Security & Risk6 minNewsroom

ShinyHunters Claims to Have Taken Over Clop Leak Site

Macrofotografia de discos de um HD empilhados no eixo, com riscos concêntricos e poeira sobre a superfície metálica espelhada.

The group claims control of Clop's Tor site and threatens to reveal companies that paid ransoms during attacks on Oracle E-Business Suite. Clop responded but did not confirm the extent.

The extortion group ShinyHunters claims to have taken over the Clop leak site on the Tor network and raised its demands on Monday: it stated that the required payment increases every 24 hours without a response and added the demand for a public apology. The most significant threat to the corporate sector came along with this, according to published reports: the group states it might disclose which companies paid Clop during the extortion campaign against Oracle E-Business Suite servers, including amounts and associated Bitcoin addresses.


Clop publicly responded on Monday, on the very site that was taken over. "Shiny Hunters we trying to reach you. Your email does not work. Come online old platform no email," it wrote. The message confirms that the group has lost control of the page but does not confirm the extent of access that ShinyHunters claims.


What is Claim and What is Verified


What can be observed is the graffiti: the page began displaying a notice that the domain had been taken over by ShinyHunters. The rest comes from the attacker itself. The group claims to have exploited an unauthenticated file upload vulnerability in Grav CMS on the night of Friday, September 18, and asserts it gained full access to the server, including source code, plugins, system logs, and the onion service private keys. The claim regarding the Tor keys has not been independently verified.


The initial demand, according to the same reports, was for an eight-figure sum in Bitcoin, with contact through an Onionmail address. No company cited as a payer has been publicly identified by the time this article was published, and none has commented. There is no confirmation from any law enforcement or regulatory authority regarding any part of the episode.


The origin of the conflict is operational. In October 2025, Clop exploited flaws in Oracle E-Business Suite servers, including the zero-day CVE-2025-61882, to steal data during extortion campaigns. A Google analyst estimated that more than 100 companies were affected. ShinyHunters claims that the exploit used was originally theirs and that Clop obtained it without authorization.


The Risk is Not the Site, It's the List


For a CISO, the dispute between two criminal groups is just noise. What is not noise is the possibility that ransom payment records change hands. A company that negotiated with Clop in 2025 and paid did so under the premise that the transaction and its identity would remain out of the news. This premise depends on the receiver of the payment maintaining confidentiality, and now there is a second actor claiming possession of those records without any agreement with the original victim.


A Bitcoin address is traceable. If amounts and wallets are published, reconstructing the flow by blockchain analysis firms ceases to be intelligence work and turns into a public exercise. This is where the exposure becomes more than just reputational.


Obligations That Don't Expire with Payment


In the United States, publicly traded companies must disclose material cyber incidents in a specific form within a short deadline. A company that treated the 2025 episode as resolved may have to reassess the materiality if the information comes to light now, with audits and risk committees reopening a case that was closed. There is also the sanction exposure: payment to a group subject to U.S. sanctions is a regulatory issue in itself, regardless of the leak.


In Germany and the rest of the European Union, the GDPR requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach, with fines reaching 4% of global revenue. A re-publication of the same data by a third party is likely to be treated as new knowledge, not as a continuation of the 2025 incident.


In India, the vector is operation. Shared service centers running Oracle E-Business Suite for American and European clients were part of the surface affected in the original campaign, and it is in these centers that necessary logs are located to respond to what may be published now. In Brazil, the LGPD imposes communication to ANPD and data subjects, and the same logic of new knowledge applies to companies that addressed incidents from 2025 without communication.


The detail that changes the calculation of who pays the ransom is legal, not technical. A silence agreement with a criminal group has never had enforceable possibilities, but so far it has functioned in practice because the interlocutor had a commercial incentive to honor it. When the interlocutor itself is breached, that incentive no longer protects the victim, and the payment becomes merely an accounting record waiting for someone willing to publish it.

The week's analysis, by email

One weekly edition with what matters to people who decide. No ads, no sponsorship.

One-click cancellation, at any time.

Security & Risk