companyClop ransomware gang
confirmedlowVulnerabilityFirst reported Sep 25, 2026
Clop: leak site hacked and defaced via Grav CMS path traversal flaw
The Clop ransomware gang confirmed its data leak site server was compromised and defaced through an unpatched Grav CMS vulnerability, reported to be an unauthenticated path traversal flaw. Clop has since moved its leak site to a new Tor address. The intrusion was attributed to ShinyHunters.
Members only
The full record: the timeline and 2 linked reports
- Every update as it happened, with the status at each step
- Every report behind the record, newest first
- Alerts the moment Clop ransomware gang — or anything else you track — is hit again
A free account is all it takes — no card, one minute.