Hacker working on computer showing ransomware gang

ShinyHunters Hacks Rival Ransomware Gang Cl0p and Takes Over its Dark Web Tor Data Leak Site

The prolific ransomware gang ShinyHunters has hacked Cl0p and defaced its public-facing data leak site after allegedly taking over its infrastructure. ShinyHunters uploaded a small text file after exploiting an unauthenticated file-upload vulnerability in Grav, the content management system that Clop uses on its data leak site.

Grav is a PHP-based, open-source, flat-file content management system (CMS) that does not require a database system and stores content as files. Consequently, securing the CMS requires proper server and application configuration.

Additionally, Grav has disclosed security vulnerabilities in Twig sandboxing, IIS configuration, and privilege escalation, which could allow unauthenticated attackers to gain access.

ShinyHunters PWNs Clop ransomware gang

ShinyHunters bragged about hacking Clop, a rival ransomware gang, after allegedly taking over its IT infrastructure after compromising a file upload vulnerability in Grav. The ransomware gang also posted a “domain seized by ShinyHunters” message before the site became unavailable. In a classic case of the “hunter becoming the hunted,” the Clop ransomware gang reportedly reached out to ShinyHunters to negotiate.

“Shiny Hunters we trying to reach you Your email does not work. Come online old platform no email,” Clop ransomware wrote.

Meanwhile, ShinyHunters claims to have obtained important files, including server logs, source code, Grav plugins, and Cl0p’s Tor service private keys. If the hacking allegations were true, ShinyHunters could use the stolen private keys to access Cl0p’s Tor platform and impersonate the rival ransomware gang.

Additionally, ShinyHunters repurposed Cl0p’s data leak site and published Salesforce data for download. The ransomware group demanded an eight-figure sum from the sum that Cl0p earned after weaponizing the Oracle Business Suite zero-day vulnerability. The ransomware group also demanded interest and an extra amount from the Oracle EBS hack.

Ransomware gangs clash over Oracle E-Business Suite zero-day software vulnerability

The hack seemed to stem from an existing feud between the two rival ransomware gangs over CVE-2025-61882, the Oracle E-Business Suite (EBS) zero-day vulnerability, for which both groups claim to have discovered. The critical vulnerability (CVSS V3 9.8) in the EBS BI Publisher Integration could enable an unauthenticated attacker to take over Oracle’s Concurrent Processing.

Besides the contested EBS data breach, Clop has built a reputation for compromising managed file transfer (MFT) systems to carry out large-scale data exfiltration. In 2023, Clop claimed responsibility for exploiting MOVEit Transfer and GoAnywhere MFT systems. It also exploited the Accellion File Transfer Application (FTA) in 2021 and the Cleo file transfer system in 2024, collectively impacting approximately 200 organizations.

ShinyHunters has also carved out a name for itself in cybersecurity by carrying out large-scale data exfiltration by targeting widely used enterprise software solutions, SaaS products, cloud environments, and identity providers. The ransomware gang employs phishing and social engineering tactics to gain initial access before pivoting to other systems.

In 2025, it stole over 1.5 billion records after breaching Salesloft Drift by exploiting stolen OAuth credentials. It also accessed over 285 records after breaching exposed Salesforce instances.

Some high-profile entities breached by ShinyHunters include Rockstar Games, Telus, the European Commission, Air France/KLM, Cisco, Allianz Life, Qantas, PowerSchool, Neiman Marcus, AT&T, Santander, Ticketmaster, Tokopedia, Wattpad, and Bonobos.