ShinyHunters hacks Clop ransomware gang and threatens to extort it
Hackers hack the hackers

Mystery man in silhouette red with binary code background. Kmatta/Getty.
- ShinyHunters defaced Clop’s Tor leak site and added its own branding and messages.
- The group claims it stole source code, system logs, plugins, and Tor onion service keys.
- ShinyHunters says it plans to give Clop 72 hours to respond to an extortion message.
- The attack appears linked to a dispute over Clop’s Oracle E-Business Suite data theft campaign.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
You might think hackers would be immune to getting hacked themselves – but ShinyHunters’ latest attack on Clop’s data leak site proves otherwise. The gang defaced Clop’s Tor site, allegedly stole server data, and is now threatening to extort the ransomware group.
ShinyHunters claims to have exploited an unauthenticated file upload vulnerability in Grav CMS to compromise the Clop data leak site.
They then uploaded a message warning Clop not to threaten them: "THIS SITE HAS BEEN PWN3D BY SHINYHUNTERES #Skids10p - Maybe don't try to threaten us next time.” The uploaded file also contained a link to ShinyHunters’ data leak platform.
The gang told BleepingComputer that it had "completely defaced" the Clop site. A later visit to the website showed that it had been taken over by ShinyHunters branding, featuring an ASCII depiction of the Pokémon Umbreon (the gang’s logo) alongside a link to the group’s own Tor site. The page also included a message: "rooting your systems since '19 ;)".
The defaced content was still present during the latest report.
ShinyHunters said it had gained "full access" to the server and extracted source code, Grav CMS plugins, system logs, and other information.
"The data we stole includes source codes, gravCMS plugins, and other things. We are still downloading and reviewing them," ShinyHunters told BleepingComputer.
The hackers also claim to have stolen all files stored in the server’s /var/log directory, which could include records of system activity, authentication logs, and IP addresses associated with connections to the server. On top of that, the gang claims to have obtained the private keys for Clop’s Tor onion service.
"We have their onion keys. So if they kick us out it wouldn't matter at all because we control the private keys to host the same exact onion URL," the group said.
ShinyHunters said it was reviewing the obtained data and plans to post an extortion message on its site, giving Clop 72 hours to contact the group.
According to the gang, the attack came in response to threats of violence and threats to identify group members allegedly made by a Clop representative during a dispute over Clop’s 2025 Oracle E-Business Suite data theft campaign.
"During the Oracle EBS campaign they ran and stole from me last year, someone from cl0p personally messaged me and said, and I quote (translated from Russian): I have more money than you and all of your people combined, I'll kill you soon," ShinyHunters told BleepingComputer.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Cybercrime groups aren’t exactly “colleagues.” They commonly compete for victims, money, reputation, and everything in between. In March 2025, DragonForce defaced the leak sites of rival ransomware operations BlackLock and Mamona, reportedly to shame the group and disrupt a competitor.
And in 2026, the rivalry between two ransomware groups went too far when 0APT and KryBit hacked and leaked each other's operational data, leaving both operations severely damaged.