ShinyHunters allegedly breached and defaced the Tor-based data-leak site of the Clop/Cl0p ransomware operation following a dispute between the cybercrime groups. The group said it exploited an unauthenticated file-upload flaw in Grav CMS, first placing a taunting text file on the site and then replacing it with an Umbreon-themed defacement page.
ShinyHunters claimed it obtained full server access and stole Clop source code, Grav CMS plugins, logs, server data, and private keys for the operation's onion service. It has threatened to extort Clop using the purportedly stolen material; however, the asserted access and data theft have not been independently verified. The conflict is reportedly tied to Clop's alleged threats and its 2025 Oracle E-Business Suite extortion campaign involving CVE-2025-61882.

TTPs, infrastructure, and targeting history in one profile.
15 events from the most recent confirmed update back to the earliest known activity.
A message attributed to Clop appeared on the compromised leak site stating that ShinyHunters' supplied contact email did not work and proposing renewed communication through a previously used platform. The message did not address the payment demands or theft claims, and the site reportedly displayed only this message after prior content was removed.
ShinyHunters said its demand against Clop would increase every 24 hours until Clop responded. The group also expanded its demand to all proceeds allegedly earned from Clop's Oracle E-Business Suite campaign, plus additional money and interest.
Hackread observed that visitors to Clop's compromised onion address could download Salesforce-related data that ShinyHunters had also published through its own leak site. The reference does not establish the data's provenance or identify affected organizations.
ShinyHunters allegedly began compromising Clop/Cl0p's Tor-hosted data-leak site by exploiting an unauthenticated file-upload vulnerability in Grav CMS.
Clop exploited multiple Oracle E-Business Suite vulnerabilities, including zero-day CVE-2025-61882, to steal organizational data as part of an extortion campaign.
Clop reportedly began exploiting the Oracle E-Business Suite zero-day CVE-2025-61882 in August 2025, later using the campaign to send mass extortion emails to executives at dozens of companies.
ShinyHunters previously claimed responsibility for a HackForums defacement whose Umbreon-themed artwork was later reported to match the artwork used on Clop's leak-site defacement.
After ShinyHunters' defacement, Clop's darknet site displayed a short Russian-language message translated as “Relax, we are working on it.” Clop's data-leak site was reportedly unavailable and returned timeouts at the time of reporting.
ShinyHunters demanded an eight-figure payment and a public apology from Clop, and threatened to disclose companies that allegedly paid Clop during its Oracle EBS campaign, including alleged payment amounts and Bitcoin addresses.
ShinyHunters said it was reviewing the allegedly stolen data and intended to extort Clop, reportedly in retaliation for alleged identification and violent threats by a Clop representative. The group said it would direct Clop to make contact within 72 hours through a message on its own leak site.
ShinyHunters claimed it obtained full server access and stole source code, Grav CMS plugins, logs, other server data, and private keys for Clop's onion service. These theft claims were not independently verified.
ShinyHunters replaced Clop's leak site with an Umbreon-themed ASCII-art defacement page linking to its own Tor site. The defacement was independently verified.
ShinyHunters uploaded a text file warning Clop not to threaten the group and linking to ShinyHunters' leak site. The file was independently confirmed as downloadable from Clop's Tor site.
Threat actors calling themselves Scattered Lapsus$ Hunters, including ShinyHunters, released a proof-of-concept exploit that Oracle later confirmed matched one used in Clop's Oracle E-Business Suite attacks.
The Clop Oracle E-Business Suite zero-day campaign was reported to have victimized more than 100 organizations worldwide. Reported victims included Harvard University, the University of Phoenix, The Washington Post, Schneider Electric, Broadcom, Estée Lauder Companies, Cox Enterprises, Abbott, and Humana.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
20 references tracked. Mallory keeps watching after this page renders.
securitymagazine.com
Open sourceteiss.co.uk
Open sourceitpro.com
Open sourceheise.de
Open sourcecyberveille.ch
Open sourcehackread.com
Open sourcemalware.news
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.