The Clop ransomware group has moved its dark web data-leak site to a new server this month after rival hackers calling themselves ShinyHunters breached the previous one, according to Cybersecurity Insiders.
Clop has shown no interest in paying the ransom ShinyHunters demanded and is instead considering retaliation against those responsible, Cybersecurity Insiders reported, citing BleepingComputer, which first reported the development.
ShinyHunters said it broke into Clop’s Tor-hosted leak site on Sept. 18, defacing it with ASCII art of Umbreon, a Pokemon character the group uses as its logo, and a message reading, “THIS SITE HAS BEEN PWN3D BY SHINYHUNTERES #Skids10p - Maybe don’t try to threaten us next time,” according to BleepingComputer’s initial report.
The group claimed it gained full access to Clop’s server and stole source code, Grav CMS plugins, system logs and the private keys to Clop’s onion service, BleepingComputer reported. It said it could not independently verify those broader theft claims, though it confirmed the defacement itself.
On Sept. 19, a message attributed to ShinyHunters demanded an unspecified eight-figure payment in bitcoin and told Clop to make contact through an Onionmail address, according to BleepingComputer. The note said the demand would rise every 24 hours Clop failed to respond and would eventually include “a mandatory apology issued directly to me PUBLICLY.”
Clop denied any relationship with its attackers. “We do not know them, we have never worked with them, and at the moment we are not in contact with them,” the group said in a message posted to its site, according to The Record. Clop also said the compromised server held only website content and no sensitive operational or financial data, The Record reported.
ShinyHunters told BleepingComputer the intrusion exploited an unauthenticated file-upload flaw in Grav CMS, the content management system running Clop’s leak site, which was on version 1.7.43. The group said a form parameter called __unique_form_id__ was inserted into a temporary file path without being checked, letting an attacker use directory-traversal sequences to place files outside the intended upload folder.
Grav’s developers confirmed the flaw after BleepingComputer shared the technical details, saying, “Yes, it’s a legitimate flaw, and the threat actor’s description is accurate.” The issue is tracked as CVE-2026-42608. Grav said it had fixed the bug in version 2.0.0-beta.2 in April but never backported the patch to the older 1.7 line that Clop was running; it has since released version 1.7.53.4 to close the gap.
BleepingComputer and other outlets have linked the attack to an ongoing feud between the two criminal groups, reportedly triggered by threats a Clop representative made toward ShinyHunters members, against the backdrop of Clop’s 2025 campaign exploiting Oracle E-Business Suite to steal data from corporate victims. ShinyHunters separately claimed this month to have breached FBI systems, saying it wanted a public correction rather than a ransom payment.
Clop’s old leak-site address is expected to remain reachable for a period before being retired in favor of the new one, according to BleepingComputer. Neither group has disclosed further contact, and Cybersecurity Insiders reported that Clop’s planning for possible retaliation could open a new round of attacks between the two operations.

