Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-20 · updated: 2026-09-20 · tags: [incident, global, ransomware] · confidence: medium · severity: critical · affected_sectors: [global] · au_impact: false

The ShinyHunters extortion gang breached the leak site of the Clop (Cl0p) ransomware operation, uploading a taunting text file on Friday night and then replacing the Tor site with ASCII art of Umbreon — the Pokémon used as ShinyHunters' logo — carrying the message "rooting your systems since '19 ;)". ShinyHunters says it exploited an unauthenticated file upload vulnerability in Grav CMS to plant the file, and that it gained full server access, stealing source code, Grav CMS plugins, all files under /var/log and the private keys for Clop's Tor onion service. If the keys are valid, the gang could operate a site at Clop's existing onion address from infrastructure it controls, which is the claim that would matter most were it confirmed. BleepingComputer independently confirmed the uploaded file could be downloaded directly from Clop's server and that the defacement was still being served from Clop's own infrastructure, but it has not independently verified the theft of logs, source code or onion keys. ShinyHunters said it plans to publish a message instructing Clop to make contact within 72 hours, and gave its motive as retaliation — "maybe don't try to threaten us next time". The episode is unusual in that it is criminal-on-criminal rather than victim-facing; the practical risk for defenders is the disclosure of whatever logging the leak site held about visitors to it.

Attribute Detail
**Sector Global (Macro)
**Date 2026-09-20
**Source BleepingComputer
**Reliability Tier 2