theft and extortion. The name has more recently appeared alongside other loosely affiliated cybercrime identities under the Scattered Lapsus$ Hunters banner.

Threat actor card of ShinyHunters

Threat actor card of ShinyHunters

Clop has operated a Dark Web leak site since 2020 and is known for mass-exploitation campaigns targeting enterprise software. Its previous operations have targeted vulnerabilities in Accellion, GoAnywhere, MOVEit, and Oracle EBS, often using stolen data rather than file encryption as its primary extortion leverage.

Threat actor card of Cl0p

Threat actor card of Cl0p

Why Losing a Leak Site Matters

A leak site is more than a website for an extortion operation. It gives the group a public channel for naming victims, publishing stolen files, issuing deadlines, and increasing pressure on organizations to pay.

Losing control of that infrastructure, even temporarily, can disrupt operations and damage the credibility on which those threats depend. In this case, Clop’s own pressure mechanism was effectively repurposed against it.

The incident also raises questions about data obtained during previous Clop compromises. If ShinyHunters genuinely accessed internal logs, payment records, or other operational material, information related to past victims could potentially move between criminal actors or become public.

As of September 21, however, the extent of that access remains unverified.

Conclusion

The Clop hack is more than one cybercrime group defacing another’s website. ShinyHunters claims Clop took an Oracle EBS exploit that belonged to them, profited from the resulting campaign, and later threatened its members. Its current demand for all of Clop’s EBS proceeds, plus interest, makes the dispute look as much financial as personal.

Exploits, stolen data, access, and ransom proceeds all have value, but there is no trusted mechanism for settling disputes when one group believes another has taken what belongs to it.

That matters to past victims as well. If ShinyHunters really obtained Clop’s internal records, information from previous campaigns could end up in the hands of another group or be published as part of the dispute. Paying an extortion demand or disappearing from a leak site does not necessarily mean stolen data has reached the end of its lifecycle. Copies may remain with individual operators or pass to other groups, potentially resurfacing through another extortion attempt, a sale, or a public leak months or even years later.

If attacks on rival cybercrime infrastructure become a more common way of settling underground disputes, organizations could also face renewed exposure without suffering another breach themselves. The original intrusion may be over, but control of the stolen data can continue to change hands.