Clop’s dark web leak site went quiet in the third week of September, and when a page finally loaded again, Clop wasn’t the one in control. Cybersecurity Insiders and other outlets tracking the ransomware underground reported that a rival extortion crew, ShinyHunters, had broken into the server hosting Clop’s leak site, planted a taunting defacement, and demanded an eight-figure payment to stay quiet. Six days later, on September 25, 2026, Clop resurfaced at a new Tor onion address, a tacit admission that its old infrastructure was gone for good.
The incident is unusual even by the low standards of the ransomware underground. Criminal extortion crews shake down hospitals, schools, and Fortune 500 vendors for a living, but they rarely turn that playbook on each other. ShinyHunters’ move against Clop looks like a hostile takeover dressed up as a hack, and it has left incident responders and threat researchers trying to work out who actually controls Clop’s stolen data right now. Below is what’s confirmed, what’s still just a claim, and what it means for anyone currently on the wrong end of a Clop extortion email.
Clop’s Leak Site Goes Dark, Then Reappears Under New Control
According to reporting dated September 19, 2026, Clop’s data-leak site, the page the group uses to publish stolen files from companies that refuse to pay, was compromised and defaced. The attacker didn’t just knock the site offline. They replaced it with their own branding, effectively hijacking the address Clop’s victims and researchers had used to track the group’s activity for months. By September 25, Clop had abandoned that server entirely and stood up a fresh Tor onion address, according to the same reporting. For a ransomware operation, losing control of your leak site is closer to losing your storefront than losing a single web page. It’s the channel victims use to verify what’s been stolen and the channel researchers use to attribute new breaches to the group.
The identity of the intruder wasn’t a mystery for long. ShinyHunters, a data-extortion collective that has spent 2026 building a reputation for large-scale corporate breaches, claimed credit almost immediately and left little doubt about its involvement.
The Umbreon Defacement and ShinyHunters’ Message
Reports from Cybersecurity Insiders describe the defaced page as carrying ShinyHunters’ Umbreon Pokémon logo, a calling card the group has used elsewhere, alongside a link pointing back to ShinyHunters’ own leak site. The original defacement message, as reported, read: “THIS SITE HAS BEEN PWN3D BY SHINYHUNTERS… Maybe don’t try to threaten us next time.” That last line matters. It implies a grievance, not just an opportunistic hack, though the specific nature of any prior dispute between the two groups hasn’t been independently confirmed by outside researchers.
Defacements like this serve a dual purpose in the extortion economy. They humiliate the target in front of an audience of victims, journalists, and rival criminals, and they double as proof of access, a way to signal that the intrusion is real before any ransom conversation even starts. The Grav CMS breach behind this incident echoes tactics documented in how ransomware groups are adapting their exfiltration methods, where public-facing infrastructure often turns out to be the weakest link in an otherwise disciplined operation.
How ShinyHunters Reportedly Got In: A Grav CMS Flaw
The intrusion has been attributed to an unauthenticated path-traversal vulnerability in Grav CMS, the open-source content management system Clop was apparently running to serve its leak pages. Path traversal bugs let an attacker request files outside the directory a web application is supposed to expose, often without needing a username or password. Depending on what’s reachable, that can mean reading configuration files, extracting credentials, or in the worst case landing enough access to overwrite content outright, which appears to be roughly what happened here.
There’s a certain irony in a ransomware gang getting popped through the same class of software flaw its own victims are so often breached by. Clop built its reputation on mass-exploitation campaigns against file-transfer software rather than bespoke intrusions, and running a leak site on a general-purpose CMS with an unpatched, unauthenticated bug is the kind of operational security lapse that shows even sophisticated criminal groups skip patch management. Security teams evaluating their own exposure to path-traversal classes of bugs can cross-reference recent disclosures, including the Roundcube SQL injection flaw rated CVSS 8.1 that surfaced earlier this year, which required no authentication either.
# A defensive check, not an exploit: confirm your CMS version and
# installed plugins before assuming you're not affected by a
# path-traversal disclosure in a self-hosted CMS.
composer show | grep -i grav
find . -maxdepth 2 -iname "*.yaml" -path "*system*" -newer /etc/hostname
# Cross-check the reported version against your vendor's advisory
# before treating any instance as confirmed vulnerable.
The Eight-Figure Demand and the 24-Hour Clock
Once in control of the server, ShinyHunters reportedly demanded an eight-figure payment from Clop and said the price would climb every 24 hours that Clop failed to respond, according to the reporting. ShinyHunters also demanded a public apology, a detail that stands out even among extortion demands. Asking for money is standard practice for this crowd. Asking a rival criminal enterprise to publicly grovel suggests the motive here runs on ego as much as it does on profit.
