ShinyHunters' defacement and immediate evidence
On Friday night, visitors to Clop's Tor data leak site found the page replaced by ASCII art of Umbreon — the Pokémon image ShinyHunters uses as its logo — and a defacement message that included a link to ShinyHunters' Tor site and the line "rooting your systems since '19 ;)." BleepingComputer confirmed both the earlier uploaded text file and the later defacement page on Clop's server.
ShinyHunters told BleepingComputer it had "completely defaced" the site, and the group says the defaced page continues to be served from Clop's infrastructure "at the time of this writing." VXDB, a cybersecurity researcher, told BleepingComputer the Umbreon artwork now displayed matches the image used in the August 2020 defacement of the HackForums website, which ShinyHunters had claimed at the time.
Claims of full server access, stolen logs, and onion private keys
ShinyHunters told BleepingComputer it gained "full access" to Clop's server and began downloading files it claims include source code, Grav CMS plugins, and other items. The threat actor also said it had stolen files under /var/log — which, the group noted, could contain system activity, authentication logs, and potentially IP addresses of connecting hosts.
Most strikingly, ShinyHunters claims to have obtained the private keys used by Clop's Tor onion service. "We have their onion keys. So if they kick us out it wouldn't matter at all because we control the private keys to host the same exact onion URL," the group told BleepingComputer. If accurate, those keys would allow the actors to host an identical onion address on their own infrastructure.
BleepingComputer independently confirmed the defacement and the earlier uploaded file, but has not independently verified ShinyHunters' broader claims of stolen server logs, source code, or onion private keys.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadExploit vector: alleged Grav CMS unauthenticated file upload
ShinyHunters said the intrusion began when it exploited what the group claims was an unauthenticated file upload vulnerability in Grav CMS. Using that vector, the group said it uploaded a small text file to Clop's site; the file contained the taunting message and a link to ShinyHunters' leak site. BleepingComputer was able to download the uploaded file directly from Clop's Tor site and confirmed its presence.
Feud traced to Clop's 2025 Oracle E-Business Suite campaign
ShinyHunters characterized the attack as retaliation for threats allegedly made by a Clop representative during an ongoing dispute between the groups. The contention, the group said, dates back to Clop's 2025 campaign targeting Oracle E-Business Suite (EBS) servers.
According to ShinyHunters, in October 2025 Clop exploited multiple vulnerabilities in Oracle EBS — including a zero-day tracked as CVE-2025-61882 — to steal data used in extortion campaigns. Around that time, entities calling themselves "Scattered Lapsus$ Hunters," which included ShinyHunters, leaked a proof-of-concept exploit that Oracle later confirmed matched an exploit used in the Clop attacks. ShinyHunters told BleepingComputer the exploit had originally belonged to them and that Clop obtained it without authorization.
ShinyHunters also relayed a personal, translated threat it says came from a Clop representative: "I have more money than you and all of your people combined, I'll kill you soon." BleepingComputer has not independently verified these allegations and has contacted Clop for comment.
How Clop, security teams, and researchers are positioned
- Clop (the ransomware gang): If ShinyHunters' claim about the onion private keys is accurate, Clop could lose practical control of its leak site's onion address and face a new extortion vector from another criminal group. ShinyHunters has said it will publish a message on its leak site instructing Clop to contact them within 72 hours.
- Security teams and defenders: BleepingComputer's confirmation of a file upload and site defacement provides an observable indicator; however, the broader claims of data exfiltration and key theft remain unverified. Teams tracking access to Grav CMS instances and any exposed /var/log repositories linked to known Clop infrastructure may find relevant forensic artifacts.
- Cybersecurity researchers: VXDB's note that the Umbreon artwork matches a previous 2020 defacement may help attribution of the defacement to ShinyHunters and offers a data point for those compiling behavior and artifact timelines among criminal groups involved in leak-site operations.
ShinyHunters told BleepingComputer it is "still downloading and reviewing" the files it claims to have taken and stated its intent: "Going to extort them." BleepingComputer has reached out to Clop for comment and said it will update its reporting if a response is received. The immediate facts — a confirmed upload and an ongoing defacement — sit beside unverified but consequential claims about stolen logs and onion keys, leaving a short, high-stakes countdown before ShinyHunters says it will demand contact.
Source: BleepingComputer — ShinyHunters hacks Clop leak site, threatens to extort ransomware gang



