Six days after ShinyHunters defaced Clop’s dark-web leak site and demanded an eight-figure payment, the ransomware group has resurfaced at a new Tor onion address, according to reports first surfaced on September 19, 2026 and updated September 25. Clop has not publicly confirmed the ransom demand, and one report says the group denied having any ongoing relationship or active negotiations with ShinyHunters at all. The quiet relocation, rather than a public statement, is doing most of the talking.
The episode matters beyond the schadenfreude of watching one extortion crew get extorted by another. It exposes how fragile the infrastructure behind these leak sites actually is, and it raises a question insurers, incident responders, and would-be victims are now asking out loud: if Clop can’t keep its own server safe, what does that say about the operational security it claims to run when it’s the one breaking in?
What actually happened to Clop’s leak site
Clop’s data-leak site, the page the group uses to name and shame victims who won’t pay, went down and came back looking nothing like itself. ShinyHunters had uploaded a file to the server and then replaced the page entirely, swapping Clop’s usual branding for ShinyHunters’ own Umbreon Pokémon logo and a link pointing back to ShinyHunters’ leak site. The defaced page carried a blunt message: “THIS SITE HAS BEEN PWN3D BY SHINYHUNTERS… Maybe don’t try to threaten us next time.”
That line hints at friction between the two groups that predates this specific breach, though the exact nature of it hasn’t been independently pinned down. What is documented is the aftermath: Clop’s leak site disappeared, then reappeared at a different .onion address, a routine move for a dark-web operator that’s been popped but an unusually public one this time, since the takeover itself was so visible before the migration happened.
The vulnerability: an unauthenticated path-traversal bug in Grav CMS
The break-in traces back to an unauthenticated path-traversal vulnerability in Grav CMS, the flat-file content management system Clop was reportedly running to host its leak portal. Path traversal is one of the oldest bug classes in web security, cataloged for decades in the OWASP path traversal reference, and it typically lets an attacker walk outside a web application’s intended directory to read or write files it was never supposed to touch. When that flaw doesn’t require authentication, it turns a public-facing content page into an open door.
Grav is an open-source, database-free CMS that publishes its own security advisories through its project blog. The choice to run a flat-file CMS on a dark-web leak site isn’t unusual, these operations favor lightweight, self-hosted tools precisely because they avoid the footprint of a full database stack. But lightweight also means fewer eyes on the code, and fewer of the hardening layers a mainstream CMS accumulates over a decade of bug bounty pressure. ShinyHunters found the gap and used it to walk in the front door Clop had left ajar.
The demand: eight figures, a public apology, and a 24-hour clock
Once inside, ShinyHunters didn’t just deface the page and leave. The group demanded an eight-figure payment from Clop and said it would raise that number every 24 hours if Clop didn’t respond. It also demanded a public apology, a condition that reads less like a ransom term and more like a settling of scores. ShinyHunters claimed to have pulled source code, Grav CMS plugins, system logs, and other server data off the box before the defacement went live.
None of that is confirmed independently. ShinyHunters’ broader claims, that it obtained Clop’s Tor private keys, gained full server access, or walked away with everything it says it did, have not been verified by outside researchers. Extortion groups routinely oversell a breach to maximize leverage, and there’s no reason to assume ShinyHunters is an exception just because its target is another ransomware crew. Treat the eight-figure number, the private-key claim, and the scope of the data theft as ShinyHunters’ account of events until something more concrete surfaces.
Clop’s response: silence, denial, and a quiet move
Clop hasn’t issued anything resembling a public rebuttal to ShinyHunters’ specific claims. What has emerged is a denial that the two groups have an ongoing relationship or that any negotiation is taking place, a description that doesn’t quite square with the “vows not to pay” framing that’s circulated in some coverage. There’s a meaningful difference between “we won’t pay a ransom we’re negotiating” and “there is no negotiation to speak of,” and the available reporting supports the latter far more clearly than the former.
