Global Edition
Global Edition
UK Edition
EU Edition
US Edition

Understand the story, not the spin.

Markets

Cl0p Leak Site Defaced in Attack Claimed by Rival ShinyHunters

Published 21 September 2026

The Cl0p ransomware gang's dark web leak site was defaced on September 18, 2026, in an attack claimed by the rival ShinyHunters extortion group. The incident, which has been confirmed by independent verification, marks a rare public confrontation between two major cybercriminal operations. Visitors to Cl0p's Tor onion address on Friday night were greeted with a page displaying ASCII artwork of the Pokémon Umbreon, a known ShinyHunters signature, along with the message "THIS SITE HAS BEEN PWN3D BY SHINYHUNTERS" and a link to the group's own leak platform. Security researchers confirmed the defacement was active on Cl0p's infrastructure and that a malicious text file had been uploaded to the server. ShinyHunters has claimed responsibility for the breach, stating it exploited an unauthenticated file upload vulnerability in Grav CMS, the content management system powering Cl0p's leak site. The group alleges it gained full access to the server, stealing source code, system logs, and, most significantly, the private keys for Cl0p's Tor onion service. If valid, these keys would allow ShinyHunters to operate a site using Cl0p's exact dark web address on its own servers.

0:00 / 0:00