The ShinyHunters extortion crew broke into the Tor data leak site of the Clop (Cl0p) ransomware operation on the night of September 18, 2026, and defaced it. It then turned its usual extortion playbook on the ransomware gang itself. BleepingComputer confirmed that a ShinyHunters file was being served from Clop's own infrastructure, and it later saw the full defacement. Other reports put ShinyHunters' demand at eight figures (more than $10M). The ransom note posted on the hijacked site does not name a figure. Instead it demands "all the money you made off the EBS campaign plus more AND WITH INTEREST," plus a public apology, and it says the demand grows every 24 hours. According to a later report, Clop reappeared at a new onion address on September 25. That suggests it had given up on the old server. Clop has not made a statement, no law enforcement agency has confirmed anything, and no forensic report has been published. ShinyHunters' claims that it stole data and the site's onion private keys have not been verified.
What Happened
- The attack began on the night of Friday, September 18. BleepingComputer's report of September 19 says the attack started "Friday night." Anomali places the defacement on the evening of September 18. iSec News dates the observed defacement to September 19. The difference comes down to when it started versus when it was first reported.
- First, a test file. According to BleepingComputer, ShinyHunters first uploaded a small text file reading "THIS SITE HAS BEEN PWN3D BY SHINYHUNTERES #Skids10p - Maybe don't try to threaten us next time." The file linked to ShinyHunters' own leak site. BleepingComputer confirmed the file could be downloaded directly from Clop's Tor site.
- Then, the full defacement. Several hours later the leak site was replaced with ASCII art of Umbreon, the Pokémon ShinyHunters uses as its logo, and the line "rooting your systems since '19 ;)". Malwarebytes reported on September 21 that the page had a "Domain seized by ShinyHunters" banner and a "Note to Cl0p" that mirrored ShinyHunters' own leak site.
- The demands got bigger over time. The note quoted by Malwarebytes started on September 19 with an ultimatum for Clop to make contact. On September 20 it named alleged Clop figures ("Likhogray & Tarasov" and "j0nny") and set a 66-hour countdown. It threatened to publish which companies paid Clop, how much they paid, and to which Bitcoin addresses. By September 21 it added a mandatory public apology, and the author claimed to be "3-0" against Clop.
- Clop moved to a new address. National Cyber Security Consulting, citing Cybersecurity Insiders, reports that Clop came back at a new Tor onion address on September 25. It reads the move as a tacit admission that the old infrastructure was lost. This comes from a single OTHER-tier source and should be treated as reported, not confirmed.
- The same week, ShinyHunters claimed a breach of the FBI. SOCRadar reports that ShinyHunters says it breached FBIJobs.gov on September 21 through an Oracle PeopleSoft zero-day. Reuters, via ABC, reported that ShinyHunters said it went after the FBI because of a May 2026 bureau advisory telling victims not to pay the group. The Register reported on September 25 that the FBI had "confirmed the breach." The FBI statement The Register quotes is more cautious, though: it says "the point of breach is still undetermined," whether that is a third party or the FBI's own systems. SOCRadar says the FBI has not confirmed the scope ShinyHunters claims. So the accounts differ on how far the FBI's confirmation goes.
What Was Taken
Everything below comes from ShinyHunters' own claims. None of it has been independently verified.
- Server data. ShinyHunters told BleepingComputer it had "full access" and took source code, Grav CMS plugins, system logs and "other things," and that it was "still downloading and reviewing them."
- Onion service private keys. ShinyHunters says it holds the private keys for Clop's onion service. With those keys it could run Clop's old address even after Clop took the host back. iSec News cites an analysis by Parminder Kumar Sharma: the defacement proves write access to web content, but no cryptographic proof of key possession, root access or database dumps has been published.
- Victim payment records (threatened). The ransom note threatens to publish the companies that paid Clop, how much they paid and to which Bitcoin addresses. Anomali warns that if ShinyHunters has Clop's negotiation records, past Clop victims could be exposed to a second adversary.
For the separate FBI claim: ShinyHunters says it took 2 to 3 TB of data (SOCRadar) covering "almost ALL FBI Agents" and job applicants. 404 Media reviewed a sample of about 5,000 records containing names, addresses, phone numbers and details about spouses. Reuters partially verified sample data that included names, home addresses, Social Security numbers and assignments. None of this establishes the full volume ShinyHunters claims.