Neither the exact ransom figure nor whether Clop ever engaged with the demand has been independently established in the available reporting. Extortion-on-extortion situations like this one don’t come with the usual channels, no cyber insurance broker, no incident response retainer, no law firm managing disclosure obligations, so the outside world is largely reliant on whatever each side chooses to post publicly. That makes claims from both parties harder to verify than in a typical corporate breach.
What ShinyHunters Claims to Have Taken
Beyond the defacement itself, ShinyHunters said it obtained source code, Grav CMS plugins, system logs, and other server data from Clop’s infrastructure, according to the reporting. If accurate, that kind of access could hand researchers and law enforcement a rare look inside how a top-tier ransomware operation actually runs its leak-site backend, information that’s normally locked away behind Tor and operational security discipline built specifically to prevent exactly this kind of exposure.
That’s a meaningful distinction from most public ransomware takedowns, which tend to come from coordinated law enforcement operations rather than a rival gang’s server logs leaking sideways. The scale of what’s actually usable from this haul, if any of it holds up, remains to be seen.
Separating Confirmed Facts From Unverified Claims
Extortion disputes between criminal groups are, almost by definition, hard to fact-check. Neither party has an incentive to tell the truth, and neither is going to sit for an interview. Here’s the line between what’s been reported by named outlets and what’s still just an unverified claim from one side of the dispute:
- Reported as fact: Clop’s leak site was compromised and defaced, then replaced with ShinyHunters’ branding and a link to its own site.
- Reported as fact: The intrusion has been attributed to an unauthenticated path-traversal flaw in Grav CMS.
- Reported as fact: Clop relaunched at a new Tor onion address by September 25, 2026.
- Unverified claim: ShinyHunters’ assertion that it obtained Clop’s Tor private keys or complete server access.
- Unverified claim: The exact scope and authenticity of all the server data ShinyHunters says it exported.
- Unverified: The precise ransom figure, whether Clop ever negotiated, and whether any payment changed hands.
That last category matters most for readers trying to size up the story. Headlines framing this as Clop flatly refusing to pay ShinyHunters go further than the underlying reporting supports. What’s actually on the record is narrower and more cautious.
Clop’s Public Posture: Denial, Not Confirmation
Rather than confirming or denying a ransom negotiation, one report indicated Clop denied having any ongoing relationship or active negotiations with ShinyHunters at all. That’s a meaningfully different posture than publicly refusing to pay a named demand. Denying a relationship exists is a way to dismiss the entire episode as beneath response, which fits a pattern criminal groups often use when they’d rather not legitimize a rival’s claims by engaging with them directly.
It also leaves plenty of room between the two positions. A group can deny an ongoing relationship with an extortionist while quietly still having paid, negotiated, or ignored an earlier one-off demand. Without a verified statement laying out Clop’s actual response, readers should treat the “vowed not to pay” framing as inference rather than a confirmed fact.
Who Is Clop, and Why the Group’s Infrastructure Matters
Clop has operated as a ransomware and data-extortion brand for years, and it’s best known for mass-exploitation campaigns against file-transfer software rather than one-off intrusions into individual companies. Rather than breaching victims one at a time, the group has repeatedly found a single vulnerable platform used by hundreds of organizations at once and exploited it broadly before anyone patched. That approach lets a relatively small crew claim an outsized number of victims in a short window, which is part of why losing control of the leak site used to publicize those victims is such a meaningful setback.
Who Is ShinyHunters
ShinyHunters has built a reputation through 2026 as a prolific data-extortion operation, one that has repeatedly been named in coverage of major corporate breach claims and in law enforcement activity tied to the group. Shattered.io has covered the group’s collisions with the FBI, including a cyber incident declaration that came with a seven-day deadline and a separate report where the FBI confirmed an active breach probe tied to the group. Dutch authorities have also moved against individuals linked to the ShinyHunters name, with police in the Netherlands arresting a 24-year-old suspect earlier this year. None of those actions are confirmed to be directly connected to the Clop server compromise, but they establish the group’s pattern of aggressive, high-visibility operations against large targets.
