Clop Moves Leak Site After Grav CMS Attack Confirmed
Clop ransomware confirmed its Tor leak site was breached via an unpatched Grav CMS path traversal flaw. The group has migrated to a new Tor address.

Clop has migrated its data leak site to a new Tor address. The move follows the ransomware group’s own confirmation that its previous server was compromised and defaced via an unpatched path traversal vulnerability in Grav CMS. BleepingComputer reported the confirmation on September 25, 2026.
Confirmed. Clop acknowledged the breach vector: Grav CMS, running unpatched on their leak-site infrastructure, exploited through a path traversal flaw. The group has relocated their victim publication site to a fresh onion address.
What changed since the initial breach:
The compromise was first observed September 20. At that point, ShinyHunters claimed access to Clop’s Tor-hosted server and the exfiltration of onion private keys. By September 22, ShinyHunters had pivoted to using the stolen victim data as leverage, directly contacting Clop victims whose files they now held. Now, as of September 25, Clop has publicly confirmed the attack vector and announced the infrastructure move.
The flaw. Grav CMS is an open-source flat-file content management system. A path traversal vulnerability allows an attacker to read or write files outside the intended web root. No CVE identifier for this specific flaw has been cited in available reporting; Clop’s confirmation of “Grav CMS” as the vector comes via their own statement to BleepingComputer. Confidence: medium. The specific patch status of Clop’s former Grav installation and whether a public CVE exists remain unconfirmed in open sources as of this writing.
For affected organizations. Victims whose data appeared on Clop’s former site should note: Clop is operational on a new address, and ShinyHunters holds an independent copy of data from the compromised period. The extortion surface has widened to include two separate threat actors. Organizations with prior Clop exposure should treat the situation as unchanged in terms of risk, or elevated.
Context. Sophisticated threat actors running unpatched CMS software on their own public infrastructure is a documented pattern. Operational security lapses are not unique to less capable groups. Clop’s quick migration suggests the group has functional redundancy procedures.
Earlier coverage: ShinyHunters Breaches Clop Tor Site, Steals Onion Keys (September 20) and ShinyHunters Extorts Cl0p, Victim Data at Risk (September 22). See also the ransomware topic hub for related coverage.
Found this useful? Share it.