What Clop did instead of talking was move. The group’s data-leak site now sits at a new Tor onion address, a standard incident-response step for any operator whose infrastructure has been compromised, but a notable one here because it happened in plain sight. Migrating to a fresh Tor hidden service address is trivial technically, generate new keys, stand up the service, update whatever internal directory points victims to the right page, but it does nothing to answer whether the data ShinyHunters claims to have actually left the building.
Timeline: from defacement to relocation
| Date | Event |
|---|---|
| Before Sept. 19, 2026 | ShinyHunters exploits the unauthenticated path-traversal flaw in Clop’s Grav CMS instance |
| Sept. 19, 2026 | Clop’s leak site is defaced with ShinyHunters’ Umbreon logo and a taunting message; the compromise is first reported |
| Sept. 19-20, 2026 | ShinyHunters demands an eight-figure payment and a public apology, threatens to escalate the demand every 24 hours |
| Sept. 20-24, 2026 | No confirmed public statement from Clop addressing the specific demand or data-theft claims |
| Sept. 25, 2026 | Clop’s leak site resurfaces at a new Tor onion address; a report notes Clop denies an ongoing relationship or active negotiations with ShinyHunters |
| Sept. 29, 2026 | Ransom amount, data-theft scope, and any resolution remain unconfirmed |
Clop and ShinyHunters: two different extortion playbooks
The two groups involved here aren’t peers running the same business model. Clop is a ransomware operator with a long history of mass-exploitation campaigns against file-transfer software, the kind of group that breaches dozens of organizations through a single vulnerability and then runs a leak site to pressure each one individually. ShinyHunters operates more like a data-broker-turned-extortionist, associated with large-scale data theft and, more recently, with aggressive public pressure campaigns against both corporate victims and, in this case, a rival criminal group.
| Trait | Clop | ShinyHunters |
|---|---|---|
| Primary tactic | Mass exploitation of enterprise software flaws, then leak-site pressure | Large-scale data theft and public extortion campaigns |
| Leak site model | Self-hosted Tor site, reportedly running Grav CMS | Separate Tor leak site, used here to redirect Clop’s visitors |
| Public posture in this incident | No confirmed public statement; site quietly relocated | Public defacement, named demand, public taunt |
| Confirmed claim status | Denies ongoing relationship or negotiation with ShinyHunters | Claims full server access, source code, and Tor key theft (unverified) |
Why ransomware groups keep hacking each other
This isn’t the first time one extortion crew has turned its tools on another, and it won’t be the last. Ransomware-as-a-service groups have splintered, rebranded, and informed on each other for years, driven by the same incentives that split any criminal enterprise: disputes over affiliate cuts, stolen code, poached talent, or simple opportunism when a rival’s defenses slip. What’s different about the Clop-ShinyHunters episode is the venue. This wasn’t a leaked chat log or a law enforcement indictment airing dirty laundry, it was a live, technical compromise of production infrastructure that a major ransomware brand depended on to run its business.
That distinction matters for how the security community should read the event. It’s not gossip, it’s a demonstrated vulnerability class (unauthenticated path traversal) in a real piece of software (Grav CMS) that any organization running that stack, criminal or legitimate, should be checking right now. The fact that the victim happens to be a ransomware operator doesn’t change the underlying lesson about patch hygiene and public-facing CMS exposure.
What’s confirmed and what isn’t
It’s worth separating the documented facts from the parts of this story still riding on one group’s word. Confirmed: Clop’s leak site was defaced, the Umbreon branding and taunt message appeared, ShinyHunters demanded an eight-figure sum with a public apology and a 24-hour escalation clock, and Clop’s site has since moved to a new onion address. Unconfirmed: the claim that ShinyHunters stole Clop’s Tor private keys, that it achieved complete server access, that it exfiltrated all the data it says it did, the exact ransom figure, the identity of any individual speaking for either group, and whether any payment or negotiation actually occurred.
