Read as article
ShinyHunters Ratchets Up Cl0p Feud With Ransom and Apology Demands
By @sharedot · · 8 pages
ShinyHunters escalated its takeover of Cl0p's leak site with rising eight-figure demands, a public apology requirement and threats to expose Cl0p's payers.
The feud escalates past the defacement
Since then the confrontation has hardened into a full extortion attempt against the ransomware gang itself. According to The Record, messages posted on the seized site set an unspecified eight-figure demand — described as '2.333%' of the ShinyHunters author's own claimed net worth — and warned that demands would increase every 24 hours Cl0p failed to respond. By Monday, The Record reports, the demands had expanded again to include a mandatory public apology from Cl0p, alongside proceeds from Cl0p's recent Oracle E-Business Suite campaign 'plus more.' Cl0p's leak site now carries a ShinyHunters 'Note to Cl0p' that Malwarebytes republishes in full, including a 66-hour countdown and the taunt 'I am 3-0 against you rich and broke criminals.'
Why a gang-on-gang hijacking is so unusual
Cybercriminal groups frequently share resources and rent services to each other, but open, named attacks by one gang on another are rare. ShinyHunters is treating Cl0p like any ordinary victim: PCMag reports the group told Reuters its aim is straightforward extortion, and BleepingComputer says that when asked what it planned to do with its access, the attacker replied simply, 'going to extort them.' Infosecurity Magazine quotes KnowBe4 lead CISO advisor Javvad Malik, who notes that criminal groups are 'competitive businesses driven by trust, reputation and money,' so double-crossing is always a credible threat. TechRadar frames the feud as a possible 'cyber war' recalling Conti's 2022 collapse, when leaked internal messages splintered that gang into successors like Black Basta and Royal.
What ShinyHunters says it stole
The claimed haul goes well beyond a defaced homepage. TechRadar reports ShinyHunters claims to have taken source code, Grav CMS plugins, system logs and everything in the server's /var/log directory — including authentication logs and the IP addresses of Cl0p members who connected to the service. According to Infosecurity Magazine, that data could in principle be used to identify members of the Cl0p operation. ShinyHunters also says it holds the private keys for Cl0p's Tor onion service, telling BleepingComputer via Malwarebytes and TechRadar: 'We have their onion keys. So if they kick us out it wouldn't matter at all because we control the private keys to host the same exact onion URL.' The gang additionally threatened, per The Record, to release records showing which companies paid Cl0p, how much, and to which Bitcoin addresses.
The original insult behind the beef
ShinyHunters traces the feud to Cl0p's 2025 Oracle E-Business Suite campaign, a wave of attacks that prompted warnings from Oracle, the FBI and cybersecurity agencies in the UK and Singapore, according to The Record. ShinyHunters claims Cl0p 'stole' its exploit — Infosecurity Magazine identifies the shared target as the zero-day CVE-2025-61882 used by both groups — and says a Cl0p member then threatened it.
The irony of an unpatched CMS
For a gang that made hundreds of millions of dollars exploiting unknown vulnerabilities in file-transfer products like MOVEit, GoAnywhere, Cleo and Accellion — as The Record notes — Cl0p proved remarkably lax about its own infrastructure. PCMag and BleepingComputer via Malwarebytes report ShinyHunters got in through what it claims was an unauthenticated file-upload vulnerability in the Grav content management system Cl0p was running, uploading a small text file on Friday night before fully defacing the site. Malwarebytes researcher Pieter Arntz captures the irony directly: you might expect groups that monetize unpatched vulnerabilities to be more vigilant about their own systems, but they sometimes let their guard down. The defacement itself left no ambiguity, reading 'THIS SITE HAS BEEN PWN3D BY SHINYHUNTERES #Skids10p — Maybe don't try to threaten us next time.'
Where the standoff goes next
Cl0p's only public response so far, visible on its own site, is a plea for a different channel: 'Shiny Hunters we trying to reach you. Your email does not work. Come online old platform no email,' The Record and PCMag both report. Meanwhile ShinyHunters says it is still downloading and reviewing stolen material, according to TechRadar, meaning further leaks remain possible. Infosecurity Magazine adds 2026 campaigns against Salesforce Experience Cloud and a claimed McKesson breach. If ShinyHunters follows through on naming Cl0p's paying victims, the fallout could reach well beyond the two gangs.
Sources
- therecord.media › ShinyHunters cybercrime gang takes over Cl0p ransomware site, demands extortion payment
- malwarebytes.com › ShinyHunters hacks rival extortion gang and takes over its dark web site
- infosecurity-magazine.com › ShinyHunters Claim Hack of Rival Ransomware Gang Clop
- pcmag.com › Hacker-on-Hacker Crime: ShinyHunters Is Trying to Extort CLOP Ransomware Group
- techradar.com › Cybercrime civil war brewing? ShinyHunters reportedly hacks Cl0p ransomware gang and threatens further damage