Security1 publisher2 min readPublished
ShinyHunters claims the private keys to Clop's onion address after defacing the leak site
BleepingComputer confirmed the defacement and the file ShinyHunters uploaded to Clop's Tor site. The stolen logs and the onion keys are so far only the attacker's account, and Clop has 72 hours to make contact.
The Watch · Security desk

What happened
- ShinyHunters began the attack on Friday night and got in through what it says is an unauthenticated file upload vulnerability in Grav CMS, using it to upload a small text file to Clop's leak site.
- Several hours later the site had been replaced with ASCII art of Umbreon, the Pokemon used as ShinyHunters' logo, alongside a link to the group's own Tor site.
- ShinyHunters told BleepingComputer it had full access to the server and took source code, Grav CMS plugins, system logs and other data that it was still downloading and reviewing.
- BleepingComputer confirmed the defacement and the uploaded file, and did not independently verify the claimed theft of server logs, source code or Clop's onion private keys.
- Clop exploited several Oracle E-Business Suite vulnerabilities in October 2025, including the zero-day CVE-2025-61882, in data theft and extortion campaigns.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- capability Whoever holds an onion service's private keys can serve that address from their own hardware, so evicting an intruder from the box does not return control of the URL to its operator.
- exposure Every host that connected to Clop's leak site, victim-side responders included, is exposed in a copied log set if the /var/log claim holds.
- contradiction The only description of the Grav CMS flaw comes from the attacker, with no identifier or affected version, so anyone running Grav has nothing to check their own installation against.
- decision Clop now has to choose inside 72 hours between negotiating with ShinyHunters and abandoning the onion address that victims and researchers know it by.
ShinyHunters told BleepingComputer, "We have their onion keys. So if they kick us out it wouldn't matter at all because we control the private keys to host the same exact onion URL" [8]. BleepingComputer said that if the keys are valid, the group could run a Tor site at Clop's existing onion address from servers it controls [9]. Researchers and responders treat a listing at a known leak-site address as the gang's own publication. Once two parties can serve one address, a post there does not establish who wrote it [20].
The evidence is uneven across the five outcomes ShinyHunters described. Two are confirmed: the uploaded file, which BleepingComputer downloaded directly from Clop's Tor site [4], and the defacement. The source code and Grav plugins, the contents of /var/log, and the onion keys rest on the group's own account [19].
The retrievable file does establish one thing. An attacker could write into a path that Clop's web server then handed back to any visitor [22]. The file read: "THIS SITE HAS BEEN PWN3D BY SHINYHUNTERES #Skids10p - Maybe don't try to threaten us next time" [3].
ShinyHunters also says it took every file under /var/log, which can hold system activity, authentication records, and the IP addresses of hosts that connected to the site [7]. As of the report, the defaced page was still being served from Clop's own infrastructure, according to the group [18].
The dispute has a paper trail. Around the time of the Oracle campaign, actors calling themselves Scattered Lapsus$ Hunters, ShinyHunters among them, leaked a proof-of-concept exploit that Oracle later confirmed matched the one used in the Clop attacks, and ShinyHunters said the exploit had been theirs and that Clop took it without authorization [15]. The group says a Clop representative then threatened to identify its members and made violent threats after ShinyHunters disrupted a Clop data theft campaign [16]. Researcher VXDB told BleepingComputer that the Umbreon artwork now on Clop's site is the same image used in the August 2020 defacement of HackForums, which ShinyHunters also claimed at the time [13].
ShinyHunters said it would post a message on its own leak site telling Clop to make contact within 72 hours [12]. Asked what it planned to do with the stolen data, the group said, "Going to extort them." [11]
What to watch
- Whether Grav publishes an advisory or a CVE matching the unauthenticated upload path ShinyHunters describes.
- Whether Clop's existing onion address later resolves to content ShinyHunters controls, which would test the key claim.
- Whether ShinyHunters publishes anything from /var/log identifying hosts that connected to the leak site.