Reporters and researchers tracking this should hold that line carefully. Ransomware groups lie to each other and to journalists as a matter of course, inflating breach scope is a negotiating tactic whether the target is a hospital chain or a rival gang. Until independent researchers can verify the data ShinyHunters claims to hold, the safest framing is “ShinyHunters says,” not “ShinyHunters found.”
Illustrative example: what a Tor onion migration looks like
For readers unfamiliar with how a dark-web site relocates after a compromise, the mechanics are straightforward. A v3 Tor hidden service address is derived from a fresh public key, so standing up a new address means generating a new keypair and publishing the resulting 56-character .onion hostname. The format looks like this (example only, not a real address):
hostname format: [56-char base32 string].onion
example shape: exampleonionaddressxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx.onionGenerating a new address is the easy part. The harder problem for any compromised operator, criminal or legitimate, is knowing whether the attacker retained a copy of the private key material, backend code, or victim data before the relocation, which is exactly the open question hanging over Clop right now.
Market and industry impact
For organizations currently listed, or fearing they’ll be listed, on Clop’s leak site, this incident adds a genuinely new variable to an already messy calculation. If ShinyHunters’ claims about accessing system logs and server data hold up even partially, information about which victims Clop was actively pressuring, and potentially details of any side conversations, could end up outside Clop’s control entirely. Incident response firms and ransom negotiators who track leak-site activity as a signal of a group’s credibility and follow-through now have to factor in that Clop’s own operational security failed at a moment its business model depends on looking untouchable.
There’s also a reputational cost inside the criminal ecosystem itself. Ransomware-as-a-service brands compete for affiliates the same way any franchise competes for operators, on perceived reliability, payout history, and technical competence. A group whose own leak site gets defaced by a rival crew, using a bug class as basic as path traversal, takes a hit to that reputation regardless of what happens with the demanded payment. Whether that translates into affiliates jumping to a different franchise is the kind of shift that typically shows up in underground forum chatter over the following weeks rather than in any public statement.
Historical context: infrastructure has always been ransomware’s weak link
Clop is far from the first ransomware brand to get caught by the same class of sloppy web security it exploits in victims. Law enforcement operations and rival hackers alike have repeatedly found that leak sites, negotiation portals, and affiliate panels run on outdated or misconfigured software, the same gap that lets a ransomware crew into a hospital network can let a researcher, a rival, or a police unit into the crew’s own back office. Clop specifically has built its reputation on mass-exploiting enterprise file-transfer tools rather than on the sophistication of its own web infrastructure, so a basic CMS flaw taking down its leak site fits a pattern rather than breaking one.
The broader lesson for defenders is one worth revisiting: as covered in our look at how ransomware groups are adapting their exfiltration methods, these operations are businesses under constant pressure to move fast, and speed tends to come at the expense of the same hardening discipline they punish victims for lacking.
Where this sits alongside other 2026 extortion incidents
This episode lands in the middle of a busy year for extortion-driven headlines. ShinyHunters has been a near-constant presence in 2026 coverage, from the initial breach and eight-figure demand against Clop itself, to the arrest of a 24-year-old suspect by Dutch police, to the FBI’s declaration of a cyber incident tied to a ShinyHunters deadline. That’s a group operating on multiple fronts at once, against corporate targets, government infrastructure, and now a rival ransomware brand, in the same news cycle.
It’s also not the only recent example of extortion infrastructure getting breached through a basic web flaw. Supply-chain and CMS-adjacent compromises, like the Brevo supply-chain hack that hit roughly 100,000 sites via a ClickFix-style attack, and CI/CD-adjacent ransomware incidents such as the TeamCity flaw that led to ransomware hitting 160 servers, all point to the same underlying trend: self-hosted, internet-facing software with a thin patching cadence remains the easiest way in, whether the target is a Fortune 500 company or a criminal enterprise’s own leak page.
Predictions: where this goes next
- Clop stays quiet publicly. Groups in this position rarely issue detailed rebuttals. Expect continued silence on the specific ransom figure and data-theft claims rather than a point-by-point denial.
