An unusual clash between two well-known cybercrime groups has unfolded on the dark web, as ShinyHunters claimed responsibility for the breach of the leak website of Cl0p, the ransomware group that uses the portal to publicize victims' names and increase pressure on organizations that refuse to meet its demands.
The attack was discovered on Friday evening, September 18, when visitors to the onion service were presented with a completely different page. In place of the Cl0p content, an ASCII image of the Pokémon Umbreon, accompanied by a message claiming that the website had been compromised by ShinyHunters. This type of site defacement is known as a defacement attack.
The characteristic message of the attackers
The corrupted page also contained a link to the leak platform attributed to ShinyHunters, as well as the phrase "rooting your systems since '19", which serves as the group's signature message.

According to BleepingComputer, the breach of Cl0p's website has been confirmed, as has the upload of a file to its infrastructure. However, this confirmation does not mean that all of the claims subsequently made by ShinyHunters have been proven.
The choice of Umbreon is of particular interest. Researcher VXDB spotted the same image in an earlier hack of a website on HackForumsin August 2020, which was also attributed to ShinyHunters. The similarity is a clue that strengthens the effectiveness of the attack, but cannot in itself be conclusive proof of identity.
See also: ShinyHunters: Claims to have stolen 200,000 records from Florida DMV
In the spotlight: Grav CMS
ShinyHunters claim that they managed to enter Cl0p's infrastructure by exploiting process file upload of Grav, the content management system used by the website.
According to their version, the flaw did not require prior authentication, allowing unauthorized file uploads to occur. From the initial access point, the attackers claim to have been able to gain access to parts of the infrastructure, including source code, plugins, and log files.
So far, however, no independent evidence has been released to confirm this entire chain of attacks. The only safe conclusion is that the website was compromised and that the perpetrators managed to upload at least one file.

The Tor keys claim
Even more serious is ShinyHunters' claim that they have obtained the private keys associated with Cl0p's onion service. If proven, this could allow for the impersonation of that service or create significant problems with the reliability of the group's infrastructure.
However, there is currently no public evidence that the keys were actually stolen, a claim that, if confirmed, could significantly change the picture of the case.
See also: Ransomware in Berlin: Rhysida threatens to leak government data
An old dispute returns
The new conflict appears to be connected to a broader confrontation between the two groups. ShinyHunters claims that an exploit used by Cl0p in an attack on Oracle E-Business Suite in October 2025 was originally created by them.
The claim has not been independently verified and comes from one criminal group regarding the activity of another. Nevertheless, it shows the competition that can develop even between groups operating in the same cybercrime space.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Two teams with a significant history of attacks
Cl0p has been linked to some of the largest mass exploitation campaigns in recent years, most notably the MOVEit Transfer in 2023, which affected over 2,000 organizations.
ShinyHunters, on the other hand, has also been linked to extensive data theft and extortion operations. In 2026, companies with significant databases were among those targeted, while in June, attacks involving more than 100 companies via Oracle PeopleSoft.
What do we know for sure?
Cl0p has not commented publicly on the incident, and media requests for comment have not been responded to. There have also been reports that the ShinyHunters platform was later taken down, but there is no evidence of any retaliation by Cl0p.
For now, confirmed data remains limited: the Cl0p website was hacked, its content was altered, and at least one file was uploaded by the perpetrators. Allegations of source code theft, access to wider infrastructure, and possession of private Tor keys remain unverified.
See also: McKesson breach: ShinyHunters group says it stole millions of records

The case is of particular interest precisely because it reveals a less discussed aspect of cybercrime: the competition between different criminal ecosystems. Even when groups use similar extortion methods, the confrontation between them can lead to attacks against the very infrastructure they use for their illegal activities.
