ShinyHunters Took Over Cl0p's Leak Site and Threatened to Name Every Company That Paid
ShinyHunters defaced Cl0p's Tor leak site on 18 September 2026 with Umbreon art and a downloadable file, then threatened to publish which companies paid, how much, and to which Bitcoin addresses. Stolen onion keys remain a claim. Only the defacement and upload are confirmed.

One extortion crew has seized another's shakedown site and pointed it straight back at the gang that built it.
On Friday night, 18 September, ShinyHunters defaced Cl0p's Tor leak site and left behind Pokémon and Umbreon artwork, the taunt "THIS SITE HAS BEEN PWN3D BY SHINYHUNTERS," a link to its own leak platform, and a downloadable file. Malwarebytes captured the live page and a demand that ShinyHunters kept rewriting through 21 September.
The message is personal. It names Cl0p operators Likhogray and Tarasov, tells "boss j0nny" to wake up, and counts down in lines like "66 hours remaining," with the price climbing every 24 hours and now carrying a demand for a public apology. The threat underneath the theatrics is the one that should worry every company Cl0p ever hit: ShinyHunters says it will publish which victims paid, how much, and to which Bitcoin addresses.
How much of the rest is real is harder to pin down. ShinyHunters says it walked in through an unauthenticated file-upload flaw in Grav CMS, made off with source code, plugins, and logs, and now holds the onion private keys, meaning it could rebuild the same address even if evicted. Those are the attackers describing their own work. What outside researchers have actually confirmed is narrower: the defacement and the uploaded file, nothing more.
The grudge, by ShinyHunters' telling, dates to Cl0p's Oracle EBS campaign, after which a Cl0p member allegedly messaged in Russian that he had more money than ShinyHunters and would kill him. Cl0p has said nothing.
Both crews are heavyweights, which is why the feud reads like a turf war rather than a prank. Cl0p's recent Windchill campaign named more than 40 alleged victims, among them Shell, Philips, and Fiserv. ShinyHunters claims it pulled 3.65 TB from Instructure's Canvas platform across roughly 9,000 institutions, a volume play in the same market as the Gyazo breach that exposed 23 million accounts and 490 million image links.
There is one thread tying the mask to a face, and it is thin. Researcher VXDB matched the Umbreon art to an August 2020 HackForums defacement that ShinyHunters also claimed at the time. It points at the group, but it does not prove who is at the keyboard now.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free