ShinyHunters Hackers Breach Clop Ransomware Group's Server
The notorious ransomware group Clop was forced to migrate its data leak site after ShinyHunters compromised its server infrastructure.

A major incident has rocked the cybersecurity landscape. As reported by BleepingComputer, the hacker group ShinyHunters successfully breached the data leak site belonging to Clop, a well-known ransomware operator. The attack resulted in the defacement of Clop’s website and the alteration of its content.
The Weak Link: Grav CMS
According to experts, ShinyHunters executed the attack by exploiting a vulnerability within Grav CMS. The issue, a path traversal vulnerability, allowed the hackers to bypass authentication and gain unauthorized access to protected server files. Because this flaw remained unpatched at the time, it provided the attackers with an ideal opportunity.
Clop acknowledged that its infrastructure had been compromised. Consequently, the group was forced to migrate its data leak portal to a new Tor address to prevent further interference. This incident highlights that even criminal organizations are not immune to becoming targets of other hackers if they rely on outdated or vulnerable software.
Why This Matters
Such incidents are significant as they reveal the internal conflicts and competition occurring among cybercriminals. While this event does not pose a direct threat to the average user, it confirms that even the most dangerous hacking groups have technical vulnerabilities. For users of various CMS platforms, this serves as a critical reminder that timely software updates remain a fundamental pillar of digital security.