Read as article
ShinyHunters Hacks Rival Clop's Dark Web Leak Site
By @sharedot · · 6 pages
ShinyHunters hacked rival Clop's Tor leak site, stole its private keys and set a 72-hour extortion deadline.
Rival gang hijacks Clop's leak site
In an unusual turn within the cybercrime ecosystem, the ShinyHunters extortion syndicate has claimed responsibility for breaching and defacing the Tor-based leak website operated by the rival Clop ransomware group. According to Cybersecurity Insiders, ShinyHunters gained unauthorized access to parts of Clop's infrastructure and replaced the leak site's contents with messages and branding of its own. The group also reportedly issued an extortion demand against Clop, giving the ransomware operation a 72-hour deadline to respond. Both outlets reporting the incident describe it as a rare case of one major cybercriminal operation directly attacking another's public infrastructure rather than a corporate victim.
Stolen keys could permanently seize the domain
The breach reportedly goes far beyond a website defacement. Cybersecurity Insiders reports that ShinyHunters may have obtained source code, system logs, plugins, and Tor service keys tied to Clop's operations. Streamline Feed goes further, reporting that ShinyHunters claims root-level access to the hosting server and theft of the cryptographic private keys for Clop's Tor hidden service — possession of which would allow it to hijack or clone the dark web address outright. Streamline Feed also attributes the intrusion to an unauthenticated arbitrary file upload vulnerability in Grav CMS, the open-source system Clop used to publish stolen data, and says the defacement featured ASCII artwork of Umbreon with a taunt about rooting systems since 2019.
The feud traces to a shared Oracle exploit
Both outlets connect the attack to a dispute over data theft from Oracle E-Business Suite environments. Streamline Feed reports the conflict dates to October 2025, when both groups exploited a zero-day tracked as CVE-2025-61882, with ShinyHunters alleging Clop obtained the exploit without authorization and used it in its own campaigns — and that Clop representatives then issued threats in underground channels. The reported ransom demand adds stakes: Cybersecurity Insiders reports it is believed to be in the double-digit millions of dollars. Threat intelligence managers from Ascent Solutions and SpyCloud, cited by Streamline Feed, confirmed that while underground disputes happen, public infrastructure hijacking is a significant escalation.
What it means and what to watch
The incident highlights a rarely seen dynamic: ransomware groups are not a monolith, and rivalry over victims, stolen data and access can turn criminal organizations against each other. Both syndicates have extensive histories — Clop is known for mass exploitation of MOVEit Transfer, GoAnywhere MFT and Accellion FTA, while ShinyHunters operates as a data theft and extortion syndicate without deploying encryptors. If the stolen material includes authentic operational credentials or logs, security researchers and law enforcement could gain rare insight into Clop's infrastructure. Both outlets caution that details remain preliminary and uncorroborated; the industry is watching whether Clop responds before the 72-hour deadline expires.