Cyber & AI intelligence
Wasteland.
Briefs indexed2769
Issues28
Published Mondays07:30 CT
▣ Breach CLOP-LEAK-SITE 2026-09-20

Clop Ransomware: ShinyHunters Breach and Deface Rival Gang's Leak Site

"The Clop ransomware operation, fresh off a mass-exploitation campaign that named between 40 and 50-plus corporate victims, has itself been breached. BleepingComputer reports that the ShinyHunters extortion crew…"

The Clop ransomware operation, fresh off a mass-exploitation campaign that named between 40 and 50-plus corporate victims, has itself been breached. BleepingComputer reports that the ShinyHunters extortion crew compromised Clop's Tor-based data leak site starting Friday night, defaced it, and claims to have exfiltrated server data including source code, Grav CMS plugins, system logs, and the private keys for Clop's onion service. ShinyHunters is now threatening to extort the extortionists. The defacement was independently verified by BleepingComputer, which confirmed it could download the attacker-planted file directly from Clop's own Tor infrastructure. The data-theft and private-key claims rest solely on ShinyHunters' word and remain unverified.

What Happened

The intrusion began with a probe rather than a bang. According to BleepingComputer's reporting, ShinyHunters exploited what they describe as an unauthenticated file upload vulnerability in Grav CMS, the flat-file content management system running Clop's leak site, and used it to drop a small text file onto the server.

The contents were less a ransom note than a taunt: "THIS SITE HAS BEEN PWN3D BY SHINYHUNTERES #Skids10p - Maybe don't try to threaten us next time," alongside a link to ShinyHunters' own leak site. BleepingComputer verified the file was live on Clop's server and downloadable from the gang's Tor site, making this one of the rare underground claims with contemporaneous third-party confirmation.

Several hours later, ShinyHunters escalated, telling BleepingComputer they had "completely defaced" the site. The leak site was replaced with ASCII art of Umbreon, the Pokémon that serves as ShinyHunters' logo, a link to the group's Tor site, and the line "rooting your systems since '19 ;)". At the time of BleepingComputer's writing, the defaced page was still being served from Clop's own infrastructure, per ShinyHunters.

The "maybe don't try to threaten us next time" framing suggests retaliation for prior friction between the two operations, though neither the specifics nor any Clop response have been publicly documented.

What Was Taken

ShinyHunters told BleepingComputer it obtained "full access" to the server and stole source code, Grav CMS plugins, system logs, and other data, adding that they were "still downloading and reviewing them." The group additionally claims to have taken the private keys for Clop's onion service.

That last item, if true, is the one that matters. Onion service private keys are what bind a .onion address to a specific server. Whoever holds them can stand up an impostor site at Clop's exact address, indistinguishable from the real one to any visitor, including victims arriving to negotiate.

Two caveats belong on all of this. First, no volume figures have been published: ShinyHunters has not quantified the haul, and no independent party has reviewed it. Second, the only externally corroborated element is the defacement itself. The source code theft, the log access, the private keys, and the extortion threat are single-sourced to the attackers and relayed by BleepingComputer without independent verification. Treat them accordingly.

Why It Matters

The timing is the story. Clop spent August riding one of its largest campaigns in years, and the victim count varies meaningfully by source: SecurityWeek and InfoSecBulletin both put it at "more than 40" organizations, DataBreaches.Net (relaying Tiffany Wang's reporting) says "more than 40 firms," TechTicker describes "close to 50," and CPO Magazine claims "more than 50." The named victims include Shell, General Electric, Philips, Fiserv, Zebra, Mindray, Largan Precision, and ToastTab.

Being knocked offline by a rival mid-campaign carries real operational cost. Clop's extortion model depends on the leak site functioning as a credible countdown clock; a defaced site undermines the threat. Notably, DataBreaches.Net observed that GE had already been removed from Clop's leak site, the usual signal that a victim has opened negotiations, which illustrates how much the site's status functions as live business infrastructure.

For defenders, there are two takeaways. Any organization currently listed on or negotiating with Clop should assume the site's integrity is compromised and that communications routed through it may be observed or impersonated by a third party. More broadly, the stolen server data, if it exists as described, could include operational artifacts of genuine intelligence value: affiliate infrastructure, logs, tooling, victim lists. Whether any of that surfaces publicly is unknown.

The Attack Technique

Clop was undone by the same class of flaw it has built a business on: an unauthenticated vulnerability in an internet-facing web application. ShinyHunters claims an unauthenticated file upload bug in Grav CMS. Grav is a flat-file PHP CMS, and an unauthenticated write primitive against a PHP application is typically a short path to code execution.

