Clop Ransomware Group Migrated Data Site After Defacement

The criminal group shifted infrastructure following a vulnerability exploit by rival hackers.

Updated on Sept. 28, 2026 in Cybersecurity

Isometric editorial illustration of server cabinets and network cables, representing a shift in digital infrastructure.
The Clop ransomware group migrated its data leak site to a new Tor address after the ShinyHunters group compromised its previous infrastructure. AI Illustration. Upload story photo >

Live Poll

Should software companies face stricter regulations regarding the security of their legacy product versions?

The Clop ransomware gang has migrated its data leak site to a new Tor address after the ShinyHunters group compromised its previous server. This shift followed a defacement attack that exploited an unauthenticated path traversal vulnerability.

Why it matters

The breach highlights how even cybercriminal infrastructure is subject to traditional software vulnerabilities, forcing groups to relocate operations to evade further intrusion.

The incident involved an unauthenticated path traversal vulnerability, tracked as CVE-2026-42608, which allowed attackers to bypass security controls in Grav CMS. The flaw is resolved in Grav CMS 2.0 and the 1.7.53.4 patch for the 1.7 branch.

The players

Clop

A ransomware group known for hosting data leak sites on the Tor network to extort victims.

ShinyHunters

A threat actor group that engages in unauthorized server access and data theft.

Grav CMS

A flat-file content management system that provides web infrastructure and recently issued patches for critical path traversal flaws.

The details

The breach occurred when ShinyHunters exploited an unauthenticated path traversal flaw—a vulnerability that allows unauthorized users to navigate outside the intended folder structure—within the Grav CMS platform. By exploiting this mechanism, the attackers gained access to server files, including source code, logs, and private keys. Clop subsequently moved its operations to a new Tor address, maintaining that the compromised server did not house sensitive victim financial data.

Timeline

  1. September 28, 2026: The security incident was documented and published.

The Tech Race

This incident mirrors broader trends in the ransomware landscape where criminal syndicates are increasingly targeted by rival groups using the same vulnerabilities they once used against corporate targets. It underscores a shift where digital hygiene, even within illegal botnets, has become a competitive requirement for threat actors.

Web administrators using Grav CMS should audit their current installation and ensure they have updated to version 2.0 or 1.7.53.4 to mitigate CVE-2026-42608. Failing to patch this path traversal flaw could allow external actors to gain unauthorized access to server-side source code and private keys.

The takeaway

The event serves as a reminder that misconfigured CMS platforms remain a high-risk vector even for sophisticated criminal infrastructure. Security teams should prioritize patching path traversal vulnerabilities to prevent unauthorized access to sensitive server assets.

Further reading

For broader trends in infrastructure security, visit the Cybersecurity section.

Source note: This article includes information reported by SC Media.

Live Poll

Should software companies face stricter regulations regarding the security of their legacy product versions?