A Short History of Ransomware Gangs Turning on Each Other
Infighting inside the ransomware ecosystem isn’t new, though it’s usually triggered by outsiders rather than rival gangs. Law enforcement’s Operation Cronos seized and defaced LockBit’s leak site in 2024, using the group’s own infrastructure to troll its affiliates. Conti’s internal chat logs leaked to researchers in 2022 after an insider turned against the group following its public support for Russia’s invasion of Ukraine, exposing years of internal operations. What sets the Clop-ShinyHunters episode apart is that the attacker in this case wasn’t a police agency or a disgruntled insider. It was another for-profit extortion operation, applying its own playbook to a competitor instead of a corporate victim. That’s a genuinely new wrinkle in an ecosystem that has generally treated rival gangs as competitors to ignore, not targets to breach.
Why This Matters for Enterprise Security and Incident Response Teams
For companies currently dealing with a Clop extortion attempt, this episode adds a layer of uncertainty that didn’t exist a month ago. If ShinyHunters genuinely holds a copy of Clop’s server data, victim files that were supposed to stay locked behind one group’s infrastructure could now be sitting somewhere else entirely, outside the negotiation channel a company thought it was dealing with. Incident response teams and outside counsel managing active Clop cases now have to consider whether their client’s stolen data is exposed to a second, unaccounted-for party.
There’s also a broader lesson about infrastructure hygiene that applies well beyond criminal groups. A leak site running outdated, unpatched CMS software is functionally no different from any other internet-facing application with a patch management gap, and the same unauthenticated path-traversal class of bug that took Clop down has shown up repeatedly in legitimate enterprise software this year, including the TeamCity flaw rated CVSS 9.8 that CISA linked to ransomware activity on roughly 160 servers. Security teams that treat “who would even bother attacking us” as a risk model are making the same mistake Clop apparently did.
Market and Industry Impact
The immediate market impact is harder to quantify than a stock move or a funding round, but it’s real. Cyber insurers and incident response firms that track ransomware group reliability, whether a group actually deletes data after payment, whether it reappears under a new name, now have one more data point suggesting Clop’s own operational security isn’t as tight as its exploitation campaigns might suggest. That matters directly to any company weighing whether to pay a Clop ransom demand at all, since the calculus depends heavily on trusting the group to honor its side of the deal.
It also feeds a broader trend researchers have flagged around breach-notification chaos this year, where multiple parties claim credit for overlapping incidents and victims struggle to figure out who actually holds their data, a dynamic visible in the ongoing fallout from the IDScan.net breach affecting more than 153 million identity records. When extortion groups themselves become breach victims, the already murky question of “who has our data” gets murkier still.
Clop vs. ShinyHunters: A Side-by-Side Comparison
| Factor | Clop | ShinyHunters |
|---|---|---|
| Primary tactic | Mass exploitation of file-transfer software | Large-scale corporate data theft and extortion |
| Leak site status (as of Sept. 25, 2026) | Relaunched at a new Tor onion address | Original site reportedly unaffected |
| Reported role in this incident | Victim of the server compromise | Claimed the intrusion and defacement |
| Demand style | Standard ransom negotiations with corporate victims | Eight-figure demand plus a public apology, per reports |
| Recent law enforcement attention | Long-running international scrutiny over file-transfer campaigns | Named in multiple 2026 FBI and Dutch police actions |
| Public communication style | Reportedly denied an ongoing relationship with ShinyHunters | Publicly defaced rival’s site and claimed credit |
Timeline of the Clop Leak-Site Incident
| Date | Event |
|---|---|
| Sept. 19, 2026 | Clop’s leak site is compromised via a Grav CMS path-traversal flaw and defaced with ShinyHunters’ Umbreon logo, per Cybersecurity Insiders’ reporting |
| Sept. 19, 2026 | ShinyHunters reportedly demands an eight-figure payment plus a public apology, with the price set to rise every 24 hours |
| Sept. 19–25, 2026 | Clop’s response, if any, to the demand is not independently confirmed in available reporting |
| Sept. 25, 2026 | Clop relaunches its leak site at a new Tor onion address, according to reports |
| Sept. 29, 2026 | Coverage continues as researchers work to verify the scope of ShinyHunters’ claimed data haul |
What Happens Next: Five Predictions
The following are analytical predictions based on how the ransomware ecosystem has historically responded to similar disruptions, not confirmed facts about what Clop or ShinyHunters will do next.
