ShinyHunters Hacked Clop. Now What About Clop's Victims?
Recorded: Sept. 21, 2026, 9 p.m.
| Original | Summarized |
ShinyHunters Hacked Clop. Now What About Clop's Victims? Informa TechTarget|Cybersecurity DiveInformationWeekChannel DiveTechTarget: CybersecurityExplore our brandsAn Informa TechTarget PublicationDark Reading Resource LibraryBlack Hat NewsOmdia CybersecurityAdvertiseNewsletter Sign-UpNewsletter Sign-UpCybersecurity TopicsRelated TopicsApplication SecurityCybersecurity CareersCloud SecurityCyber RiskCyberattacks & Data BreachesCybersecurity AnalyticsCybersecurity OperationsData PrivacyEndpoint SecurityICS/OT SecurityIdentity & Access Mgmt SecurityInsider ThreatsIoTMobile SecurityPerimeterPhysical SecurityRemote WorkforceThreat IntelligenceVulnerabilities & ThreatsRecent in Cybersecurity TopicsVulnerabilities & ThreatsCisco Zero-Day Highlights API Endpoint Authentication IssuesCisco Zero-Day Highlights API Endpoint Authentication IssuesbyRob WrightSep 18, 20264 Min ReadCybersecurity OperationsAI Security Spending Jumps as Fear Outpaces Proof of ValueAI Security Spending Jumps as Fear Outpaces Proof of ValuebyJai VijayanSep 16, 20265 Min ReadWorld Related TopicsDR GlobalAsia PacificEuropeLatin AmericaMiddle East & AfricaSee AllThe EdgeDR TechnologyEventsRelated TopicsUpcoming EventsPodcastsWebinarsSEE ALLResourcesRelated TopicsResource LibraryWhite PapersReportsWebinarsNewslettersPodcastsHeard It From a CISOReporters' NotebookDark Reading's 20thVideosDark Reading PollsPartner PerspectivesMeet the EditorsAdvertise With Us About UsDark Reading Resource LibraryCyberattacks & Data BreachesVulnerabilities & ThreatsCybersecurity OperationsCyber RiskNewsShinyHunters Hacked Clop. Now What About Clop's Victims?ShinyHunters defaced Clop's Dark Web site and claims to have stolen victim data, potentially exposing organizations that paid ransoms to renewed extortion attempts.Alexander Culafi,Senior News Writer,Dark ReadingSeptember 21, 20264 Min ReadSource: winhorse via Getty ImagesShinyHunters apparently breached rival ransomware gang Clop last week, and the incident could pose additional risks to victim organizations caught in the middle.ShinyHunters is a financially motivated cybercrime group known primarily for data theft and extortion attacks. The group's identity has become increasingly fluid, with researchers observing ties to and collaboration with cybercriminals associated with the Scattered Spider and Lapsus$ collectives.Clop, meanwhile, is a notorious ransomware gang best known for large-scale data extortion campaigns, particularly involving zero-day vulnerabilities. Clop actors were behind the massive 2023 campaign that exploited a zero-day in Progress Software's MOVEit file transfer software, as well as a similar campaign that targeted a Fortra GoAnywwhere flaw that same year.Over the weekend, ShinyHunters defaced Clop's Dark Web data leak site with a message: "DOMAIN SEIZED BY SHINYHUNTERS." As first reported by BleepingComputer, ShinyHunters claimed the attack began on Friday night when it exploited an unauthenticated file upload vulnerability in the Grav CMS used by Clop's leak site.Related:Cybercriminals Are Hiding New Malware in Torrents for Popular FilmsShinyHunters vs. Clop: Cybercrime FeudShinyHunters claimed it obtained full access to Clop's leak site server and stole source code, Grav CMS plug-ins, system logs, private keys for its Onion service, and other data. Those data-theft claims have not been independently verified.The attackers continued to leave messages on Clop's site taunting the ransomware group and attempting to extort it. On Sept. 19, a message attributed to ShinyHunters demanded an unspecified eight-figure payment in Bitcoin and directed Clop to contact an Onionmail address.On Sept. 20, the attackers wrote on Clop's page, "I want all the money you made off the EBS campaign plus more AND WITH INTEREST, before I start releasing information regarding the companies that paid you, how much, and to what Bitcoin address."The reference to "EBS" likely references Clop's extortion campaign targeting customers affected by the critical Oracle E-Business Suite (EBS) zero-day vulnerability CVE-2025-61882 last fall. Public feuds and attacks between cybercriminal groups aren't