On the night of Friday, September 18, the Tor leak site that the Cl0p ransomware gang used to name and pressure its victims was defaced. Another criminal group claimed responsibility, according to BleepingComputer.
When people visited the site, they saw Pokémon artwork, an ASCII Umbreon, above the message “THIS SITE HAS BEEN PWN3D BY SHINYHUNTERS” and the sign-off “rooting your systems since ’19”.
The post also included a link to ShinyHunters’ own leak platform. BleepingComputer confirmed that the defacement was active on Cl0p’s infrastructure and that the attackers uploaded a downloadable file.
The artwork acts as a kind of signature. The researcher VXDB matched the same Umbreon image to a HackForums defacement in August 2020, which ShinyHunters also claimed. This is a clue for attribution, not proof, and it marks the end of what this story can verify.
The group says it got in through an unauthenticated file-upload flaw in Grav, the content management system behind the leak site, and from there took Cl0p’s source code, plugins, and system logs.
ShinyHunters claims to have the private keys to Cl0p’s onion service, which would allow it to impersonate the gang’s dark web address. No one has shown proof of this, and security analysts note that this is the one unproven detail that could change the story if confirmed.
Along with these claims, ShinyHunters gave a 72-hour ultimatum, threatening to extort another extortion group.
The conflict seems to go back to October 2025, when Cl0p used a zero-day exploit in Oracle’s E-Business Suite. Since then, ShinyHunters has claimed the exploit was originally their work. This is a criminal’s claim about a crime involving a rival group.
Both groups have a history of attacks. Cl0p led the MOVEit Transfer campaign in 2023, affecting over 2,000 organizations, and had earlier campaigns against GoAnywhere and Accellion.
In 2026, ShinyHunters targeted several companies, including a phone company that lost 1.6 million records and, in June, more than 100 firms through Oracle PeopleSoft.
Cl0p has not commented, and the group did not respond to requests from BleepingComputer or Hackread. There are also reports that ShinyHunters’ own site later went offline, but no one has linked this to retaliation.
So far, the only things that can be confirmed are the defaced web page and a file upload. The stolen source code, server access, and Tor keys are only mentioned by the group claiming responsibility.
Get the TNW newsletter
Get the most important tech news in your inbox each week.