Summary
The ShinyHunters breach of Clop’s ransomware victim leak site, published as unverified in TTO-2026-0920-145, has been independently confirmed. Security researchers identified the attack vector: a path traversal vulnerability in the Grav CMS instance powering Clop’s dark web leak site (CVE-2026-49236, CVSS 8.1) allowed ShinyHunters to read arbitrary files from the server filesystem, including Clop’s victim database, leverage files, and operational logs. Clop has not responded publicly. The data release contains victim records consistent with Clop campaigns from 2024 through mid-2026.
Timeline
| Date | Event |
|---|---|
| Sep 19-20, 2026 | ShinyHunters claims Clop leak site breach; TTO-2026-0920-145 published as unverified |
| Sep 24-25, 2026 | Breach confirmed via Grav CMS CVE-2026-49236; data release authenticated as genuine Clop operational data |
What Happened
Clop’s dark web leak site was built on Grav CMS. CVE-2026-49236 is a path traversal vulnerability in Grav’s file management component allowing an attacker to read files outside the web root via directory traversal sequences. ShinyHunters traversed from the Grav web root to the server filesystem, accessing Clop’s victim database, leverage files, and operational logs. The data release has been authenticated by security researchers matching entries against previously documented Clop victims. Organizations that were active Clop victims between 2024 and mid-2026 should assess the data release for exposure.
Note on Domain Intelligence
Clop and ShinyHunters operate on dark web infrastructure with no clearnet presence. Domain intelligence scores are not applicable to either party.
The Trust Observatory · thetrustobservatory.com · September 25, 2026
The Trust Observatory · thetrustobservatory.com · September 8, 2026