Summary
- ShinyHunters defaced Clop’s dark web leak site over the weekend by exploiting a vulnerability in the site’s underlying software.
- The crew claims broad access to Clop’s infrastructure and is demanding an eight-figure payment, later escalating to all proceeds from Clop’s Oracle EBS campaign plus interest.
- ShinyHunters alleges Clop stole a zero-day exploit it discovered and used it against corporate victims — the payment demand is framed as a cut of those proceeds.
- If ShinyHunters’ access claims are accurate, it may publish records of previous ransom payments, including company identities, negotiated sums, and Bitcoin addresses.
- Clop has not responded publicly; two independent security researchers told Reuters the confrontation appears genuine.
What happened
Clop’s dark web leak site was hijacked over the weekend, displaying a ‘DOMAIN SEIZED BY SHINYHUNTERS’ banner along with the tagline ‘rooting your systems since ’19.’ ShinyHunters told Reuters it gained access on Friday by exploiting a vulnerability in the software running Clop’s site, and claimed the breach gave it extensive reach into Clop’s broader infrastructure. The Register confirmed the defaced site was visible and that ShinyHunters was actively posting escalating demands on it.
The backstory: a dispute over a zero-day
ShinyHunters frames the confrontation as settling a grievance. The crew claims it discovered a zero-day vulnerability in Oracle’s E-Business Suite first, only for Clop to acquire the exploit and deploy it against corporate networks in a campaign last year. ShinyHunters now wants a share of whatever Clop earned from those attacks. Whether that account is accurate is not independently verified, and Clop has offered no public comment.
Escalating demands
The initial demand, posted on 19 September, sought an eight-figure sum described as 2.333 percent of ShinyHunters’ claimed net worth — an odd piece of theatre given the context. A subsequent update raised the demand to all money Clop made from the Oracle EBS campaign, plus interest. By 21 September, ShinyHunters added a new condition: a public apology. The crew also warned that its demands would increase every 24 hours Clop remained silent.
The broader exposure risk
Beyond the obvious reputational damage to Clop, the more significant concern for the wider business community is ShinyHunters’ stated intention to publish records of previous ransom payments. The crew claims it holds data on companies that paid Clop, including negotiated amounts and associated Bitcoin addresses. Organisations that paid Clop under the expectation of confidentiality may find that assumption no longer holds — if ShinyHunters’ access is as extensive as it claims. Those claims remain unverified at the time of writing.
What this means for Clop’s operational credibility
Clop is among the more consequential extortion groups operating today. Its 2023 MOVEit campaign compromised thousands of organisations and exposed data belonging to tens of millions of individuals. The group’s leverage has always rested partly on its ability to demonstrate control — of stolen data, of its leak infrastructure, and of the narrative around victim negotiations. Having a rival crew publicly seize that infrastructure and repurpose it as an extortion vehicle against Clop itself is a meaningful blow to that posture, regardless of how the standoff ultimately resolves.
ShinyHunters’ own record
ShinyHunters is not a peripheral actor. The group has been linked to numerous large-scale data theft and extortion operations. Its decision to target Clop reflects an increasingly combative dynamic within cybercrime ecosystems, where groups compete over exploits, infrastructure, and victims. That competition does not make either party a sympathetic figure, but it does create secondary risks for organisations caught in the crossfire.
Why it matters
For security executives, this incident has two distinct dimensions. First, any organisation that previously negotiated with Clop — paying a ransom or otherwise settling — should treat the possibility of exposure as a live risk. If ShinyHunters publishes payment records, those companies could face renewed reputational, regulatory, and legal scrutiny regardless of how quietly the original incident was managed. Second, this episode is a reminder that criminal infrastructure is not inherently stable or trustworthy. Paying an extortion demand has never guaranteed confidentiality, but this case illustrates concretely how that assumption can collapse when threat actors turn on each other. Security teams should review whether any prior engagements with Clop — direct or through incident response providers — could surface in a data release, and ensure legal and communications teams are briefed accordingly.
What to do now
- If your organisation previously negotiated with Clop or paid a ransom demand attributed to the group, brief your legal, communications, and executive teams now on the possibility that payment records could be published publicly.
- Monitor threat intelligence feeds and dark web sources for any publication of Clop victim or payment data by ShinyHunters.
- Review your organisation’s Oracle E-Business Suite environment for indicators of compromise related to the EBS zero-day campaign referenced in reporting, given Clop’s documented exploitation of that vector.
- Reassess any assumptions about confidentiality in past ransomware negotiations — this incident underscores that payment does not guarantee data or negotiation details will remain private.
