· via dev.to (home feed)
ShinyHunters claims breach of Clop leak site and theft of Tor private key
ShinyHunters says it broke into Clop's Tor leak site through an unauthenticated Grav CMS upload and stole the onion service's private key; BleepingComputer confirmed the defacement but not the theft claims.

Hackers claim to have breached Clop's leak site
The ShinyHunters group says it compromised the Tor-hidden leak site operated by the Clop ransomware gang, and is now threatening to extort the gang with what it stole. According to BleepingComputer, whose September 19 report was summarised in a write-up on dev.to, the group attributes the initial break-in to an unauthenticated file upload vulnerability in Grav CMS, the content management system running the site.
Parts of the account are verifiable. BleepingComputer confirmed that a small text file planted by the attackers, carrying a message and a link to a leak site run by ShinyHunters, could be downloaded directly from Clop's existing onion address. Hours later, a defaced page displaying the ShinyHunters logo and message appeared at that same address.
What the attackers say they took
Beyond the visible intrusion, ShinyHunters claims it reached full access to the underlying server and made off with the site's source code, its Grav plugins, system logs held under /var/log, and the private key for the Tor onion service. None of that has been independently confirmed. BleepingComputer could also not establish whether the defaced page was served from Clop's original server or from separate hardware run by the attackers, a meaningful gap, because a working copy of the private key would be enough to bring the identical onion address up on another machine.
The group set a 72-hour deadline for Clop to make contact, which positions the stolen material as leverage. The extortion methods ransomware crews apply to companies would, in this telling, be aimed at one of the crews.
What is confirmed and what is not
Public reporting establishes two things: the rogue text file and the defacement both appeared at Clop's known address. Everything beyond that, including code execution, privilege escalation, bulk data theft and the key compromise, rests entirely on the attackers' word. The precise flaw in Grav, whether it sits in the core or in a plugin, the affected versions, and the route from an uploaded text file to server-wide control have not been published. There is also no public information about where any exfiltrated data was sent or how much of it existed.
The value of an onion service key
An onion service's address and its private key are inseparable. Whoever holds the key can host the same .onion address on their own infrastructure, publish content under the gang's name, read messages intended for the gang, or take the address dark entirely. For a leak site, the channel a ransomware operation uses to name victims and apply pressure, control of the address is close to control of the operation's public identity. Companies in negotiations with Clop and researchers tracking its campaigns would have no obvious way to distinguish genuine content from an impostor's.
Why it matters
The incident is an unusual case of criminal infrastructure becoming the target of an attack by other criminals, and it lands on the ecosystem's core trust mechanism: if the claims hold, a single key file decides who speaks for Clop online. It also underlines that hidden services get no exemption from ordinary web hygiene. An unauthenticated upload path in a CMS remains one of the most common ways servers fall in the first place, and a Tor-hidden deployment changes nothing about that risk; onion service operators should treat key theft as a scenario demanding a new key and a new address, not just a patch. Finally, the distance between what was confirmed and what was claimed is a reminder to read incident reports with attribution in mind. A defacement proves the address was compromised at some level; it does not prove everything the attacker says came after.
- #ransomware
- #tor
- #security
- #grav-cms
- #data-breach