Clop has moved its data-leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has established is an unauthenticated path traversal. ShinyHunters breached the Clop site earlier in September, first uploading a small text file and then replacing the page with a full-page defacement carrying its Umbreon Pokémon logo and a link to its own leak site, before claiming on its own site that it had stolen source code, Grav CMS plugins, server logs and the private keys for Clop's Tor onion service — and issuing a ransom demand against the rival gang. Clop has confirmed its Grav installation "had not been fully updated" — "We didn't update the Grav plugin — though it happened eventually" — and has denied any relationship or ongoing negotiation with ShinyHunters, stating it has neither provided nor will provide them with information. Clop disputes the theft's significance, asserting the server "contained nothing but content", with no data or financial activity present. Grav CMS has confirmed that the vulnerability and the exploitation details relayed by ShinyHunters are accurate. Clop was subsequently and quietly removed from ShinyHunters' leak site — the usual signal that negotiations are under way — which ShinyHunters declined to discuss. The transferable point for defenders is unglamorous: the same unpatched-plugin condition that funds these crews' operations was present on their own infrastructure, and an unpatched CMS behind a Tor service is patched no more reliably than one in an enterprise DMZ.
| Attribute | Detail |
|---|---|
| Sector | Global (Macro) |
| Date | 2026-09-28 |
| Source | BleepingComputer |
| Reliability | Tier 2 |