Product1 publisher2 min readPublished
ShinyHunters says a Grav upload flaw got it inside Cl0p's leak site
BleepingComputer confirmed a defaced page and an uploaded file on Cl0p's infrastructure. Everything past that is a criminal crew's own inventory, and the route it describes runs through the content layer.
The Product Desk · Product desk

What happened
- The Cl0p leak site was defaced on the night of Friday, September 18, showing an ASCII Umbreon above the message "THIS SITE HAS BEEN PWN3D BY SHINYHUNTERS" and the sign-off "rooting your systems since '19".
- The group also claims to hold the private keys to Cl0p's onion service, which would let it impersonate the gang's dark web address; the claim remains unproven.
- Cl0p has stayed silent and did not respond to requests from BleepingComputer or Hackread. ShinyHunters' own site is reported to have gone offline later, with no link to retaliation.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- exposure A victim who negotiates at Cl0p's familiar onion address has no way to tell who is reading the messages if the key claim is true, so impersonation is cheap for whoever holds them.
- decision Anyone briefing an executive on this has to decide whether to repeat a criminal group's inventory of what it took when the confirmed record is one defaced page and one uploaded file.
- constraint A CMS patch cycle usually sits outside the application team's release calendar, so the least-owned hostname sets the timetable for everything that shares its host and deploy account.
- precedent Extortion crews can now expect their own publishing infrastructure to be a target for rivals, complete with a countdown pointed back at them.
Grav is the software that put the victim names on the page. On ShinyHunters' account, an unauthenticated file-upload flaw in it was the entry point, and the trip from there to Cl0p's source code, plugins and system logs was short [5].
BleepingComputer confirmed that the defacement was live on Cl0p's infrastructure and that the attackers uploaded a downloadable file [4]. The source code, the server access and the Tor keys are in the story because the crew that did the defacing said they were [12]. The researcher VXDB matched the Umbreon image on the page to a HackForums defacement in August 2020 that ShinyHunters also claimed [6]. That match is a clue for attribution and stops there [7].
Counted from the Friday night defacement, the 72-hour clock ran out on Monday night, September 21 [16]. Cl0p has stayed silent in public and did not answer questions from BleepingComputer or Hackread [13]. The dispute appears to date to October 2025, when Cl0p used a zero-day in Oracle's E-Business Suite, an exploit ShinyHunters says was its own work first [15].
Both crews make their money on other people's software. Cl0p ran the MOVEit Transfer campaign in 2023, which affected more than 2,000 organizations, after earlier campaigns against GoAnywhere and Accellion [10]. ShinyHunters, over 2026, hit a phone company that lost 1.6 million records and, in June, more than 100 firms through Oracle PeopleSoft [11].
A box like that one gets written off as brochureware, on the grounds that the real data lives elsewhere and the blast radius is a defaced homepage. A CMS can reach whatever else the same host and the same deploy account can touch. Two questions sort internet-facing hostnames: whether an unauthenticated user can write a file to them, and whether a named person gets paged when they break. The hostnames that accept writes with nobody's name against them go first, ahead of the application the pen test budget was written for.
What to watch
- Proof of the onion private keys, such as a signed message from Cl0p's old address, would move that claim from boast to fact.
- Any statement from Cl0p, silent so far to both BleepingComputer and Hackread.
- Whether ShinyHunters' own leak platform stays offline; nobody has tied the reported outage to retaliation.