uncommon; earlier this year, two emerging ransomware groups, 0APT and KryBit, hacked one another and leaked internal data.What About the Ransomware Victims?ShinyHunters' effort does not appear to have yet resulted in a payment, as the defacement message included a note dated today. "Every 24 hours you fail to engage with us the demands increase. The demand now includes a mandatory apology issued directly to me PUBLICLY," the latest note read.Related:Vectra AI Launches Ascent to Help Address New Era of AI-Driven AttacksHowever, Dark Reading confirmed that, as of this writing, Clop's leak site removed the defacement message and now displays a plain text note, possibly from Clop itself, claiming ShinyHunters' email address does not work.On one hand, cybercriminals feuds could be seen as a positive, because as Malwarebytes' Pieter Arntz noted in a blog post, "The good news is that while they are after each other, they probably have less time to attack legitimate businesses."On the other hand, it's unknown whether ShinyHunters obtained any information about Clop's victims. At this time, ShinyHunters has not provided proof that it has this data in its possession. That said, ShinyHunters has already threatened to publish information about companies that allegedly paid Clop, including payment amounts and Bitcoin addresses. If ShinyHunters obtained additional information tied to Clop's victims, those organizations could potentially face further exposure or even renewed extortion attempts.Jon Baker, vice president of threat-informed defense at AttackIQ, tells Dark Reading that there's no proof yet that ShinyHunters actually obtained Clop's victim files, but a larger point is that "stolen information doesn't retire."Related:EY Survey Finds Autonomous AI Implementation Outpaces Oversight"[Stolen data] sits on servers run by the original group, its affiliates and its infrastructure providers, and every copy is another chance for theft, resale or exposure," he says. "A company can spend years accountable for data it can no longer locate or control."Similarly, Darren Guccione, CEO and cofounder at Keeper Security, said the fundamental problem behind this is that "you can't rely on criminals to honor agreements" even if you paid a ransom."Paying for deletion assumes the criminal will destroy the data, but you're negotiating with someone whose business model is deception and theft," Guccione says. "Once data leaves an organization's control, there's no mechanism to verify it was destroyed, no audit trail and no recourse if the promise is broken."It remains to be seen whether ShinyHunters actually obtained Clop victim information or not. This public feud, however, illustrates a risk that begins the moment data is exfiltrated: An organization may remain responsible for information that is now stored on infrastructure it cannot secure, audit, or even locate.About the AuthorAlexander CulafiSenior News Writer, Dark ReadingAlex is an award-winning writer, journalist, and podcast host based in Boston. After cutting his teeth writing for independent gaming publications as a teenager, he graduated from Emerson College in 2016 with a Bachelor of Science in journalism. He has previously been published on VentureFizz, Search Security, Nintendo World Report, and elsewhere.At Dark Reading, he covers a variety of cybersecurity topics, including the cybercrime ecosystem, open source security, and the intersection between AI and threat actors. In his spare time, Alex hosts the weekly Nintendo podcast, "Talk Nintendo Podcast," and works on personal writing projects, including two previously self-published science fiction novels.He has received numerous awards, including TechTarget's Writer of the Year in 2022 as well as more than 10 Azbee awards for his reporting between 2022 and today.See more from Alexander CulafiWant more Dark Reading stories in your Google search results?Add Us NowMore InsightsIndustry ReportsThe State of Cloud Security: The Latest ChallengesHow Organizations Are Managing Incident ResponseHow Enterprises Are Developing Secure ApplicationsInside RSAC 2026: security leaders reveal the risks redefining your defense strategyEssential News & Insights from Black Hat USA 2025Access More ResearchWebinarsEffective