- Copycat attempts. Other extortion crews may try similar hostile takeovers against rival leak sites now that ShinyHunters has shown it works as a publicity tactic, even without full confirmation of the claimed data haul.
- Faster infrastructure hardening. Expect Clop, and likely other groups running self-hosted CMS platforms for leak sites, to migrate away from Grav or apply emergency patches rather than risk a repeat.
- Stalled negotiations for existing Clop victims. Companies currently negotiating with Clop may pause or slow payments until it’s clearer whether ShinyHunters holds a duplicate copy of their stolen files.
- Law enforcement interest regardless of outcome. Agencies tracking both groups are likely to treat ShinyHunters’ claimed server logs as a potential intelligence source, even if the underlying extortion dispute never gets resolved publicly.
- More scrutiny of leak-site software. Researchers who track ransomware infrastructure will likely start fingerprinting the CMS platforms behind other groups’ leak sites, treating them as a legitimate attack surface rather than an afterthought.
How This Fits the Broader ShinyHunters Pattern
Taken alongside the group’s other 2026 activity, the Clop server compromise looks less like an isolated stunt and more like an extension of ShinyHunters’ broader strategy of maximizing visibility around every claimed intrusion. The group has shown a consistent pattern of pairing technical access with public messaging designed to pressure targets in front of an audience, whether that target is a Fortune 500 company or, in this case, a criminal rival. For organizations building threat models around this group, the Clop incident is a reminder that ShinyHunters treats reputational damage as a weapon on par with the data itself.
Frequently Asked Questions
Did ShinyHunters actually hack the Clop ransomware group?
Reports from Cybersecurity Insiders and other outlets say ShinyHunters compromised and defaced the server hosting Clop’s data-leak site, replacing it with its own branding. That intrusion has been reported as fact. ShinyHunters’ broader claims about the scope of data it obtained have not been independently verified.
Did Clop pay the ransom ShinyHunters demanded?
That isn’t established in available reporting. One report indicated Clop denied having an ongoing relationship or active negotiations with ShinyHunters, but that’s a different statement than a confirmed refusal to pay a specific demand.
What vulnerability did ShinyHunters reportedly use to breach Clop?
The intrusion has been attributed to an unauthenticated path-traversal vulnerability in Grav CMS, the content management platform Clop was apparently running to serve its leak site.
How much money did ShinyHunters demand from Clop?
ShinyHunters reportedly demanded an eight-figure payment, with the amount set to increase every 24 hours if Clop didn’t respond, along with a public apology. The exact figure has not been confirmed.
Is Clop’s leak site still operating?
Yes. According to reporting dated September 25, 2026, Clop relaunched its leak site at a new Tor onion address after abandoning the compromised server.
Why would one ransomware group attack another?
The motive hasn’t been independently confirmed, but the defacement message left behind referenced a prior threat, suggesting a grievance-driven motive rather than a purely opportunistic hack. Extortion groups also gain publicity and credibility within the criminal underground by demonstrating they can breach even well-established rivals.
Does this affect companies that were already breached by Clop?
Potentially. If ShinyHunters’ claims about obtaining server data are accurate, some information tied to Clop’s operations, though not necessarily individual victim files, may now exist outside Clop’s direct control. Companies in active negotiations with Clop should treat that uncertainty as a factor in their incident response planning.
Where can I read more about ransomware group tactics like this?
Outlets like Krebs on Security, BleepingComputer, and The Record track ransomware group infrastructure and leak-site activity on an ongoing basis, alongside research from firms like Mandiant and threat intelligence writeups published by SANS.
Related
- FBI Declares Cyber Incident, ShinyHunters Set 7 Days [2026]
- FBI Confirms Breach Probe, FBIJobs.gov Down 5 Days [2026]
- Dutch Police Arrest ShinyHunters Suspect, 24 [2026]
- How Ransomware Groups Are Adapting by Using Encrypted Exfiltration Methods
- TeamCity Flaw CVSS 9.8: Ransomware Hits 160 Servers [2026]
Related Coverage
- Clop Denies ShinyHunters Deal, Moves Site in 6 Days [2026]
- Dutch Police Arrest ShinyHunters Suspect, 24 [2026]
- FBI Declares Cyber Incident, ShinyHunters Set 7 Days [2026]
- Passkeys Explained: What Security Teams Should Tell Employees Before Rollout
- FBI Jobs Portal Down 6 Days, PeopleSoft Bug Cited [2026]




