Oracle and Grav CMS: ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

Oracle and Grav CMS: ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

ShinyHunters Breaches Clop Ransomware Gang’s Data Leak Site in Retaliatory Cyberattack

The ShinyHunters extortion group successfully breached and defaced Clop ransomware’s Tor-based data leak site, claiming to have stolen sensitive server data, including private keys for its onion service. The attack, which began on a Friday night, exploited an unauthenticated file upload vulnerability in Grav CMS a content management system used by Clop to upload a taunting message and a link to ShinyHunters’ own leak site.

Within hours, ShinyHunters replaced Clop’s site with a defacement page featuring ASCII art of Umbreon (the group’s logo) and the message, "rooting your systems since '19 ;)". The group asserted full access to Clop’s server, alleging theft of source code, Grav CMS plugins, system logs (including authentication records and potential visitor IPs), and the private keys for Clop’s Tor onion service. If verified, the stolen keys could allow ShinyHunters to impersonate Clop’s official Tor site.

ShinyHunters stated their intent to extort Clop, threatening to publish a demand on their leak site for the ransomware gang to contact them within 72 hours. The attack stems from an ongoing feud between the two groups, with ShinyHunters citing threats from a Clop representative including violent rhetoric following disputes over a 2025 Oracle E-Business Suite data theft campaign. During that operation, Clop exploited multiple vulnerabilities, including a zero-day (CVE-2025-61882), while ShinyHunters claimed Clop had stolen their exploit code.

The defacement mirrors a 2020 attack on HackForums, where ShinyHunters used the same Umbreon artwork. As of reporting, Clop’s site remains defaced, though the group has not responded to requests for comment. The incident highlights escalating tensions between cybercriminal factions, with potential implications for Clop’s operations and future extortion tactics.

Source: https://www.bleepingcomputer.com/news/security/shinyhunters-hacks-clop-leak-site-threatens-to-extort-ransomware-gang/

Oracle cybersecurity rating report: https://www.rankiteo.com/company/oracle

GRAV® cybersecurity rating report: https://www.rankiteo.com/company/grav

"id": "ORAGRA1789827870",
"linkid": "oracle, grav",
"type": "Cyber Attack",
"date": "10/2025",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Cybercrime',
                        'name': 'Clop Ransomware Gang',
                        'type': 'Cybercriminal Organization'}],
 'attack_vector': 'Unauthenticated file upload vulnerability in Grav CMS',
 'data_breach': {'data_exfiltration': 'Yes',
                 'personally_identifiable_information': 'Potential visitor IPs '
                                                        'and authentication '
                                                        'records',
                 'sensitivity_of_data': 'High (private keys for Tor onion '
                                        'service, authentication records, '
                                        'visitor IPs)',
                 'type_of_data_compromised': 'Source code, system logs, '
                                             'private keys, Grav CMS plugins'},
 'description': 'The ShinyHunters extortion group successfully breached and '
                'defaced Clop ransomware’s Tor-based data leak site, claiming '
                'to have stolen sensitive server data, including private keys '
                'for its onion service. The attack exploited an '
                'unauthenticated file upload vulnerability in Grav CMS, a '
                'content management system used by Clop, to upload a taunting '
                'message and a link to ShinyHunters’ own leak site. The group '
                'asserted full access to Clop’s server, alleging theft of '
                'source code, Grav CMS plugins, system logs, and private keys '
                'for Clop’s Tor onion service. ShinyHunters threatened to '
                'extort Clop, demanding contact within 72 hours.',
 'impact': {'brand_reputation_impact': 'Potential reputational damage to Clop '
                                       'ransomware gang',
            'data_compromised': 'Source code, Grav CMS plugins, system logs '
                                '(including authentication records and visitor '
                                'IPs), private keys for Tor onion service',
            'operational_impact': 'Defacement of Clop’s data leak site, '
                                  'potential impersonation of Clop’s Tor site',
            'systems_affected': 'Clop ransomware gang’s Tor-based data leak '
                                'site'},
 'initial_access_broker': {'entry_point': 'Unauthenticated file upload '
                                          'vulnerability in Grav CMS',
                           'high_value_targets': 'Clop’s Tor-based data leak '
                                                 'site'},
 'investigation_status': 'Ongoing',
 'motivation': 'Retaliation, Extortion, Feud between cybercriminal groups',
 'post_incident_analysis': {'root_causes': 'Feud between ShinyHunters and '
                                           'Clop, exploitation of '
                                           'unauthenticated file upload '
                                           'vulnerability in Grav CMS'},
 'references': [{'source': 'Cybersecurity Reporting'}],
 'threat_actor': 'ShinyHunters',
 'title': 'ShinyHunters Breaches Clop Ransomware Gang’s Data Leak Site in '
          'Retaliatory Cyberattack',
 'type': 'Defacement, Data Breach, Extortion',
 'vulnerability_exploited': 'Unauthenticated file upload vulnerability (Grav '
                            'CMS)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.