S&P 500100.00-1.70%NASDAQ112.50-0.85%Apple125.000.00%Microsoft137.50+0.85%Google150.00+1.70%Amazon162.50-1.70%Tesla175.00-0.85%Meta187.500.00%Bitcoin200.00+0.85%Ethereum212.50+1.70%EUR/USD225.00-1.70%Gold237.50-0.85%Oil250.000.00%
The Wiregazette
Detailed close-up of horse hooves navigating sandy terrain in a riding area.
Cybersecurity

ShinyHunters Breaches Clop Leak Site, Threatens to Extort Rival Ransomware Gang

3 min read

Share

The ShinyHunters extortion collective hacked Clop’s dark web data leak site, stealing source code, server logs, and Tor onion service private keys, and has issued a ransom demand to the rival ransomware group.

The ShinyHunters extortion gang struck a rare target late Thursday: a fellow cybercriminal operation. The collective breached Clop’s (also known as Cl0p) Tor-based leak site, defacing the page with its branding and stealing a cache of sensitive internal data, according to multiple reports.

ShinyHunters claimed to have stolen source code, Grav CMS plugins, system logs, and the private cryptographic keys for Clop’s onion service — the infrastructure that hosts the ransomware gang’s public-facing leak site. “We have their onion keys. So if they kick us out it wouldn't matter at all because we control the private keys to host the same exact onion URL,” ShinyHunters told BleepingComputer, as reported by TechRadar.

The attackers also said they downloaded everything in the server’s /var/log directory, including authentication logs and IP addresses associated with connections to the server. ShinyHunters gave Clop 72 hours to respond to a ransom demand, according to TechRadar and Infosecurity Magazine. When asked by BleepingComputer what they planned to do with the access, the attacker reportedly replied, “going to extort them.”

**How the breach happened**

ShinyHunters defaced Clop’s site by exploiting an unauthenticated file upload vulnerability in the Grav content management system Clop was running, according to TechRadar. Cybernews confirmed the defacement, which displayed an ASCII image of a Pokémon character and a large message: “THIS SITE HAS BEEN PWN3D BY SHINYHUNTERES #Skids10p - Maybe don't try to threaten us next time.”

The taunt refers to a prior threat made by a Clop member during the group’s 2025 Oracle E-Business Suite attacks, ShinyHunters told BleepingComputer. “During the Oracle EBS campaign they ran and stole from me last year, someone from cl0p personally messaged me and said, and I quote (translated from Russian): I have more money than you and all of your people combined, I'll kill you soon,” ShinyHunters said, as reported by TechRadar.

**Rivalry over Oracle zero-day**

The attack appears to be the latest escalation in a feud between the two groups that began in 2025, according to Infosecurity Magazine. The origin centers on competing claims over ownership of vulnerabilities in Oracle E-Business Suite servers, including the zero-day CVE-2025-61882, which both groups exploited to steal data from organizations.

“This is a useful reminder that cybercriminal groups are not a single, coordinated ecosystem; they are competitive businesses driven by trust, reputation and money,” said Javvad Malik, lead CISO advisor at KnowBe4, in a statement reported by Infosecurity Magazine. “When relationships are built on deception and fear, double-crossing and betrayal is always a credible threat.”

**Implications for victims**

The breach raises concerns about secondary exposure, according to DarkReading. The stolen data could include payment logs and victim communications from Clop’s leak site, potentially exposing companies that have paid ransoms. The threat of new data leaks also adds uncertainty for organizations already compromised by Clop.

TechRadar compared the feud to the collapse of the Conti ransomware group in 2022, when internal messages were leaked after a political standoff, leading to the group’s fragmentation. While ShinyHunters’ stolen onion keys could allow it to impersonate Clop’s site indefinitely, cybersecurity experts noted that identifying individual Clop members may prove difficult, as the gang is believed to operate from Russia, where prosecutions are rare.

ShinyHunters is one of the most active extortion groups of 2026, with recent campaigns against Salesforce Experience Cloud and Canvas Learning Management System users, and a claimed attack on healthcare giant McKesson, according to Infosecurity Magazine. Clop has been active since 2019, notably exploiting a MOVEit vulnerability in 2023 and breaching the University of Phoenix in December 2025, affecting nearly 3.5 million people.

Share

About Daniel Pryce

Technology & Innovation Reporter. Covers technology companies, venture funding, and the software and security issues that affect financial institutions and markets. He reports on product launches, funding rounds, and cyber incidents with market relevance. Startups and established tech firms both appear on his beat.

Related articles