ShinyHunters says it hijacked Cl0p’s dark web leak site
ShinyHunters claims to have defaced Cl0p's dark web leak site, citing an unauthenticated file-upload flaw in Grav. They assert possession of Cl0p's source code and private keys, threatening further extortion. Both groups have a history of significant cyberattacks.
- 1. ShinyHunters claims to have defaced the Cl0p ransomware gang's dark web leak site, replacing its content with Pokémon artwork and a message stating "THIS SITE HAS BEEN PWN3D BY SHINYHUNTERS."
- 2. ShinyHunters alleges they gained access through an unauthenticated file-upload flaw in Grav, the content management system used by Cl0p, and claims to have obtained Cl0p's source code, plugins, and system logs.
- 3. The conflict between ShinyHunters and Cl0p appears to stem from a dispute over a zero-day exploit in Oracle's E-Business Suite, with ShinyHunters claiming the exploit was originally their work.
Catch up on The Next Web articles in minutes
skim analyzes recent The Next Web coverage for what holds up, what reads as opinion, and what may not be fully supported. Last updated 21st September 2026.