ThreatPaper
Weak Evidence

ShinyHunters breached Clop via an unauthenticated Grav CMS file-upload flaw

Assessment

ShinyHunters told BleepingComputer it exploited an unauthenticated file upload vulnerability in Grav CMS — the flat-file content-management system running Clop's leak site — to plant its file and gain access. BleepingComputer frames this as 'what they claim,' and independently confirmed only that a file was uploaded to Clop's server and that the site was defaced, not the specific vector used. So while the compromise itself is proven by the confirmed defacement, the Grav CMS file-upload mechanism is the attacker's uncorroborated account of how it got in. It is plausible and specific, but repeating it as the confirmed root cause overstates what has been established.

Where this claim appeared

ShinyHunters (via BleepingComputer) · 2026-09-19

https://www.bleepingcomputer.com/news/security/shinyhunters-hacks-clop-leak-site-threatens-to-extort-ransomware-gang/

What “Weak Evidence” means

Evidence exists but is thin, circumstantial, or explicitly qualified as weak by the source that published it. Shared hosting infrastructure between threat clusters is the recurring example.

3 of 5 · rating scale

Assessed in

ShinyHunters defaces Clop's leak site and claims its onion keys — a cybercrime feud, and what's actually confirmed

Think this assessment is wrong? Report an error.