The prolific Clop ransomware gang has seen its own operations targeted by rival extortionists, as the hacking group ShinyHunters claimed responsibility for compromising and defacing Clop’s Tor-based data leak site. The intrusion, which took place between September 18 and 19, 2026, was punctuated by the appearance of ShinyHunters’ signature ASCII art—the Pokémon Umbreon—replacing the usual list of ransomware victims.
The breach exploited a critical flaw in Grav CMS, the software underlying Clop’s public-facing infrastructure. According to security researchers and technical data, the attackers utilized CVE-2026-74907, an unauthenticated path traversal vulnerability. This specific weakness resides in the CMS’s static asset server within the index.php file, allowing an attacker to navigate the directory structure and access sensitive system files that should remain restricted.

The scope of the compromise appears extensive. ShinyHunters reported the theft of several high-value assets, including the site’s source code, system logs (/var/log) potentially containing the IP addresses of site visitors, and critical Tor onion private keys. Access to these keys theoretically allows the attackers to hijack the site’s address or impersonate Clop’s infrastructure. Perhaps most damaging for Clop’s ongoing operations is the alleged theft of victim negotiation logs, which could expose private settlement discussions and the identities of currently affected organizations.
A Growing Criminal Feud
This incident is not a random act of opportunistic hacking but rather a significant escalation in a year-long conflict between the two groups. Analysis of the rivalry suggests the tension dates back to a 2025 dispute involving an Oracle E-Business Suite exploit. ShinyHunters and their associates reportedly accused Clop of “misusing” or deploying that exploit without authorization from its original developers, leading to a breakdown in the perceived “honor among thieves” that occasionally governs top-tier cybercriminal circles.
The fallout from the breach has moved from technical defacement to direct extortion. ShinyHunters has reportedly set a 72-hour deadline for Clop to pay a ransom. Failure to comply, the group warns, will result in the public release of Clop’s internal operational data and the logs of their negotiations with corporate victims. As SC Media reported, the defacement served as a public demonstration of the breach’s validity, placing Clop in the unusual position of being the victim of the same extortion tactics they typically leverage against others.
For organizations currently listed on Clop’s site or those in active negotiations with the gang, the breach introduces a new layer of risk. If ShinyHunters follows through on their threat to leak the negotiation history, victims could face double-extortion from a second, independent party or see their private data exposed regardless of any payments made to Clop. The incident highlights a critical irony in the ransomware ecosystem: while these groups demand millions to secure their victims’ data, their own reliance on common, unpatched software vulnerabilities can leave their entire operational history exposed to rivals.