Alert Triage: Reducing Noise and Finding Real ThreatsCybersecurity Outlook 2027Benchmark Scores Are a False FlagThreat Exposure Analytics: Measuring and Communicating Security RiskBuilding an Effective Red Team: Beyond Penetration TestingMore WebinarsFeaturedCheck out the Black Hat USA 2026 Conference Guide for coverage and intel from — and about — the show!Editor's ChoiceCyber RiskAnthropic CEO: Time to Shift From Improving to Controlling AIAnthropic CEO: Time to Shift From Improving to Controlling AIbyElizabeth MontalbanoSep 14, 20266 Min ReadCyber RiskWhy AI Is So Good at Scamming HumansWhy AI Is So Good at Scamming HumansSep 11, 2026Want more Dark Reading stories in your Google search results?November 12, 2026 | VIRTUALWhat Every Enterprise Should Know About Securing Cloud Assets In the Age of AISave Your SpotKeep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.SubscribeDiscover MoreBlack HatOmdiaWorking With UsAbout UsMeet the EditorsAdvertiseReprintsJoin UsNewsletter Sign-UpFollow UsCopyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466.Home|Cookie Policy|Privacy|Terms of UseYour Privacy Choices |
The interaction between the financially motivated cybercrime group ShinyHunters and the ransomware gang Clop raises significant concerns regarding the security and accountability of organizations that have fallen victim to extortion. ShinyHunters, known for data theft and extortion, defaced Clop's Dark Web site, claiming to have stolen crucial assets such as source code, system logs, Grav CMS plug-ins, and private keys, although these specific claims have not been independently verified. This conflict highlights the precarious nature of digital assets when they are in the hands of organized cybercriminals. ShinyHunters reportedly gained access by exploiting an unauthenticated file upload vulnerability in the Grav CMS used by Clop's leak site, which suggests a successful breach of the server. The attackers further engaged in extortion, demanding substantial payments, including specifying amounts related to previous campaigns, and threatening to release information about the companies involved, potentially exposing payment details and Bitcoin addresses. Clop itself is a notorious ransomware group recognized for large-scale data extortion, notably through campaigns that exploited zero-day vulnerabilities in software like Progress Software's MOVEit and Fortra GoAnywwhere. This feud between the two groups underscores the broader risks associated with data exfiltration, irrespective of which party is the primary target. A critical unresolved question is whether ShinyHunters actually obtained any information pertaining to Clop's victims. Although the attackers threatened to publish details about the organizations that paid ransoms, the text notes that there is no current proof that ShinyHunters possessed Clop's victim files. This situation extends to the systemic problem of data ownership and accountability following a breach. As noted by Jon Baker, vice president of threat-informed defense at AttackIQ, stolen information does not retire, and this concept is amplified when data resides on infrastructure controlled by criminal entities, meaning any copy creates further opportunities for theft or exposure. Darren Guccione, CEO and cofounder at Keeper Security, articulates that the core issue lies in the inability to rely on criminals to honor agreements, regardless of ransom payment. Paying a ransom does not equate to data destruction, and once data leaves an organization's control, there is no reliable mechanism for verification, auditing, or recourse should the promise of deletion be broken. This reality suggests that organizations can remain responsible for data that is merely stored on infrastructure they cannot secure, locate, or audit. While public feuds between cybercriminal groups may seem paradoxical, one perspective suggests a potential benefit, as observed by Pieter Arntz of Malwarebytes, where such conflicts might reduce the time available for attacks against legitimate businesses. Nevertheless, the incident serves as a stark illustration that the risk begins the moment data is exfiltrated, leaving organizations exposed to ongoing liability and potential renewed extortion attempts. |