ShinyHunters Breaches Cl0p Ransomware Gang in High-Stakes Cyber Feud
In a rare case of cybercriminals turning on one another, the ransomware group ShinyHunters successfully hacked its rival, Cl0p, by exploiting an unauthenticated file-upload vulnerability in Grav, the content management system (CMS) powering Cl0p’s data leak site. The breach allowed ShinyHunters to deface Cl0p’s public-facing platform, replacing it with a "domain seized" message before taking the site offline.
The attack stemmed from a critical flaw in Grav, a PHP-based, flat-file CMS that stores content without a database. Poor server and application configurations can leave Grav installations vulnerable, as seen in this incident. ShinyHunters claimed to have exfiltrated sensitive data, including server logs, source code, Grav plugins, and Cl0p’s Tor service private keys potentially enabling impersonation of the rival gang’s dark web operations.
In a twist, Cl0p attempted to negotiate, reaching out to ShinyHunters via an old platform after failing to establish contact through email. Meanwhile, ShinyHunters repurposed Cl0p’s leak site to publish stolen Salesforce data, demanding an eight-figure ransom plus interest from the profits Cl0p allegedly earned by exploiting the Oracle E-Business Suite (EBS) zero-day vulnerability (CVE-2025-61882). Both gangs have claimed discovery of the flaw, which allows unauthenticated attackers to take over Oracle’s Concurrent Processing system.
The feud highlights the escalating rivalry between top-tier ransomware groups. Cl0p, known for large-scale data exfiltration via managed file transfer (MFT) systems, has previously exploited MOVEit Transfer (2023), GoAnywhere MFT (2023), Accellion FTA (2021), and Cleo (2024), impacting nearly 200 organizations. ShinyHunters, meanwhile, has built a reputation for breaching enterprise software, SaaS platforms, and cloud environments, often using phishing and stolen OAuth credentials. Recent high-profile targets include Salesloft (1.5B records stolen in 2025), Salesforce (285M records), and major corporations like AT&T, Cisco, and the European Commission.
The breach underscores the growing sophistication of cybercriminal infighting, where even threat actors are not immune to exploitation.
Cisco cybersecurity rating report: https://www.rankiteo.com/company/cisco
Ransom-ISAC cybersecurity rating report: https://www.rankiteo.com/company/ransom-isac
"id": "CISRAN1790619887",
"linkid": "cisco, ransom-isac",
"type": "Ransomware",
"date": "9/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Cybercrime',
'name': 'Cl0p',
'type': 'Ransomware gang'},
{'customers_affected': '285M records exposed',
'industry': 'Technology/Cloud Services',
'name': 'Salesforce',
'size': 'Large',
'type': 'SaaS Platform'},
{'customers_affected': '1.5B records stolen',
'industry': 'Technology/Sales Engagement',
'name': 'Salesloft',
'size': 'Large',
'type': 'Enterprise Software'},
{'industry': 'Various',
'name': 'Oracle E-Business Suite users',
'type': 'Enterprise Software Users'}],
'attack_vector': 'Unauthenticated file-upload vulnerability in Grav CMS',
'data_breach': {'data_exfiltration': 'Yes',
'number_of_records_exposed': ['285M (Salesforce)',
'1.5B (Salesloft)'],
'personally_identifiable_information': 'Likely '
'(Salesforce/Salesloft '
'data)',
'sensitivity_of_data': 'High (private keys, source code, PII '
'in Salesforce/Salesloft data)',
'type_of_data_compromised': ['Server logs',
'Source code',
'Grav plugins',
'Tor service private keys',
'Salesforce data',
'Salesloft data']},
'description': 'In a rare case of cybercriminals turning on one another, the '
'ransomware group ShinyHunters successfully hacked its rival, '
'Cl0p, by exploiting an unauthenticated file-upload '
'vulnerability in Grav, the content management system (CMS) '
'powering Cl0p’s data leak site. The breach allowed '
'ShinyHunters to deface Cl0p’s public-facing platform, '
"replacing it with a 'domain seized' message before taking the "
'site offline. ShinyHunters claimed to have exfiltrated '
'sensitive data, including server logs, source code, Grav '
'plugins, and Cl0p’s Tor service private keys, potentially '
'enabling impersonation of the rival gang’s dark web '
'operations. Cl0p attempted to negotiate, while ShinyHunters '
'repurposed Cl0p’s leak site to publish stolen Salesforce '
'data, demanding an eight-figure ransom plus interest.',
'impact': {'brand_reputation_impact': 'Reputation damage to Cl0p due to '
'defacement and data exposure',
'data_compromised': 'Server logs, source code, Grav plugins, Tor '
'service private keys, Salesforce data (285M '
'records), Salesloft data (1.5B records)',
'downtime': 'Cl0p’s public-facing platform taken offline',
'operational_impact': 'Defacement of Cl0p’s leak site, potential '
'impersonation of Cl0p’s dark web operations',
'systems_affected': 'Cl0p’s data leak site, Grav CMS, Oracle '
'E-Business Suite, Salesforce, Salesloft'},
'initial_access_broker': {'entry_point': 'Grav CMS unauthenticated '
'file-upload vulnerability',
'high_value_targets': 'Cl0p’s Tor service private '
'keys, source code'},
'lessons_learned': 'Cybercriminal groups are not immune to exploitation; poor '
'server and application configurations can lead to severe '
'breaches even among threat actors. The incident '
'highlights the escalating sophistication of cybercriminal '
'infighting and the risks of unpatched or misconfigured '
'systems.',
'motivation': ['Rivalry',
'Financial gain',
'Data exfiltration',
'Reputation damage'],
'post_incident_analysis': {'corrective_actions': 'Patch Grav CMS, secure dark '
'web operations, implement '
'stricter access controls '
'for MFT systems, monitor '
'for zero-day exploits.',
'root_causes': 'Unauthenticated file-upload '
'vulnerability in Grav CMS, poor '
'server/application configurations, '
'unpatched Oracle E-Business Suite '
'zero-day (CVE-2025-61882)'},
'ransomware': {'data_exfiltration': 'Yes',
'ransom_demanded': 'Eight-figure ransom plus interest'},
'recommendations': ['Regularly audit and patch CMS platforms like Grav to '
'prevent unauthenticated file-upload vulnerabilities.',
'Implement strict access controls and monitoring for dark '
'web operations.',
'Enhance security for managed file transfer (MFT) systems '
'to prevent exploitation.',
'Monitor for zero-day vulnerabilities in enterprise '
'software (e.g., Oracle E-Business Suite).',
'Assume threat actors may target each other and prepare '
'for potential collateral damage.'],
'references': [{'source': 'Cyber Incident Report'}],
'response': {'communication_strategy': 'Cl0p attempted negotiation via old '
'platform',
'containment_measures': 'Cl0p’s leak site taken offline'},
'threat_actor': ['ShinyHunters', 'Cl0p'],
'title': 'ShinyHunters Breaches Cl0p Ransomware Gang in High-Stakes Cyber '
'Feud',
'type': 'Ransomware, Data Breach, Cybercriminal Infighting',
'vulnerability_exploited': 'CVE-2025-61882 (Oracle E-Business Suite '
'zero-day), Grav CMS misconfiguration'}