Circuit Wire — a daily news update from the Circuit.
The ShinyHunters extortion group defaced the dark web leak site run by the Clop ransomware gang on Friday, September 18, and is now trying to extort the group it broke into. BleepingComputer confirmed the defacement and reported that the attack began with a small text file uploaded to Clop's server carrying the message: "Maybe don't try to threaten us next time."
ShinyHunters said it got in through what it describes as an unauthenticated file upload flaw in Grav CMS, the software running Clop's site. Hours later the page was replaced with the group's Pokemon logo artwork, a link to its own Tor site and the tagline "rooting your systems since '19." ShinyHunters told BleepingComputer it gained full access to the server and took source code, CMS plugins and system logs, and that it holds the private keys to Clop's onion address. If those keys are real, the group could run a site at Clop's existing address on infrastructure it controls. BleepingComputer verified the defacement and the uploaded file, but not the claims about stolen data or keys.
The demand followed. ShinyHunters set an eight-figure price, which it said represented 2.333 percent of Clop's net worth, then warned that the figure would rise every 24 hours Clop stayed silent. It added a demand for a public apology. It also threatened to publish the names of companies that allegedly paid Clop during the Oracle E-Business Suite extortion campaign, along with the amounts and the Bitcoin addresses involved. The Register reported that two security researchers assessed the clash as genuine, though the claims about payment records remain unverified.
Clop replied in public on September 21 with a short note posted on its own hijacked site, saying its email was not working and asking ShinyHunters to make contact on an older platform. ShinyHunters rejected the approach and repeated its demand.
The feud traces back to October 2025, when Clop exploited flaws in Oracle E-Business Suite servers, including a zero-day tracked as CVE-2025-61882, to steal data from corporate networks. ShinyHunters says the exploit was originally its own and that Clop took it without permission, and that a Clop representative later threatened members of the group. Clop is best known for the 2023 MOVEit campaign, which affected thousands of organizations and exposed information belonging to tens of millions of people. ShinyHunters has been linked to large-scale data theft and extortion at Ticketmaster, AT&T and Carnival, among others.
The Register reported that the defaced page was still being served from Clop's own infrastructure as of Monday, and that Clop had not otherwise commented on the breach.
Want a weekly roundup of the major stories shaping the security industry? The On The Circuit newsletter is read by more than 12,000 protection professionals.
Spotted something we should cover? Send tips and feedback via circuit-magazine.com.

