Open Menu Close Menu
User
Scroll arrow
World

Hackers Hacking Hackers

ShinyHunters Seizes Cl0p’s Dark Web Site as Cybercrime Feud Erupts

Author
By TheZeal
Published: 22nd Sep 2026, 01:00 AM


Illustration of a hooded Umbreon at a laptop, with ShinyHunters and Cl0p displayed on surrounding screens.
Illustration of a hooded Umbreon at a laptop, with ShinyHunters and Cl0p displayed on surrounding screens.

Two of the world's most prolific cyber-extortion operations have turned their skills on one another, with ShinyHunters breaking into and defacing the dark web site of rival group Cl0p in an extraordinary dispute that appears to have grown out of a quarrel over a prized software exploit.

The intrusion began on Friday, September 18, when ShinyHunters says it found a weakness in software used by Cl0p's data-leak site, a Tor-based website through which the group has named organisations it says it compromised and applied pressure during extortion campaigns. Cybersecurity news site BleepingComputer independently confirmed that ShinyHunters had succeeded in uploading a file to Cl0p's server and, several hours later, found that the site itself had been replaced.

In its place was a page bearing ShinyHunters' distinctive visual signature: ASCII artwork, an image assembled from keyboard characters, depicting Umbreon, the dark-coloured Pokémon used as the group's logo and calling card. The page also linked to ShinyHunters' own Tor site. Cybersecurity researcher VXDB told BleepingComputer that the same Umbreon artwork appeared in a 2020 defacement of the HackForums website that ShinyHunters also claimed.

By Saturday, a screenshot preserved by cybercrime research platform eCrime.ch showed the succinct declaration: “Domain Seized By ShinyHunters.” When Reuters attempted to reach Cl0p's site on Sunday, it was unavailable. Cl0p did not respond to repeated requests for comment. ShinyHunters was less reticent.

“We basically own them now,” ShinyHunters told Reuters in an online chat.

Precisely how far that ownership extends remains uncertain. ShinyHunters told BleepingComputer that it had obtained “full access” to the server and claimed to have copied source code, system logs, Grav CMS plugins and other internal material. Grav is an open-source content-management system that stores a website's content in files rather than requiring a conventional database. Plugins are add-ons that provide additional functions. ShinyHunters says an unauthenticated file-upload weakness in Cl0p's Grav installation provided its way in, although the precise vulnerability has not been independently identified.

More consequential is ShinyHunters' claim that it obtained the private cryptographic keys belonging to Cl0p's Tor onion service. Tor allows websites to operate through special .onion addresses designed to conceal the location of their underlying servers. The private keys establish the cryptographic identity behind such an address, and possession of them can allow another party to impersonate the onion service. If ShinyHunters genuinely possesses Cl0p's keys, it could potentially operate a site using Cl0p's existing onion address from infrastructure of its own. Cl0p could, however, create a new onion service with new keys and a different address.

The distinction between what has been demonstrated and what has merely been claimed is important. BleepingComputer independently verified the uploaded file and the defacement. It has not independently verified that ShinyHunters obtained Cl0p's system logs, source code or onion-service keys.

ShinyHunters nevertheless appears to have settled upon an appropriately symmetrical use for whatever it obtained. Asked by BleepingComputer what it intended to do with the information, the answer was brief: “Going to extort them.” The group said it intended to give Cl0p 72 hours to make contact.

The confrontation did not arise solely from competitive vanity. According to ShinyHunters, the dispute goes back to Cl0p's sprawling 2025 campaign against Oracle E-Business Suite, a collection of enterprise software used by large organisations for such functions as accounting, procurement and human resources.

Google's Threat Intelligence Group and Mandiant, its incident-response and threat-intelligence arm, found that attackers associated with the subsequent Cl0p extortion campaign had been exploiting Oracle E-Business Suite systems for months before the demands became public. The activity may have involved the critical vulnerability later designated CVE-2025-61882. A CVE number is the standard identifier used to catalogue publicly tracked software vulnerabilities. Google said exploitation may have begun as early as August 2025, weeks before a patch became available.

Google estimated that more than 100 companies were likely affected by the Oracle E-Business Suite campaign, which involved the theft of large quantities of customer data. ShinyHunters says it discovered the zero-day first and that Cl0p obtained the exploit without permission. That allegation is central to the present feud, but it has not been independently established.

The evidence surrounding that claim is more complicated.

In October 2025, an exploit was published through a Telegram group calling itself Scattered Lapsus$ Hunters, a loose banner associated with names including ShinyHunters, Scattered Spider and LAPSUS$. The released material amounted to a proof-of-concept exploit, code demonstrating how a software weakness could be used against a target system.

