VYPR
breachPublished Sep 21, 2026· 4 sources

ShinyHunters Cybercrime Gang Hijacks Cl0p Ransomware's Leak Site

The ShinyHunters extortion group has seized control of the Cl0p ransomware gang's dark web leak site, demanding a significant payment and revealing internal details.

In a dramatic turn of events within the cybercrime underworld, the ShinyHunters extortion group has reportedly taken over the dark web leak site historically used by the notorious Cl0p ransomware gang. The site, a platform where Cl0p typically published stolen data to extort its victims, was defaced over the weekend with a banner announcing its seizure by ShinyHunters, a group known more for social engineering and data theft than sophisticated ransomware operations.

Messages posted on the hijacked site by ShinyHunters outline an unspecified eight-figure extortion demand, which the group claims represents "2.333%" of Cl0p's net worth, suggesting Cl0p's holdings could be in the hundreds of millions of dollars. The hackers issued a stern warning, stating, “Clock is ticking moron. Kindly excuse our unprofessionalism,” and indicated that their demands would escalate daily if Cl0p failed to comply. By Monday, the demands had expanded to include a public apology from the ransomware group.

The dispute appears to stem from Cl0p's alleged unauthorized use of a vulnerability in Oracle's E-Business Suite, a campaign that had already drawn warnings from Oracle, the FBI, and international cybersecurity agencies. ShinyHunters claimed that Cl0p had threatened one of its members, escalating the conflict beyond a mere infrastructure hijack. The group also threatened to release sensitive financial details about Cl0p's victims, including payment amounts and Bitcoin addresses used for ransoms.

Adding to the pressure, ShinyHunters named three individuals identified as Cl0p operators, all of whom have been previously documented in public reporting. The group also demanded proceeds from Cl0p's recent Oracle E-Business Suite campaign, along with additional unspecified payments. The messages were notably aggressive, with ShinyHunters stating, “Be sure to bring an English interlocutor so you can comprehend my literacy in acquiring your bank account.”

By Monday, a message attributed to Cl0p appeared on the site, indicating an attempt to communicate with ShinyHunters, stating, “Shiny Hunters we trying to reach you Your email does not work. Come online old platform no email[.]” This suggests a potential attempt by Cl0p to negotiate or resolve the situation, though the outcome remains uncertain.

ShinyHunters has been active throughout 2026, with notable attacks including disruptions at schools across the U.S. via an attack on an education platform and the theft of data from over 4 million individuals at a major medical device company. Their previous victims also include large corporations such as Carnival Cruise Line, Ticketmaster, AT&T, McGraw Hill, ADT, and gaming company Rockstar.

Cl0p, on the other hand, has built a reputation for exploiting zero-day vulnerabilities in widely used file-transfer products, including those from Cleo, MOVEit, GoAnywhere, and Accellion, allegedly amassing hundreds of millions of dollars. This incident marks a significant internal conflict within the cybercrime ecosystem, with one prominent group turning on another's infrastructure.

The implications of this event are far-reaching, potentially disrupting Cl0p's operations and signaling a new level of inter-gang conflict. It also highlights the vulnerability of even established cybercrime infrastructure to takeover by rival groups, especially those adept at social engineering and exploiting perceived weaknesses.

The conflict between ShinyHunters and Clop has escalated, with ShinyHunters demanding an eight-figure sum and threatening to expose Clop's victim list and payment details. ShinyHunters claims to have exploited a vulnerability in Clop's leak site software to gain access, alleging that Clop stole a zero-day exploit ShinyHunters discovered and used against Oracle EBS customers. The demands have increased daily, with ShinyHunters also seeking a public apology from Clop.

The ShinyHunters gang has escalated their conflict with the Clop ransomware group by claiming to have stolen private keys and server data essential for Clop's operations. This follows ShinyHunters defacing Clop's data leak site and issuing their own ransom demand, citing a prior feud over the exploitation of vulnerabilities like CVE-2025-61882 in Oracle E-Business Suite. This internal cybercriminal conflict underscores the volatile and competitive nature of the underground economy.

The ShinyHunters group claims to have exploited a vulnerability in Grav CMS to gain unauthorized access to the Clop ransomware gang's dark web leak site. This attack escalated from a prior disruption by ShinyHunters of a Clop data-theft campaign, leading to public threats and a ransom demand from ShinyHunters for the return of control over the site.

Synthesized by Vypr AI
ShinyHunters Cybercrime Gang Hijacks Cl0p Ransomware's Leak Site · VYPR