Why It Matters
Clop is one of the most prolific mass-exploitation crews in operation. Anomali lists its record: GoAnywhere MFT (CVE-2023-0669, about 130 victims in 10 days), MOVEit Transfer (CVE-2023-34362), and the December 2025 University of Phoenix breach affecting nearly 3.5 million people. Malwarebytes notes that Clop's recent PTC Windchill campaign named more than 40 alleged victims, including Shell, Philips, Fiserv and Toast. The ransom note refers to an "EBS campaign," which points to the group's Oracle E-Business Suite operations.
This matters to defenders for three reasons:
- Paying no longer guarantees silence. If ShinyHunters has Clop's payment and negotiation data, organizations that paid Clop could have their payments publicly exposed or be extorted a second time by a different group.
- It is harder to know who you are dealing with. If ShinyHunters has the onion keys, it could run Clop's old address, so victims cannot be sure who is behind a "Clop" portal or email. iSec News recommends that past Clop victims keep their historical communications and indicators in case someone impersonates Clop.
- ShinyHunters is escalating. In a single week the group says it hit a top-tier ransomware gang and the FBI. It frames both as defending its "business" and reputation, according to its spokesperson's comments to The Register. Malwarebytes also notes its earlier claim of 3.65 TB stolen from Instructure (Canvas LMS), covering about 9,000 institutions.
The Attack Technique
ShinyHunters says it got in through an unauthenticated file upload vulnerability in Grav CMS, the flat-file CMS behind Clop's leak site (BleepingComputer). Anomali says the technique appears consistent with CVE-2024-27921, a previously disclosed file-upload path traversal flaw in Grav, but it stresses that the exact CVE has not been confirmed. The sequence observed publicly was: arbitrary file write, then a proof-of-access text drop, then full replacement of the page. That is consistent with web-content write access. It does not prove root access to the server.
The FBI intrusion ShinyHunters claims used a different route: a claimed Oracle PeopleSoft zero-day on FBIJobs.gov, followed by movement into FBI-managed AWS GovCloud servers. The group names Human Resources, Criminal Justice and Medlink services. None of these details beyond the defacement of apply.fbijobs.gov have been publicly confirmed.
What Organizations Should Do
- If you were ever a Clop victim, and especially if you paid, assume your negotiation records, payment amounts and wallet addresses could be published. Brief legal, communications and executive teams now, and prepare holding statements.
- Verify anyone claiming to be Clop. Treat new contact from "Clop," whether at the old onion address or the reported new one, as possibly from an impersonator. Check it against your preserved chat logs, keys and identifiers before engaging, and work through your incident response firm and law enforcement.
- Keep your evidence. Retain past ransom notes, portal URLs, chat transcripts and IOCs from any Clop incident, as iSec News recommends. You may need them to spot re-extortion or impersonation.
- Patch the software Clop is known to exploit. Prioritize managed file transfer (GoAnywhere, MOVEit), Oracle E-Business Suite and PTC Windchill. Audit internet-facing Oracle PeopleSoft, given ShinyHunters' zero-day claim.
- Patch Grav CMS and any flat-file CMS you run. Make sure Grav is updated past CVE-2024-27921. Restrict or disable unauthenticated upload paths and alert on unexpected file writes to web roots.
- Plan for data-theft extortion, not only encryption. ShinyHunters steals data rather than deploying ransomware. Invest in egress monitoring, SaaS and cloud access logging, and controls on help desk and identity recovery.
Sources: ShinyHunters Hacks Clop's Leak Site, Demands 8 Figures #ransomware... | ShinyHunters hacks Clop leak site, threatens to extort ransomware gang | ShinyHunters tells The Reg: We hacked the FBI to 'protect our busin... | Hacking group purports to have stolen FBI data in cyber ... | ShinyHunters hacks rival extortion gang and takes over its dark web... | ShinyHunters breaches and defaces Clop leak site and claims onion k... | ShinyHunters' Breach of Clop and What It Reveals About the Ransomwa... | ShinyHunters Claims Access to FBI Systems