Skip to content
feed: live
>_0dayNews
ransomware
● Breaking

ShinyHunters Breaches Clop Tor Site, Steals Onion Keys

ShinyHunters defaced Clop's data leak site Friday via a Grav CMS upload flaw, claiming server data and private onion keys. A 72-hour extortion deadline is running.

ShinyHunters Breaches Clop Tor Site, Steals Onion Keys
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
airgapMorgan "airgap" Reyes·Published ·1 min read

Confirmed: ShinyHunters defaced Clop’s Tor-based data leak site on Friday night. The site displayed Umbreon ASCII art, consistent with ShinyHunters’ signature from a 2020 HackForums defacement. Security researcher VXDB confirmed the match. BleepingComputer independently verified the defacement and the initial uploaded file.

Attack vector: an unauthenticated file upload vulnerability in Grav CMS, the software powering Clop’s site.

ShinyHunters claims to have taken the following:

  • Source code and Grav CMS plugins from the server
  • System logs from /var/log, including authentication activity
  • Private encryption keys for Clop’s onion service

The onion key claim is unconfirmed by any third party. ShinyHunters stated: “We have their onion keys. So if they kick us out it wouldn’t matter.” Analysis: if accurate, ShinyHunters could operate Clop’s dark web address independently of server access. That has not been verified.

ShinyHunters is demanding Clop contact them within 72 hours of Friday, September 19. If Clop does not respond, ShinyHunters says it will publish the stolen data on its own leak site. Clop had not responded as of publication.

What is at stake

Clop runs a data extortion operation. Its site hosts victim data published to pressure ransom payments. The stored logs, if ShinyHunters actually has them, could include victim communications and records of Clop’s own attack operations. Confidence on the contents: unconfirmed.

No CVE identifiers were assigned to this incident at time of publication.

ShinyHunters is a persistent data theft group with a broad target history. The group set a payment deadline in the McKesson breach earlier this month and ran sextortion campaigns tied to earlier breach data. Clop’s recent activity includes a Shell data theft claim involving 89 GB of exfiltrated data. This incident sits in the ransomware beat where both groups have been active throughout 2026.

Found this useful? Share it.