- ShinyHunters escalates the public pressure before any payment materializes. Given the pattern of public taunts and named deadlines seen in ShinyHunters’ other 2026 campaigns, a further leak or claim drop against Clop within weeks is plausible.
- Independent verification of the data-theft claims will lag the headlines. Researchers typically need days to weeks to confirm or debunk exfiltration claims of this kind, so expect the “confirmed vs. unconfirmed” gap to persist for some time.
- Other ransomware operators quietly audit their own leak-site infrastructure. A public embarrassment like this tends to trigger private housekeeping across the ecosystem, even if none of it is visible from the outside.
- Law enforcement interest in both groups continues regardless of the outcome. Given the FBI and Dutch police activity already tied to ShinyHunters this year, this incident is unlikely to change enforcement priorities, if anything it adds another data point to ongoing investigations.
What security teams should take away from this
Strip away the novelty of watching two extortion groups fight and the practical lesson is mundane: unauthenticated path-traversal bugs in self-hosted CMS software remain a live, exploitable risk in 2026, whether the box in question sits behind a corporate firewall or a Tor hidden service. Any organization running Grav or a similar flat-file CMS on internet-facing infrastructure should confirm patch status against the project’s published advisories rather than assuming a lightweight stack means a smaller attack surface.
For incident responders and ransom negotiators, the more durable takeaway is about trust calibration. If a ransomware group’s own infrastructure can be compromised through a basic web bug, the operational sophistication that group projects in its negotiations should be discounted accordingly. Victims and their advisors evaluating a Clop demand this week have one more reason to treat the group’s leverage claims with the same skepticism Clop would apply to a target stalling for time. Organizations that suspect they may already be on an extortion group’s radar can report incidents to agencies such as the FBI’s Internet Crime Complaint Center, which tracks exactly this kind of activity across the ransomware ecosystem.
Frequently asked questions
Did ShinyHunters actually hack Clop’s ransomware operation?
Reports confirm Clop’s leak site was defaced and replaced with ShinyHunters’ Umbreon branding, exploiting an unauthenticated path-traversal flaw in Grav CMS. The full scope of ShinyHunters’ claimed access, including source code and Tor private keys, has not been independently verified.
Did Clop pay ShinyHunters the eight-figure ransom?
There’s no confirmation of a payment. Available reporting indicates Clop denies an ongoing relationship or active negotiation with ShinyHunters, which is a different claim than a formal refusal to pay a specific demand.
What vulnerability did ShinyHunters exploit?
An unauthenticated path-traversal vulnerability in Grav CMS, the content management system reportedly powering Clop’s leak site. Path traversal flaws let an attacker access files outside the application’s intended directory without needing valid credentials.
Has Clop’s leak site moved to a new address?
Yes. Clop’s data-leak site now operates from a new Tor onion address, a move reported around September 25, 2026, roughly six days after the original defacement.
Is the eight-figure ransom demand confirmed?
The demand itself, an eight-figure sum plus a public apology, with the figure rising every 24 hours if unmet, comes from ShinyHunters’ own statements. The exact dollar amount and whether it was ever paid or negotiated down remain unconfirmed.
Why would one ransomware group hack another?
Motives in these cases typically involve disputes over stolen code, affiliate poaching, unpaid cuts, or simple opportunism when a rival’s infrastructure is exposed. The defacement message referencing a prior threat suggests some history between the two groups, though the specifics haven’t been publicly detailed.
Does this affect victims currently listed on Clop’s leak site?
Potentially. If ShinyHunters did obtain system logs or backend data as claimed, information tied to Clop’s active extortion targets could be exposed outside Clop’s control, though this has not been confirmed.
Is Grav CMS itself unsafe to use?
Grav is a legitimate, widely used open-source CMS. This incident points to a specific unauthenticated path-traversal flaw rather than a blanket problem with the platform. Organizations running it should verify they’re on a patched version per the project’s advisories.
