521/69 Tuesday, September 22, 2026
The extortion group ShinyHunters was observed compromising and defacing the Tor-based leak site operated by the Clop ransomware group, replacing its original content with ShinyHunters branding and a message for visitors. The incident was discovered by Hackread.com on September 19, 2026. Clop’s website displayed ASCII artwork associated with ShinyHunters, a link to the group’s website, and the message “rooting your systems since ’19 ;)”. Clop, also known as Cl0p, is a ransomware group that uses its Tor site to publish victim names and stolen data as part of its extortion activities. The incident is unusual because the target of the attack was another major cybercriminal group.
According to preliminary information, the attack may have begun on the night of Friday, September 18. ShinyHunters claimed that it discovered an unauthenticated file upload vulnerability in the Grav content management system used by Clop for its leak site, before the incident escalated into a complete website defacement. However, the visible defacement alone does not confirm how deeply the attackers gained access to the underlying server or whether they accessed or stole data from Clop’s infrastructure. Hackread.com stated that it contacted ShinyHunters for additional details regarding the access method, any data that may have been exfiltrated, and whether other systems were compromised, but had not received a response at the time of publication.
During the incident, ShinyHunters’ own onion website was also inaccessible for several hours, although it remains unclear whether the outage was related to the attack against Clop or was a separate issue. Even a temporary loss of control over Clop’s leak site could affect the group’s credibility and disrupt its primary channel for publishing victim data. Clop has been linked to several major data theft campaigns in recent years, often involving vulnerabilities in enterprise file transfer products. These include the 2023 MOVEit Transfer campaign exploiting CVE-2023-34362, which affected more than 2,000 organizations, as well as attacks involving GoAnywhere MFT, where Clop previously claimed to have stolen data from approximately 130 organizations within 10 days. At the time of the report, Clop’s leak site remained unavailable and continued to display the ShinyHunters defacement page.
Source: https://hackread.com/shinyhunters-hacks-defaces-clop-ransomware-leak-site/
