A long-running feud between two prominent cyber extortion groups has exploded into action after the ShinyHunters group hacked and then defaced the darkweb leak site belonging to the Cl0p extortion operation.
The beef began on September 19, when ShinyHunters uploaded a small text file to Cl0p’s leak site via a file upload vulnerability in the site’s CMS, according to reporting by Bleeping Computer, who were able to access Cl0p’s site before hostilities escalated.
"THIS SITE HAS BEEN PWN3D BY SHINYHUNTERES #Skids10p - Maybe don't try to threaten us next time," the file said.
Within hours, however, Cl0p’s site had been defaced, and as of writing the .onion address remains offline.
A day after the site defacement, ShinyHunters published a message to Cl0p on its own leak site.
"Email us from your official email at shinygroup@[xxx].com and let's see how rich you really are,” the hackers said.
“2.333 per cent of my net worth is a 8 figure amount, I hope you can pay that much because that is the demand, negotiable. Get your bosses in front of the whiteboard in the war room. Clock is ticking moron. Kindly excuse our unprofessionalism."
A later message, published on September 20, suggested ShinyHunters had done more than just deface Cl0p’s website and upload a note.
“Dear Likhogray & Tarasov, tell your boss j0nny to wake the f**k up. Run those pockets. I want all the money you made off the EBS campaign plus more AND WITH INTEREST, before I start releasing information regarding the companies that paid you, how much, and to what Bitcoin address,” ShinyHunters said.
“My phone book contains all major financial media outlets. CLOCK IS TICKING! LETS GET THE BALL ROLLING! Be sure to bring an English interlocutor so you can comprehend my literacy in acquiring your bank account. 66 hours remaining."
While it was busy extorting its fellow extortionist, ShinyHunters also had to deal with its own site issues, which the group strenuously claimed had nothing to do “with the matter involving Cl0p -_-. Do not spread FAKE NEWS”.
Ian Gray, VP of Intelligence at Flashpoint, offers some background on the groups and where the feud may end up.
“Clop and ShinyHunters have occupied two very different but related corners of the extortion ecosystem,” Gray told Cyber Daily.
“Clop has distinguished itself by finding and exploiting zero-day vulnerabilities in widely deployed enterprise data-handling platforms, file transfer applications like Accellion, MOVEit and Cleo, and most recently Oracle E-Business Suite, stealing data and threatening to leak it unless an extortion payment is made.
“The most recent iteration of ShinyHunters has gone after a softer target: weaknesses in how organisations verify identity, using voice phishing against IT help desks and abusing session tokens to reach data in software-as-a-service platforms. Clop's external communications have been subdued. ShinyHunters has been boisterous about its purported access and openly aggrieved toward other groups. That is where the two overlap.”
The current animosity between the groups is nothing new, and dates back to a prior hacking collective – the same one, in fact, that targeted Qantas in 2025.
“On August 10, 2025, the Telegram channel ‘scattered lapsu$ hunters – The Com HQ SCATTERED SP1D3R HUNTERS,’ associated with the actors also tracked as ShinyHunters, advertised a large number of vulnerabilities,” Gray said.
“Among them was an image showing a request to the path /OA_HTML/configurator/UiServlet, which is targeted by the server-side request forgery function in the exploit script.
“On October 3, 2025, the actor shared the post again, claiming it was the same vulnerability Clop used against Oracle. The exploit contains Python scripts that let an attacker run arbitrary commands or open a reverse shell on a vulnerable system. A member of Scattered LAPSUS$ Hunters told BleepingComputer the exploit was originally theirs, and that they leaked it because Clop had taken it and was using it ‘in an unsuccessful way’."
It’s this dispute that we are seeing play out now, to what is possibly an unsurprising conclusion: one group hacking and disrupting the infrastructure of the other.
According to Gray, ShinyHunters is framing the attack as “retaliation for a threat of violence it says a Clop representative made during the Oracle campaign”.
“The demand has escalated daily: an eight-figure payment, and as of September 21, a public apology on top of it. ShinyHunters also claims to hold the private keys to Clop's onion service; if that holds up, it could stand up a site at Clop's exact address, leaving past Clop victims facing a second actor with the same leverage over the same data,” Gray observed.
“ShinyHunters clearly demonstrated access and succeeded in publicly embarrassing a major extortion group. But we haven't seen evidence that it obtained the negotiation records, payment data or other material that would give it the leverage it claims. We'll continue to watch as this feud unfolds.”
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.