We spend a lot of time talking about ransomware and extortion groups attacking companies, stealing data and demanding money. But every once in a while, something comes along that turns the usual story completely on its head.
This time, the target was another cybercrime operation.
ShinyHunters reportedly breached the infrastructure behind Cl0p’s data leak site, defaced the Tor site and then threatened to extort the ransomware gang itself. In other words, an extortion group apparently got a taste of its own business model.
The attack on Cl0p
According to BleepingComputer’s initial report, the attack began when ShinyHunters exploited a vulnerability affecting the Grav content management system used by Cl0p’s leak site. The attackers first demonstrated access by uploading a small file and later replaced the site with a ShinyHunters defacement.
BleepingComputer independently confirmed the defacement and the uploaded file. ShinyHunters went considerably further with its claims, saying it obtained source code, plugins, logs and the private keys associated with Cl0p’s Tor onion service. Those broader theft claims were not independently verified in the initial report.
ShinyHunters then did something particularly ironic: it added Cl0p to its own leak site and demanded payment, threatening to publish allegedly stolen material if Cl0p did not comply. The demand reportedly reached eight figures and was accompanied by additional threats to expose information about companies that allegedly paid Cl0p in previous extortion campaigns.
Cl0p confirms its server was compromised
A later BleepingComputer follow-up provided an important piece of confirmation. Cl0p moved its leak site to a new Tor address and acknowledged that the previous server had been compromised.
The vulnerability was ultimately identified as CVE-2026-42608, an unauthenticated path traversal issue in Grav CMS. Grav confirmed the technical description of the flaw and said that while its newer 2.x branch was already protected, the fix had not previously been backported to the older 1.7 branch. After details of the exploitation were shared with the project, Grav released a patched 1.7 version.
Cl0p disputed ShinyHunters’ claims about what was actually stolen, saying the compromised server contained only site content and no financial or operational information. That leaves an important distinction: the compromise and defacement are confirmed, but some of ShinyHunters’ claims about the contents of the stolen data remain claims by the attackers.
Why were these groups fighting?
The feud appears to go back further than this compromise. Reuters reported that ShinyHunters said the dispute involved an Oracle E-Business Suite exploit that the group claimed it had discovered before Cl0p obtained it. Reuters could not independently establish ShinyHunters’ account of the feud.
The disagreement reportedly escalated into threats between the groups before ShinyHunters compromised Cl0p’s site. Whatever happened behind the scenes, the result became unusually public: one established cybercrime operation attacking another one’s infrastructure and then applying the same extortion tactics normally aimed at legitimate organizations.
Criminal infrastructure is still infrastructure
There is also a useful security lesson buried underneath the spectacle.
Cybercriminals may spend their time looking for vulnerabilities in everybody else’s systems, but their own infrastructure is still made out of software. It still has to be configured, maintained and patched. An unpatched vulnerability does not care whether the server belongs to a hospital, a corporation, a government agency or a ransomware gang.
In this case, Cl0p acknowledged that its Grav installation had not been fully updated. The same basic problem defenders deal with every day – vulnerable software left running – appears to have provided another criminal group with an opportunity to get inside.
An unusual cybercrime story
We’ve seen ransomware groups disappear, rebrand, get disrupted by law enforcement, fight with affiliates and leak information about one another. But a major extortion group publicly compromising another major extortion group’s leak infrastructure and then apparently trying to extort it is a particularly unusual twist.
There is certainly some irony in watching an organization built around stealing information and pressuring victims suddenly become the target of those same tactics. But it is also a reminder that cybercrime groups are not untouchable technical machines. They operate infrastructure, make mistakes and leave vulnerabilities behind just like everyone else.
And this time, another criminal crew was apparently waiting to take advantage of one.
Sources
Related
Discover more from Jared's Technology podcast network
Subscribe to get the latest posts sent to your email.
ShinyHunters hacks Cl0p: What happens when an extortion gang gets extorted?
