The Clop ransomware gang's data leak site on the Tor network was defaced after being compromised through an unpatched vulnerability in the Grav content management system. Clop later confirmed the breach and moved the site to a new Tor address.

According to BleepingComputer, the flaw exploited was an unauthenticated path traversal vulnerability in Grav CMS. The hacker group ShinyHunters was responsible for the intrusion, and the exploit path did not require authentication.

The incident shows that even ransomware groups that rely on hidden services are not immune to attacks on their own infrastructure. The failure to patch a known CMS vulnerability allowed a rival actor to take over the leak site and deface it, forcing Clop to relocate.