After a weekend Clop Tor leak-site defacement (alleged Grav CMS upload), The Register (2026-09-21) reports ShinyHunters demanded an eight-figure payout, threatened to name companies that allegedly paid Clop, warned demands would rise every 24 hours, and demanded a public apology. Clop has been silent; researchers told Reuters the clash appeared genuine; broader claims remain unverified. BleepingComputer covered the initial hijack on Sep 19.

Same day, SecurityWeek / CrowdSec: roughly 170 private GitHub repos (about 300 including public) were copied on 2026-05-22 using a just-departed employee’s still-active token after the TanStack npm supply-chain incident (CVE-2026-45321). The archive surfaced Sep 16; 83 emails and 51 investor records were exposed; infra/DBs were not accessed; credentials were rotated Sep 16–17.

Two lessons for operators: paying an extortion crew is not a permanence guarantee for “privacy,” and offboarding must revoke SaaS/GitHub/OAuth tokens as hard as you revoke badges — ITAD and access checkout should include token revoke, not just laptop wipe.