Find notable cyber news and cases, enriched with sources, timelines, and signals.

Clop (aka Cl0p) hit by network compromise linked to ShinyHunters

Incident
First reported
Last updated
Happening score
H score 77
2 unique sources, 2 articles

Summary

Hide ▲

ShinyHunters breached and defaced Clop’s Tor-based data leak site on 18 September, replacing it with its own message and link after an alleged Grav CMS upload flaw. The group claimed full access to the server, said it stole server data, source code, /var/log files, and onion-service private keys, and threatened to extort Clop. The compromise is part of a 2025 feud between the groups tied to competing claims over Oracle E-Business Suite vulnerabilities, including CVE-2025-61882. The event disrupts Clop’s leak infrastructure and could expose operator activity and authentication records if the theft claims are accurate.

Related Happenings

IT services firm in South Asia hit by ransomware attack

Incident
H score31 First: 16.07.2026 13:00 Last: 16.07.2026 13:00 Sources 1

About this happening: The IT services firm in South Asia suffered a Spirals ransomware intrusion that moved from initial access to data theft and encryption in less than 24 hours, putti...

Charter Communications hit by network compromise linked to ShinyHunters

Incident
H score70 First: 26.05.2026 22:46 Last: 26.05.2026 22:46 Sources 1

About this happening: Charter Communications confirmed a data breach tied to ShinyHunters extortion, with the company saying it is alerting authorities and that no sensitive personal...

Latest development: 29.05.2026 11:29

Have I Been Pwned analyzed leaked Charter Communications data and confirmed that the incident affected 4.9 million accounts, with exposed records including names, email addresses, job titles, phone numbers, and physical addresses. The published data also included a subset of about 85,000 records from an internal employee directory.

Madison Square Garden hit by network compromise linked to Cl0p

Incident
H score38 First: 02.03.2026 15:53 Last: 02.03.2026 15:53 Sources 1

About this happening: Madison Square Garden confirmed a data breach that exposed names and SSNs, and it has started notifying affected people. The compromise involved a hosted Oracle E-Bu...

ShinyHunters data-leak site exposing stolen attack data

Data Leak
H score71 First: 31.01.2026 17:02 Last: 31.01.2026 17:02 Sources 1

About this happening: The ShinyHunters extortion gang is publishing stolen data on a data-leak site tied to its broader Oracle PeopleSoft theft campaign. New reporting adds the University...

ShinyHunters voice-phishing campaign targeting SSO accounts for extortion

Campaign
H score78 First: 24.01.2026 01:35 Last: 24.01.2026 01:35 Sources 1

About this happening: A ShinyHunters-linked extortion campaign is using voice phishing to target Salesforce customers and steal data for ransom, with the operation first surfacing in May...

Latest development: 27.04.2026 17:43

ShinyHunters breached ADT after compromising an employee's Okta single sign-on (SSO) account in a vishing attack, then used that access to reach ADT's Salesforce instance and steal data. Have I Been Pwned said the exposed data affected 5.5 million people and included names, phone numbers, addresses, and in a small percentage of cases dates of birth and partial Social Security numbers or Tax IDs; the group later leaked an 11GB archive after extortion failed.

Timeline

  1. 19.09.2026 16:48 1 articles · 2d ago

    ShinyHunters defaces Clop's Tor leak site through a Grav CMS upload flaw

    Exploitation Observed

    ShinyHunters is reported to have used an alleged unauthenticated file upload flaw in Grav CMS to place a text file on Clop's Tor-based leak site, then replace the page with Umbreon ASCII art and a link to its own leak site. BleepingComputer confirmed the upload and the defacement on the affected Clop infrastructure.

    Show sources
  2. 19.09.2026 16:48 3 articles · 2d ago

    ShinyHunters claims server data and onion keys after the Clop breach

    Victim Impact Update

    ShinyHunters said it had "full access" to the server and was reviewing allegedly stolen data while planning to extort Clop within 72 hours. The group claimed to have taken source code, Grav CMS plugins, system logs, /var/log files, and the private keys for Clop's onion service, but those theft claims were not independently verified.

    Show sources