ShinyHunters defaces Cl0p's leak site and claims it grabbed the gang's Tor keys

The extortion crew says it walked out with source code, server logs, and the private keys that identify Cl0p's dark-web address. The fight traces back to a stolen Oracle exploit.

ThreatVectr Newsdesk· Editor: Lee Brown· 4 min read
Full-frame edge-to-edge photoreal image of a dimly lit server rack in a data centre, one blade server pulled halfway out, a single red status LED glowing among
Share

Key points

  • A rival extortion crew called ShinyHunters hijacked Cl0p's public shaming site on Friday night, replacing it with ASCII art of Umbreon, the Pokémon used as ShinyHunters' logo, and a taunt, and claims it also stole the cryptographic keys that prove ownership of Cl0p's dark-web address.
  • ShinyHunters says it got in through an unauthenticated file-upload flaw in Grav CMS, the website software Cl0p was running its leak site on.
  • The feud traces back to CVE-2025-61882, a critical Oracle E-Business Suite bug that Cl0p exploited in October 2025 to steal data from Oracle customers.
  • CISA added the flaw to its Known Exploited Vulnerabilities list and gave federal agencies a patch deadline, signalling active exploitation in the wild.
  • Threat Vectr's own leak-site tracking has recorded Cl0p victims claimed since July, with the Technology sector hit most often.

One criminal gang just publicly humiliated another, and it's worth paying attention because it started with a real vulnerability that's still hitting real companies.

The defaced site belongs to Cl0p, a Russian-speaking ransomware crew (ransomware is malicious software that locks or steals a company's files until the victim pays). Cl0p runs a "leak site" on the Tor network, the anonymised part of the internet reached through special browsers, where it names victims and dumps stolen files to pressure them into paying.

Friday night, that site was replaced with ASCII art of Umbreon and the line "rooting your systems since '19". ShinyHunters told BleepingComputer it exploited an unauthenticated file-upload flaw in Grav CMS, the open-source content management system Cl0p was hosting the site on. Once inside, ShinyHunters says it pulled source code, Grav CMS plugins, and everything stored under /var/log, the folder where Linux servers keep activity and authentication records.

Why does this actually matter to anyone outside the two gangs?

Because the fight is over a live vulnerability that's still being used to break into corporate systems.

The bug is CVE-2025-61882, a flaw in Oracle E-Business Suite, the software package many large companies use to run finance, HR operations, and supply-chain management. Oracle published the advisory in October 2025. The flaw sits in the BI Publisher Integration component and lets an attacker with nothing more than network access take over the affected system without a username or password. We first covered CVE-2025-61882 on 20 July 2026, before it became a ransomware gang's weapon of choice.

CISA added it to its Known Exploited Vulnerabilities list and gave federal agencies a patch deadline. That deadline is a signal to everyone else: this one is being used right now.

Cl0p exploited the flaw in October 2025 to steal data from Oracle customers. ShinyHunters says the working exploit was originally theirs and that Cl0p took it without permission. Oracle later confirmed that a proof-of-concept leaked by a group calling itself Scattered Lapsus$ Hunters matched what Cl0p was using in the wild.

What did ShinyHunters actually take?

The interesting claim is the onion keys.

Every Tor hidden service is identified by a long address ending in .onion, and control of that address is proved by a private cryptographic key kept on the server. If ShinyHunters really has Cl0p's key, as it told BleepingComputer, it can stand up a copy of Cl0p's leak site at the same address on servers it controls. Anyone visiting the old link would land on the impostor. BleepingComputer confirmed the site takeover but said it couldn't independently verify the key theft or the log dump.

ShinyHunters says it will give Cl0p 72 hours to make contact, then try to extort the extortionists.

Is Cl0p finished?

Probably not. A humiliation isn't a shutdown.

Item Detail
Vulnerability CVE-2025-61882
Affected software Oracle E-Business Suite
CISA status Known Exploited Vulnerability, patch deadline set for federal agencies
Defacement artwork ASCII art of Umbreon, ShinyHunters' logo

Cl0p's operation was running at scale right up to the defacement. Our tracking has logged victims listed by the gang since July 2025, spread across multiple sectors; those are unverified claims the criminals published themselves, not confirmed breaches. Our 2 September story on the Cleo Harmony flaw noted that Cl0p had a habit of moving fast when a working exploit lands in its hands. This episode confirms it hasn't slowed down.

My read: the noisy part is the Pokémon art. What defenders should care about is that CVE-2025-61882 is still sitting unpatched on Oracle E-Business Suite installs somewhere, and now two rival extortion crews both know how to walk through it.

© 2026 Threat Vectr