Hacking group ShinyHunters compromised and defaced the data leak site of the Clop ransomware gang on September 25 via an unpatched Grav CMS path traversal vulnerability. Clop relocated to a new Tor address after confirming the breach.
Between September 19 and 21, the ShinyHunters extortion group infiltrated the Clop ransomware operation's data leak site, defacing it and allegedly stealing server data, source code, and Tor private keys. The defacement was confirmed; the broader theft claims remain unverified.