The irony is sharpened by what Clop was doing weeks earlier. Its August campaign exploited CVE-2026-12569 in PTC Windchill and FlexPLM, described by SecurityWeek and InfoSecBulletin as an improper input validation flaw enabling unauthenticated remote code execution. Severity ratings differ across sources: CPO Magazine cites CVSS v3 9.8 and characterizes the root cause as deserialization of untrusted data, while ReliaQuest cites CVSS 9.3. TechTicker and CPO Magazine both describe the exploit as a chain, pairing a pre-authentication information disclosure issue in the FlexPLM WSDL endpoint with a flaw in Windchill's login servlet. PTC shipped fixes on June 17; CISA added the CVE to its KEV catalog on June 26 with a federal patch deadline. SecurityWeek notes this is the first Windchill vulnerability ever exploited in the wild, and that German police reportedly warned organizations of imminent attacks.

ReliaQuest's analysis of the post-exploitation tooling is the most technically detailed account available. Clop deployed a custom web shell that ReliaQuest characterizes as a fully equipped extortion platform rather than a generic command shell: it maps sensitive vault data, decrypts every credential in the Windchill keystore, and includes a custom Java class loader permitting arbitrary code execution inside the application process, extending the shell into an open-ended backdoor for lateral movement, ransomware deployment, or persistence. CPO Magazine reports hex-named JSP web shells at the path pattern /Windchill/login/[0-9a-f]{16}.jsp. Per Ransom-ISAC's Brandon Parsons, cited by TechTicker, the campaign began on or around July 20, with extortion emails sent to employees at affected organizations from randomly compromised accounts, an approach Parsons described as consistent with the prior Oracle EBS campaign apart from the new email addresses.

Claimed exfiltration volumes, all from CPO Magazine and all attributed to Clop itself: 391 GB from General Electric, 89 GB from Shell, and 13.5 GB from Philips. The Shell figure is corroborated by BleepingComputer, which reported the same 89 GB claim. None of these numbers have been confirmed by the victims.

Corporate responses have been consistent and narrow. Philips told Reuters it "identified and contained an attempted cybersecurity compromise of a specific enterprise server related to internal data" with "no impact on customer environments." GE said it was aware of the claim and "working to assess the potential issue," and per TechTicker, that it had "initiated our cyber response protocols." Shell confirmed awareness of "a potential incident" and said it was working with security teams and relevant experts. TechTicker notes that none of the three named Clop specifically. DataBreaches.Net reports that Philips, Fiserv, and ToastTab all said no customer data was affected.

What Organizations Should Do

Patch CVE-2026-12569 immediately if you run PTC Windchill or FlexPLM. Fixes have been available since June 17 and the flaw is in CISA's KEV catalog. PTC reports over 30,000 customers globally, including more than 1,500 brand and retail customers on FlexPLM, across aerospace, defense, automotive, heavy machinery, retail, and medtech.

Rotate every credential in the Windchill keystore on any server suspected of compromise. This is ReliaQuest's explicit guidance: the web shell decrypts the full keystore, so patching alone leaves harvested credentials valid. Treat the keystore as fully exposed, not selectively so.

Hunt for JSP web shells in Windchill codebase directories. Look for anomalous JSP files, with particular attention to the 16-character hex naming pattern under /Windchill/login/ reported by CPO Magazine. Absence of that specific pattern does not rule out compromise; the naming is a lead, not a signature.

Review access logs back to at least mid-July. Ransom-ISAC dates campaign activity to around July 20, and PTC advised customers to audit access logs when it shipped the fix. Dwell time between exploitation and public victim listing ran several weeks.

Treat extortion emails from known-good internal or partner addresses as plausible. Clop sent extortion messages from compromised third-party accounts, which means sender reputation and domain authentication will not flag them. Brief incident response and executive staff accordingly.

If you are currently listed on or negotiating with Clop, stop and reassess the channel. With the leak site defaced and onion private keys claimed stolen by a third party, any communication through that infrastructure should be assumed observable or impersonable. Route legal and negotiation activity through counsel and a retained IR firm rather than the leak site.

Sources: ShinyHunters hacks Clop leak site, threatens to extort ransomware gang | Philips and GE investigating Clop ransomware data theft claims | Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill ... | Clop Claims Data Theft From More Than 40 Companies - DataBreaches.Net | Clop Ransomware Gang Breaches 50+ Organizations, Including GE, Phil... | Clop Returns with Custom Implant in Mass-Extortion Campaign | Multiple organisations investigating fresh wave of Cl0p breaches T... | Cl0p Ransomware Listed 40+ Victims of PTC Windchill Campaign - Info...