Cyber & AI intelligence
Wasteland.
Briefs indexed2940
Issues30
Published Mondays07:30 CT
▣ Breach SHINYHUNTERS-CLOP- 2026-09-30

Clop: Leak Site Hijacked by ShinyHunters in Rival Extortion Play

"The ShinyHunters extortion crew broke into the Tor data leak site of the Clop (Cl0p) ransomware operation on the night of September 18, 2026, and defaced it. It then turned its usual extortion playbook on the ransomware…"

The ShinyHunters extortion crew broke into the Tor data leak site of the Clop (Cl0p) ransomware operation on the night of September 18, 2026, and defaced it. It then turned its usual extortion playbook on the ransomware gang itself. BleepingComputer confirmed that a ShinyHunters file was being served from Clop's own infrastructure, and it later saw the full defacement. Other reports put ShinyHunters' demand at eight figures (more than $10M). The ransom note posted on the hijacked site does not name a figure. Instead it demands "all the money you made off the EBS campaign plus more AND WITH INTEREST," plus a public apology, and it says the demand grows every 24 hours. According to a later report, Clop reappeared at a new onion address on September 25. That suggests it had given up on the old server. Clop has not made a statement, no law enforcement agency has confirmed anything, and no forensic report has been published. ShinyHunters' claims that it stole data and the site's onion private keys have not been verified.

What Happened

What Was Taken

Everything below comes from ShinyHunters' own claims. None of it has been independently verified.

For the separate FBI claim: ShinyHunters says it took 2 to 3 TB of data (SOCRadar) covering "almost ALL FBI Agents" and job applicants. 404 Media reviewed a sample of about 5,000 records containing names, addresses, phone numbers and details about spouses. Reuters partially verified sample data that included names, home addresses, Social Security numbers and assignments. None of this establishes the full volume ShinyHunters claims.

Why It Matters

Clop is one of the most prolific mass-exploitation crews in operation. Anomali lists its record: GoAnywhere MFT (CVE-2023-0669, about 130 victims in 10 days), MOVEit Transfer (CVE-2023-34362), and the December 2025 University of Phoenix breach affecting nearly 3.5 million people. Malwarebytes notes that Clop's recent PTC Windchill campaign named more than 40 alleged victims, including Shell, Philips, Fiserv and Toast. The ransom note refers to an "EBS campaign," which points to the group's Oracle E-Business Suite operations.

This matters to defenders for three reasons:

  1. Paying no longer guarantees silence. If ShinyHunters has Clop's payment and negotiation data, organizations that paid Clop could have their payments publicly exposed or be extorted a second time by a different group.
  2. It is harder to know who you are dealing with. If ShinyHunters has the onion keys, it could run Clop's old address, so victims cannot be sure who is behind a "Clop" portal or email. iSec News recommends that past Clop victims keep their historical communications and indicators in case someone impersonates Clop.
  3. ShinyHunters is escalating. In a single week the group says it hit a top-tier ransomware gang and the FBI. It frames both as defending its "business" and reputation, according to its spokesperson's comments to The Register. Malwarebytes also notes its earlier claim of 3.65 TB stolen from Instructure (Canvas LMS), covering about 9,000 institutions.

The Attack Technique

ShinyHunters says it got in through an unauthenticated file upload vulnerability in Grav CMS, the flat-file CMS behind Clop's leak site (BleepingComputer). Anomali says the technique appears consistent with CVE-2024-27921, a previously disclosed file-upload path traversal flaw in Grav, but it stresses that the exact CVE has not been confirmed. The sequence observed publicly was: arbitrary file write, then a proof-of-access text drop, then full replacement of the page. That is consistent with web-content write access. It does not prove root access to the server.

The FBI intrusion ShinyHunters claims used a different route: a claimed Oracle PeopleSoft zero-day on FBIJobs.gov, followed by movement into FBI-managed AWS GovCloud servers. The group names Human Resources, Criminal Justice and Medlink services. None of these details beyond the defacement of apply.fbijobs.gov have been publicly confirmed.

What Organizations Should Do

  1. If you were ever a Clop victim, and especially if you paid, assume your negotiation records, payment amounts and wallet addresses could be published. Brief legal, communications and executive teams now, and prepare holding statements.
  2. Verify anyone claiming to be Clop. Treat new contact from "Clop," whether at the old onion address or the reported new one, as possibly from an impersonator. Check it against your preserved chat logs, keys and identifiers before engaging, and work through your incident response firm and law enforcement.
  3. Keep your evidence. Retain past ransom notes, portal URLs, chat transcripts and IOCs from any Clop incident, as iSec News recommends. You may need them to spot re-extortion or impersonation.
  4. Patch the software Clop is known to exploit. Prioritize managed file transfer (GoAnywhere, MOVEit), Oracle E-Business Suite and PTC Windchill. Audit internet-facing Oracle PeopleSoft, given ShinyHunters' zero-day claim.
  5. Patch Grav CMS and any flat-file CMS you run. Make sure Grav is updated past CVE-2024-27921. Restrict or disable unauthenticated upload paths and alert on unexpected file writes to web roots.
  6. Plan for data-theft extortion, not only encryption. ShinyHunters steals data rather than deploying ransomware. Invest in egress monitoring, SaaS and cloud access logging, and controls on help desk and identity recovery.

Sources: ShinyHunters Hacks Clop's Leak Site, Demands 8 Figures #ransomware... | ShinyHunters hacks Clop leak site, threatens to extort ransomware gang | ShinyHunters tells The Reg: We hacked the FBI to 'protect our busin... | Hacking group purports to have stolen FBI data in cyber ... | ShinyHunters hacks rival extortion gang and takes over its dark web... | ShinyHunters breaches and defaces Clop leak site and claims onion k... | ShinyHunters' Breach of Clop and What It Reveals About the Ransomwa... | ShinyHunters Claims Access to FBI Systems