We spend a lot of time talking about ransomware and extortion groups attacking companies, stealing data and demanding money. But every once in a while, something comes along that turns the usual story completely on its head.
This time, the target was another cybercrime operation.
ShinyHunters reportedly breached the infrastructure behind Cl0p’s data leak site, defaced the Tor site and then threatened to extort the ransomware gang itself. In other words, an extortion group apparently got a taste of its own business model.
The attack on Cl0p
According to BleepingComputer’s initial report, the attack began when ShinyHunters exploited a vulnerability affecting the Grav content management system used by Cl0p’s leak site. The attackers first demonstrated access by uploading a small file and later replaced the site with a ShinyHunters defacement.
BleepingComputer independently confirmed the defacement and the uploaded file. ShinyHunters went considerably further with its claims, saying it obtained source code, plugins, logs and the private keys associated with Cl0p’s Tor onion service. Those broader theft claims were not independently verified in the initial report.
ShinyHunters then did something particularly ironic: it added Cl0p to its own leak site and demanded payment, threatening to publish allegedly stolen material if Cl0p did not comply. The demand reportedly reached eight figures and was accompanied by additional threats to expose information about companies that allegedly paid Cl0p in previous extortion campaigns.
Cl0p confirms its server was compromised
A later BleepingComputer follow-up provided an important piece of confirmation. Cl0p moved its leak site to a new Tor address and acknowledged that the previous server had been compromised.
The vulnerability was ultimately identified as CVE-2026-42608, an unauthenticated path traversal issue in Grav CMS. Grav confirmed the technical description of the flaw and said that while its newer 2.x branch was already protected, the fix had not previously been backported to the older 1.7 branch. After details of the exploitation were shared with the project, Grav released a patched 1.7 version.
Cl0p disputed ShinyHunters’ claims about what was actually stolen, saying the compromised server contained only site content and no financial or operational information. That leaves an important distinction: the compromise and defacement are confirmed, but some of ShinyHunters’ claims about the contents of the stolen data remain claims by the attackers.
Why were these groups fighting?
The feud appears to go back further than this compromise. Reuters reported that ShinyHunters said the dispute involved an Oracle E-Business Suite exploit that the group claimed it had discovered before Cl0p obtained it. Reuters could not independently establish ShinyHunters’ account of the feud.
The disagreement reportedly escalated into threats between the groups before ShinyHunters compromised Cl0p’s site. Whatever happened behind the scenes, the result became unusually public: one established cybercrime operation attacking another one’s infrastructure and then applying the same extortion tactics normally aimed at legitimate organizations.
Criminal infrastructure is still infrastructure
There is also a useful security lesson buried underneath the spectacle.
Cybercriminals may spend their time looking for vulnerabilities in everybody else’s systems, but their own infrastructure is still made out of software. It still has to be configured, maintained and patched. An unpatched vulnerability does not care whether the server belongs to a hospital, a corporation, a government agency or a ransomware gang.
In this case, Cl0p acknowledged that its Grav installation had not been fully updated. The same basic problem defenders deal with every day – vulnerable software left running – appears to have provided another criminal group with an opportunity to get inside.
An unusual cybercrime story
We’ve seen ransomware groups disappear, rebrand, get disrupted by law enforcement, fight with affiliates and leak information about one another. But a major extortion group publicly compromising another major extortion group’s leak infrastructure and then apparently trying to extort it is a particularly unusual twist.
There is certainly some irony in watching an organization built around stealing information and pressuring victims suddenly become the target of those same tactics. But it is also a reminder that cybercrime groups are not untouchable technical machines. They operate infrastructure, make mistakes and leave vulnerabilities behind just like everyone else.
And this time, another criminal crew was apparently waiting to take advantage of one.
Sources
Share this:
Like this:
Related
Discover more from Jared's Technology podcast network
Subscribe to get the latest posts sent to your email.
Published in article commentary