Google later found that evidence recovered from earlier attacks against Oracle E-Business Suite had some overlap with the leaked exploit. But its investigators said there was not enough evidence to directly connect the July 2025 activity with use of that particular exploit. More importantly for the present dispute, Google said it did not assess actors associated with UNC6240, its designation for ShinyHunters in that investigation, as having been involved in the earlier exploitation activity.

The distinction matters. Cl0p's exploitation of Oracle systems is well established. A related exploit subsequently surfaced through the Scattered Lapsus$ Hunters ecosystem. What has not been independently demonstrated is ShinyHunters' assertion that the exploit originally belonged to it and was then taken by Cl0p.

The quarrel appears to have become more personal after that. ShinyHunters alleges that a person representing Cl0p threatened to disclose the real identities of several ShinyHunters members and, according to its account to BleepingComputer, also made threats of violence. Reuters was unable to establish whether ShinyHunters' account of the feud was true, while BleepingComputer said the allegations had not been independently verified.

A threat to expose identities carries particular weight in underground hacking circles. Doxxing, the publication of a pseudonymous operator's real identity or private information, can strip away the anonymity on which such groups depend, exposing members to law enforcement and potentially to hostile rivals. The allegation concerns a person representing Cl0p, however, and there is no public evidence showing that the purported threat reflected a collective decision by the entire operation.

Cl0p is among the more established cyber-extortion operations. The Russian-speaking group emerged internationally around 2019 and has been associated in government threat reporting with TA505, the designation given to a financially motivated cybercrime ecosystem active since at least 2014. The Canadian Centre for Cyber Security describes TA505 as a Russian-speaking operation involved in ransomware, phishing, botnets and the sale of access to compromised corporate networks.

Cl0p became particularly formidable by moving beyond conventional ransomware and exploiting weaknesses in widely used enterprise software on a mass scale. In 2023 it turned vulnerabilities in MOVEit Transfer into one of the era's largest data-theft campaigns, obtaining information concerning tens of millions of people from more than 600 companies, according to Reuters. Only last month Cl0p claimed large-scale thefts involving nearly 50 companies, including Philips, Shell, Fiserv and GE, although the individual claims have had differing levels of independent confirmation.

ShinyHunters followed a different path but arrived at a similarly formidable position. The name became prominent in 2020 through the theft and sale of large corporate databases. United States prosecutors said a user operating under the ShinyHunters name offered stolen data from more than 60 companies for sale on dark web forums between April 2020 and July 2021. The operation also sometimes threatened to publish or sell stolen files unless the organisation involved paid a ransom. One participant in the earlier group, French national Sébastien Raoult, was later extradited to the United States and sentenced to three years in prison and more than $5 million in restitution.

The modern ShinyHunters operation appears less like a fixed crew than a network of operators and affiliates. Anthropic said this month that it had disrupted several apparently separate hacking clusters it believed were affiliated with the wider ShinyHunters operation. Some were using artificial intelligence to accelerate the search for exposed credentials, vulnerable systems and valuable corporate data.

There is an irony in Cl0p's predicament that requires little embellishment. Much of the group's reputation rests upon finding weaknesses in other organisations' internet-facing software and exploiting them before those organisations can respond. Cl0p's own internet-facing infrastructure has now been compromised by another highly capable hacking operation.

The dispute was still developing on September 21. Malwarebytes reported that Cl0p's dark web leak site continued to display the ShinyHunters takeover page. A message posted on ShinyHunters' own site said its demands would increase for every 24 hours in which Cl0p failed to respond. ShinyHunters was by then demanding a public apology as well as money it alleges Cl0p made from the Oracle E-Business Suite campaign. Those demands, like the group's broader claims about what it stole from Cl0p's server, remain ShinyHunters' account of events.

How damaging the intrusion will ultimately prove remains unknown. The compromise and defacement of Cl0p's site are independently supported. The deeper claims, including possession of internal logs, source code and the cryptographic keys to Cl0p's onion identity, remain unverified. Cl0p has offered no public account of what happened and, in the reporting available so far, no public answer to its rival's attempt to extort it.

For researchers accustomed to watching these organisations apply pressure to corporations, governments and institutions, the sight of two major cyber-extortion operations turning the same methods upon each other is unusual.

Joe Roosen, senior director of security research at SpyCloud, told Reuters he had never seen one cybercrime operation take another on quite so openly.

“It is rare I get to see these criminals fight each other.”

Join the Discussion
What do you think?
No account required. Comment as a guest.
0 COMMENTS:
Home Latest
NZ Videos
Video LibraryLibrary
Menu Menu