Source: winhorse via Getty Images
ShinyHunters apparently breached rival ransomware gang Cl0p last week, and the incident could pose additional risks to victim organizations caught in the middle.
ShinyHunters is a financially motivated cybercrime group known primarily for data theft and extortion attacks. The group’s identity has become increasingly fluid, with researchers observing ties to and collaboration with cybercriminals associated with the Scattered Spider and Lapsus$ collectives.
Cl0p, meanwhile, is a notorious ransomware gang best known for large-scale data extortion campaigns, particularly involving zero-day vulnerabilities. Cl0p actors were behind the massive 2023 campaign that exploited a zero-day in Progress Software’s MOVEit file transfer software, as well as a similar campaign that targeted a Fortra GoAnywhere flaw that same year.
Over the weekend, ShinyHunters defaced Cl0p’s Dark Web data leak site with a message: “DOMAIN SEIZED BY SHINYHUNTERS.” As first reported by BleepingComputer, ShinyHunters claimed the attack began on Friday night when it exploited an unauthenticated file upload vulnerability in the Grav CMS used by Cl0p’s leak site.
ShinyHunters vs. Cl0p: Cybercrime Feud
ShinyHunters claimed it obtained full access to Cl0p’s leak site server and stole source code, Grav CMS plug-ins, system logs, private keys for its Onion service, and other data. Those data-theft claims have not been independently verified.
The attackers continued to leave messages on Cl0p’s site taunting the ransomware group and attempting to extort it. On Sept. 19, a message attributed to ShinyHunters demanded an unspecified eight-figure payment in Bitcoin and directed Cl0p to contact an Onionmail address.
On Sept. 20, the attackers wrote on Cl0p’s page, “I want all the money you made off the EBS campaign plus more AND WITH INTEREST, before I start releasing information regarding the companies that paid you, how much, and to what Bitcoin address.”
The reference to “EBS” likely references Cl0p’s extortion campaign targeting customers affected by the critical Oracle E-Business Suite (EBS) zero-day vulnerability CVE-2025-61882 last fall. Public feuds and attacks between cybercriminal groups aren’t uncommon; earlier this year, two emerging ransomware groups, 0APT and KryBit, hacked one another and leaked internal data.
What About the Ransomware Victims?
ShinyHunters’ effort does not appear to have yet resulted in a payment, as the defacement message included a note stating: “Every 24 hours you fail to engage with us the demands increase. The demand now includes a mandatory apology issued directly to me PUBLICLY.”
Dark Reading confirmed that, as of this writing, Cl0p’s leak site removed the defacement message and now displays a plain text note, possibly from Cl0p itself, claiming ShinyHunters’ email address does not work.
On one hand, cybercriminal feuds could be seen as a positive, because as Malwarebytes’ Pieter Arntz noted in a blog post, “The good news is that while they are after each other, they probably have less time to attack legitimate businesses.”
On the other hand, it’s unknown whether ShinyHunters obtained any information about Cl0p’s victims. At this time, ShinyHunters has not provided proof that it has this data in its possession. That said, ShinyHunters has already threatened to publish information about companies that allegedly paid Cl0p, including payment amounts and Bitcoin addresses. If ShinyHunters obtained additional information tied to Cl0p’s victims, those organizations could potentially face further exposure or even renewed extortion attempts.
Jon Baker, vice president of threat-informed defense at AttackIQ, tells Dark Reading that there’s no proof yet that ShinyHunters actually obtained Cl0p’s victim files, but a larger point is that “stolen information doesn’t retire.”
“[Stolen data] sits on servers run by the original group, its affiliates and its infrastructure providers, and every copy is another chance for theft, resale or exposure,” he says. “A company can spend years accountable for data it can no longer locate or control.”
Similarly, Darren Guccione, CEO and cofounder at Keeper Security, said the fundamental problem behind this is that “you can’t rely on criminals to honor agreements” even if you paid a ransom.
“Paying for deletion assumes the criminal will destroy the data, but you’re negotiating with someone whose business model is deception and theft,” Guccione says. “Once data leaves an organization’s control, there’s no mechanism to verify it was destroyed, no audit trail and no recourse if the promise is broken.”
It remains to be seen whether ShinyHunters actually obtained Cl0p victim information. This public feud, however, illustrates a risk that begins the moment data is exfiltrated: an organization may remain responsible for information that is now stored on infrastructure it cannot secure, audit, or even locate.