HomeIntelligenceBrief
BREACH BRIEF 🟠 High Breach

ShinyHunters Compromises Clop Ransomware Gang’s Dark Web Leak Site via Unauthenticated File‑Upload

ShinyHunters leveraged an unauthenticated file‑upload vulnerability in the Grav CMS that powers Clop’s public leak site, defaced the page and claimed control of the onion address. The incident underscores the importance of continuous third‑party monitoring and auditable evidence for control‑assurance programs.

Verisq™ Intelligence · 📅 September 22, 2026 · 📰 malwarebytes.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
2 recommended
📰
Source
malwarebytes.com

ShinyHunters Compromises Clop Ransomware Gang’s Dark Web Leak Site via Unauthenticated File‑Upload

What Happened – ShinyHunters, an extortion‑focused cybercrime group, exploited an unauthenticated file‑upload flaw in the Grav CMS that powers the Clop ransomware gang’s public leak site. Within hours the attackers defaced the page, seized control of the onion address, and announced they now hold the private keys needed to keep the site under their command.

Why It Matters for Trust & Control Assurance

  • Demonstrates how a single unpatched web‑application flaw can give an adversary full control of a critical external asset, a scenario continuous control‑assurance programs are built to detect and evidence.
  • Highlights the need for ongoing third‑party monitoring and proof of remediation for any SaaS or CMS components used by external partners.
  • Provides a concrete example of why organizations must maintain auditable evidence of vendor security posture to satisfy multiple framework requirements.

Who Is Affected – Criminal‑operating groups (ransomware/extortion gangs) that host public leak sites; indirectly, any organization that relies on the same CMS platform for its own external portals.

Recommended Actions

  • Inventory all third‑party web applications (including CMS platforms) and verify they are patched against known upload vulnerabilities.
  • Implement continuous monitoring of external assets for unauthorized changes and maintain immutable logs as audit evidence.
  • Incorporate vendor‑risk controls into your control‑assurance framework and map evidence to the relevant control objective. Source: Malwarebytes Labs

Technical Notes

  • Attack vector: unauthenticated file‑upload vulnerability in Grav CMS (no CVE disclosed).
  • Data exposed: the public leak site content; no customer‑data breach reported.
  • Threat actor: ShinyHunters extortion group, active since 2019. Source: Malwarebytes Labs
📰 Original Source
https://www.malwarebytes.com/blog/news/2026/09/shinyhunters-hacks-rival-extortion-gang-and-takes-over-its-dark-web-site

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →