ShinyHunters Hijacks Cl0p's Dark Web Leak Site
Security / news
ShinyHunters Hijacks Cl0p's Dark Web Leak Site
The group broke in through an unpatched file-upload bug in the ransomware gang's own site software and is threatening to publish the names of Cl0p's paying victims.
ShinyHunters defaced the ransomware gang Cl0p's dark web leak site on Friday, Sept. 18, and by Monday was demanding an eight-figure ransom of its own.
BleepingComputer's Lawrence Abrams first reported the hijack Sept. 19, and Recorded Future News reporter Alexander Martin followed Sept. 21 with the exact wording of the ransom note. Both describe the same sequence: a rival extortion crew took over the Tor site Cl0p has used for years to name and pressure its own victims, then turned the same tactic on Cl0p.
How ShinyHunters got in
ShinyHunters says it used an unauthenticated file-upload vulnerability in Grav CMS, the software running Cl0p's leak site, to plant a text file reading "THIS SITE HAS BEEN PWN3D BY SHINYHUNTERES #Skids10p," according to BleepingComputer's reporting. The group later replaced the entire page with ASCII art of the Pokemon Umbreon and the line "rooting your systems since '19," alongside a link to its own leak platform.
ShinyHunters claims it pulled Cl0p's source code, the site's Grav plugins, system logs from /var/log, and the private keys to Cl0p's Tor onion service, which would let it keep serving content at the same .onion address even if Cl0p regains control of the server. Neither BleepingComputer nor The Record has independently verified that the keys are genuine.
The price: 2.333% of a number nobody can check
The Record published the ransom note in full: "I hope you can pay that much because that is the demand, negotiable. Get your bosses in front of the white board in the war room. Clock is ticking moron." ShinyHunters set the figure at 2.333% of what it calls Cl0p's total net worth, a number with no public source, and said it would raise the demand every 24 hours Cl0p failed to respond. By Sept. 21 the group had added a second condition: a public apology.
ShinyHunters is also threatening to publish which companies paid Cl0p, how much, and the Bitcoin addresses the payments moved through, information that would normally surface only through law-enforcement seizures or leaked negotiation transcripts.
A feud that started with an Oracle zero-day
The two groups' history goes back to October 2025, when Cl0p ran a mass-exploitation campaign against an Oracle E-Business Suite flaw. ShinyHunters, operating that month under the name Scattered Lapsus$ Hunters, says it had already published a working proof of concept for the same bug and accuses Cl0p of copying it rather than finding it independently. ShinyHunters also alleges a Cl0p representative later threatened the group in Russian, claiming greater financial resources and an ability to respond with violence. Oracle itself has kept shipping patches for unrelated flaws in the same product line: six flaws in its September update carried the maximum 10.0 CVSS score, a reminder of how often its enterprise software shows up on both sides of this kind of dispute.
What Cl0p says now
Cl0p answered on Sept. 21, using the site ShinyHunters still controls: "Shiny Hunters we trying to reach you. Your email does not work." That is the only public response from Cl0p so far, and it does not address the ransom demand, the apology condition, or the claim that its onion keys are compromised.
The episode inverts the incentive that usually drives a breached company to get ahead of a leak site, the same incentive that led Mathspace to notify 1.08 million students, parents and staff about a breach on its own terms rather than waiting to be named. Cl0p has no comparable option: it cannot disclose on its own terms, because the site it would disclose through belongs, for now, to the group extorting it.
| Date | Event |
|---|---|
| October 2025 | Cl0p exploits an Oracle E-Business Suite zero-day ShinyHunters says it published first |
| Friday, Sept. 18, 2026 | ShinyHunters defaces Cl0p's Tor leak site via a Grav CMS upload flaw |
| Saturday, Sept. 19, 2026 | BleepingComputer is first to report the hijack |
| Monday, Sept. 21, 2026 | ShinyHunters adds a public-apology demand; Cl0p replies on the hijacked site |
Sources
More in Security
- 01CISA Gives Agencies 3 Days to Patch an Exploited SharePoint BugMicrosoft rated the flaw a low-risk spoofing issue for 16 days after patching it, and a honeypot logged the first attack four weeks after the correction upgraded it to an 8.8.
- 02CISA Adds a Fourth MikroTrick Bug to Its Exploited ListCVE-2026-67279 joins two other bugs from the same six-flaw MikroTik batch already on CISA's list, but Bishop Fox says it, not the pair flagged in September, is the one that actually opens the door.
- 03OpenClaw's New Scanners Agree on Just 0.69% of Risky SkillsFour audits since February have counted between 341 and 1,467 malicious or flawed skills on ClawHub, and NVIDIA's scanner disagrees with the other two on all but 468 of 67,453 skills checked.
- 04CISA Lists 14 Botslab Dashcam Flaws With No Fix in SightThe worst of the bugs lets a network attacker push firmware with no cryptographic signature onto the device, and Botslab has not told CISA whether it plans to fix any of the 14.