ShinyHunters has hacked and defaced the data leak site operated by the Cl0p ransomware group, turning the infrastructure of one of the world’s most established cyber extortion operations into the target of an extortion attempt of its own.
The attack unfolded between Sept. 18 and Sept. 19, 2026, when ShinyHunters gained access to Cl0p’s Tor-based leak site and initially uploaded a small file containing a warning directed at the ransomware operation.
The compromise subsequently escalated into a full defacement. Cl0p’s normal leak site was replaced with ShinyHunters branding, including the group’s Umbreon artwork and a message claiming it had compromised the infrastructure.
ShinyHunters claims it obtained full access to the underlying server and stole source code, content management system plugins, system logs and the private keys associated with Cl0p’s Tor onion service. The group says it is reviewing the allegedly stolen material and intends to extort Cl0p, giving the ransomware operation 72 hours to make contact.
The visible compromise of Cl0p’s site has been independently verified. However, ShinyHunters’ more extensive claims about the information and cryptographic keys it allegedly stole have not been independently confirmed.
Cl0p leak site completely defaced
The intrusion initially became visible after ShinyHunters uploaded a small text file directly to the server hosting Cl0p’s leak site.
The file contained a warning directed at Cl0p and pointed visitors toward ShinyHunters’ own infrastructure. Its presence was independently verified by downloading the file directly from Cl0p’s Tor service, demonstrating that the attackers had obtained at least enough access to place content on the ransomware group’s server.
Several hours later, the compromise expanded substantially.
Cl0p’s normal data leak site disappeared and was replaced by a ShinyHunters-controlled defacement featuring ASCII artwork of Umbreon, a character the group has repeatedly used as part of its online identity.
The defacement also redirected attention toward ShinyHunters and claimed the group had been compromising systems since 2019.
The ability to replace the contents of the site provides clear evidence that Cl0p lost control of at least part of the infrastructure used to operate its public extortion platform.
ShinyHunters claims it stole Cl0p server data
ShinyHunters claims the compromise extended far beyond changing the site’s appearance.
The group says it obtained full access to the server and began downloading internal data, including source code and plugins associated with the Grav content management system used by the Cl0p site.
ShinyHunters also claims it obtained system logging data from the server.
Those logs could be particularly damaging to a cybercrime operation. Depending on the configuration and retention of the server, logging information could potentially contain authentication activity, administrative events, connection information and IP addresses associated with systems that interacted with the infrastructure.
There is currently no independent confirmation of what the logs contain or whether they expose infrastructure or individuals associated with Cl0p.
ShinyHunters said it was continuing to download and review information from the compromised server following the defacement.
Claimed theft of Tor private keys could create bigger problem
One of the most consequential claims involves the cryptographic private keys used by Cl0p’s Tor onion service.
ShinyHunters claims it obtained those keys during the compromise.
If authentic, possession of the private keys could potentially allow the group to operate infrastructure using Cl0p’s existing onion identity, significantly complicating Cl0p’s ability to regain trusted control of its established leak-site address.
Simply removing ShinyHunters from the original server would therefore not necessarily resolve the problem if the private key material was successfully stolen.
The private-key claim has not been independently verified. The confirmed defacement demonstrates substantial access to Cl0p’s web infrastructure, but it does not by itself establish that ShinyHunters successfully obtained the onion-service keys.
ShinyHunters threatens to extort the extorters
ShinyHunters says it now intends to use the allegedly stolen information against Cl0p in an extortion attempt.
The group plans to give Cl0p approximately 72 hours to make contact before potentially releasing information obtained during the intrusion.
The situation represents an unusual reversal of the model used by both operations against corporate victims. Cl0p has spent years stealing information from organizations and threatening publication through the same leak infrastructure that has now been compromised.
ShinyHunters has increasingly adopted a similar public extortion strategy, using deadlines, threatened data releases and additional pressure against organizations it claims to have breached.
The latest incident applies those tactics directly against another major cybercrime operation.
Feud traces back to Oracle E-Business Suite attacks
ShinyHunters claims the attack was retaliation for threats made during an ongoing dispute with Cl0p that dates back to the ransomware group’s 2025 Oracle E-Business Suite campaign.
Cl0p was linked to a large-scale data theft and extortion operation targeting Oracle E-Business Suite environments through vulnerabilities that included CVE-2025-61882.
The critical vulnerability affects Oracle E-Business Suite versions 12.2.3 through 12.2.14 and carries a CVSS score of 9.8. Oracle said the flaw could be remotely exploited without authentication and could result in remote code execution.
During the campaign, organizations received extortion messages claiming that information had been stolen from their Oracle environments.
A proof-of-concept exploit subsequently circulated through a channel associated with actors including ShinyHunters. Oracle later included hashes associated with that exploit package among indicators of compromise in its security advisory.
ShinyHunters has claimed the exploit originally belonged to it and that Cl0p obtained it without authorization. That allegation has not been independently established.
The group says tensions escalated after the Oracle campaign and claims a Cl0p representative later threatened members of its operation.
Compromise could expose Cl0p operational security
The longer-term significance of the breach will depend heavily on whether ShinyHunters actually obtained the internal material it claims to possess.
A defaced leak site is disruptive and embarrassing for a ransomware operation, but stolen server logs, source code and cryptographic keys could potentially have more serious consequences.
Infrastructure logs could provide investigators and security researchers with new information about how the site was administered or accessed. Source code and configuration information could reveal additional infrastructure or operational practices, while valid Tor private keys could undermine Cl0p’s control over its established onion identity.
At the same time, threat actors routinely exaggerate the scope of compromises during extortion campaigns. The confirmed evidence currently establishes that ShinyHunters gained access sufficient to upload content and subsequently deface Cl0p’s leak site.
Claims that the group obtained full server contents, system logs and Tor private keys remain unverified.
The incident nevertheless represents a rare case in which the infrastructure supporting a major ransomware operation has itself become the target of a public breach and extortion campaign.
Attention now turns to ShinyHunters’ 72-hour deadline and whether the group follows through by publishing material that could establish how deeply Cl0p’s infrastructure was compromised.












