ShinyHunters defaces Clop's ransomware leak site and demands talks
The ShinyHunters extortion crew has taken over the Clop ransomware gang's own Tor leak site, replaced the page with ASCII art and says it now intends to extort the extortionists.

Ransomware gangs spend their working lives inside other people's networks. On Friday night, someone returned the favour. The ShinyHunters extortion crew broke into the leak site that the Clop ransomware operation uses to shame its victims, defaced it, and is now threatening to extort the extortionists.
What happened to Clop's leak site
According to BleepingComputer, which saw the attack unfold and confirmed key parts of it independently, ShinyHunters began by abusing what it says is an unauthenticated file upload flaw in the Grav content management system that Clop's Tor site runs on. The first move was small: a plain text file dropped onto the server reading 'THIS SITE HAS BEEN PWN3D BY SHINYHUNTERES #Skids10p - Maybe don't try to threaten us next time,' and carrying a link to the gang's own leak site. BleepingComputer verified that the file could be downloaded directly from Clop's onion service. Hours later the site itself was gone, replaced with ASCII art of Umbreon, the Pokémon the group uses as its logo, the line 'rooting your systems since '19 ;)' and another link to the ShinyHunters site.
What ShinyHunters says it took
The gang told BleepingComputer it had gained full access to the server and walked off with source code, Grav CMS plugins, system logs and 'other things', and that it was still downloading and reviewing the haul. It also claims to hold the private keys for Clop's Tor onion address, which would let it run a site at the same address from hardware it controls. The logs matter because /var/log can hold authentication records and the IP addresses of everyone who connected to the site. ShinyHunters says it will post a message giving Clop 72 hours to get in touch, and when BleepingComputer asked what it planned to do with the data, the reply was four words: 'Going to extort them.' None of those claims has been independently verified, and the security researcher VXDB noted that the Umbreon artwork is identical to the one used in the August 2020 defacement of HackForums, which ShinyHunters also claimed at the time.
The feud behind the defacement
ShinyHunters frames the attack as payback. It says the dispute goes back to Clop's 2025 data theft campaign against Oracle E-Business Suite customers, in which Clop exploited vulnerabilities including the zero-day CVE-2025-61882. ShinyHunters, then operating inside a loose collective calling itself Scattered Lapsus$ Hunters, leaked a proof-of-concept exploit that Oracle later confirmed matched one used in the Clop attacks, and said at the time that the code had originally been its own. Tensions escalated from there: ShinyHunters says a Clop representative messaged it directly with a threat it translates as 'I have more money than you and all of your people combined, I'll kill you soon'. BleepingComputer has not verified that account and has asked Clop to respond.
Our opinion
There is a temptation to enjoy this one as a sport - two criminal enterprises discovering that the tools they built to terrorise hospitals and universities work just as well on each other - and that temptation should be resisted, because the actual victims of that Oracle campaign did not get their data back when Clop's website was overwritten with a cartoon umbrella-eared Pokémon. What the defacement does show is how thin the operational security of these groups really is: an unpatched upload handler in a content management system, on a server holding stolen records and visitor logs, sitting behind nothing more than a Tor address that anybody can resolve. The interesting detail for defenders is not the ASCII art but the claim about the onion keys, because if a rival crew really can hold a gang's address hostage, then the leak site stops being a marketplace and becomes just another unpatched web application with a reputation it can lose. None of that is justice. It is only the same negligence, pointed the other way.