Skip to content
ransomwarevulnerability

Cl0p gets extorted: how ShinyHunters seized a ransomware gang's dark web infrastructure

2 min read
Share

Cl0p gets extorted: how ShinyHunters seized a ransomware gang's dark web infrastructure

On September 18, 2026, ShinyHunters exploited an unauthenticated file-upload vulnerability in Grav CMS to take over the dark web leak site operated by Cl0p, one of the most prolific ransomware groups of the past three years. ShinyHunters defaced the site, claimed to have exfiltrated Cl0p's source code, server logs, and Tor private keys, and then did something rare in the criminal ecosystem: it turned around and extorted the extortionists.

The attack

ShinyHunters replaced Cl0p's site with a defacement page featuring a Pokemon image and the text 'THIS SITE HAS BEEN PWN3D BY SHINYHUNTERS'. The group then issued a 72-hour extortion demand framed as 2.333% of Cl0p's own stated net worth, which ShinyHunters valued at an eight-figure sum. The group threatened to publish records from Cl0p's Oracle EBS campaign showing which companies paid ransoms, how much they paid, and the cryptocurrency wallets that received those payments. The 72-hour deadline has now passed with no indication that Cl0p met the demand.

Why this matters for Cl0p victims

If ShinyHunters publishes the payment records it claims to hold, organizations that paid Cl0p ransoms face a second round of exposure. Payment data in the context of a ransomware incident is commercially and legally sensitive in most jurisdictions: it implies the ransom was paid without necessarily disclosing it, may trigger regulatory inquiry, and creates reputational risk independent of the original breach. Organizations that were previously listed on Cl0p's leak site, or that had any contact with Cl0p, should monitor developments closely over the next 48-72 hours.

What the Grav CMS flaw tells us

Ransomware operators run infrastructure, and that infrastructure has vulnerabilities. The lesson here is not that criminals are incompetent; it is that the attack surface of a criminal operation built on dark web infrastructure is not meaningfully different from any other web application. An unauthenticated file upload flaw in a CMS is a textbook web vulnerability. Cl0p spent years exploiting exactly these kinds of flaws in victim organizations. They were not immune to the same class of attack.

Gigia Tsiklauri is a Security Architect and founder of Infosec.ge. Get in touch if your organization has had prior contact with Cl0p and you need to assess your exposure.