One extortion gang just extorted another
Over the weekend of September 19-20, 2026, the ShinyHunters extortion group hijacked the dark web leak site belonging to Clop, one of the most prolific ransomware and data-extortion operations of the past several years. ShinyHunters exploited an unpatched path traversal vulnerability in Grav CMS, the content management software running Clop's site, defaced it with a banner reading domain seized by ShinyHunters, and claimed to have extracted source code, plugins, server logs, and what it described as Clop's private keys. Clop responded by standing up a new Tor address and publicly denying any relationship with ShinyHunters, a denial that reads more like damage control than a substantive rebuttal given the technical evidence already published.
The vulnerability itself, tracked as CVE-2026-42608, is not new or exotic. Grav's fix, a sanitizeId function restricting form-upload identifiers to a safe character set, shipped in the 2.0 beta more than two years before this incident, with a formal advisory in April 2026. Clop was still running the vulnerable 1.7.x branch when ShinyHunters came looking. The irony is not subtle: a ransomware operation that built its business on other organizations' failure to patch got taken down by its own failure to patch.
The real target is Clop's victims
ShinyHunters is using this breach for leverage, not just bragging rights. The group has demanded an eight-figure sum from Clop, framed at one point as 2.333 percent of Clop's alleged net worth, and escalated its demands to include everything Clop made off its Oracle E-Business Suite campaign plus interest, along with a public apology. If Clop does not pay, ShinyHunters has threatened to publish the identities of every organization that paid Clop a ransom, along with the payment amounts and the Bitcoin addresses used. ShinyHunters also says it will raise the demand every 24 hours it goes unanswered.
This is the detail that should worry every CISO who has ever authorized a ransom payment, regardless of which gang was on the other end. Companies that paid Clop, including the more than 40 alleged victims from its PTC Windchill campaign such as Shell, Philips, and Fiserv, negotiated those payments under an assumption of criminal-to-victim confidentiality. That assumption just failed, and the cause was a second criminal group compromising the first one's infrastructure for its own extortion leverage, with no law enforcement takedown or whistleblower anywhere in the picture.
Confidentiality in ransom negotiation was always an illusion
Boards and legal counsel have historically treated ransom negotiation confidentiality as a reasonably durable assumption, factoring it into decisions about whether to disclose a payment publicly, how to describe an incident to regulators, and how to manage reputational exposure. This incident demonstrates that the durability of that confidentiality depends entirely on the operational security of a criminal organization that has no incentive, contractual obligation, or reputational stake in protecting it once its own infrastructure is compromised by someone else.
The practical implication is that any past ransom payment should now be modeled as a disclosure risk with an indefinite time horizon, not a closed chapter. Legal and communications teams that handled a ransom payment as a quiet, resolved matter should revisit whether their public position, regulatory filings, and customer communications would hold up if the payment, amount, and negotiation details became public tomorrow through no fault of their own. That is a materially different risk posture than assuming the matter ended when the decryption key arrived, and it argues for treating every historical ransom payment the same way you would treat an unresolved regulatory inquiry: quietly monitored, periodically reassessed, and never fully closed out of the risk register.
Even criminal infrastructure has a patch management problem
There is a second lesson buried in the technical details that applies well beyond the extortion economy: Clop, an operation sophisticated enough to run a global data-theft campaign against dozens of enterprises, still failed at the same basic hygiene task that trips up ordinary IT departments, running a two-year-old unpatched CMS on infrastructure it depended on. Sophistication in one domain, exploiting enterprise software supply chains, does not transfer to discipline in another, patching your own stack.
For enterprise security leaders, this is a useful corrective against the assumption that adversaries are uniformly disciplined operators who never make the mistakes your own organization makes. Threat actors are running businesses with the same operational pressures, technical debt, and shortcuts as anyone else, and their infrastructure is exploitable by the same class of vulnerability you are supposed to be patching internally. It is a small but real reminder that basic patch hygiene remains one of the highest-leverage security investments available, for attackers and defenders alike, and it is worth citing the next time a patching backlog review meeting drifts toward treating unpatched third-party software as a low-priority finding rather than the kind of gap that just cost a ransomware operation its entire leak-site infrastructure.
What to do with this before it becomes your headline
If your organization has ever paid a ransom to Clop or any other extortion group, get ahead of this now: brief legal counsel and your communications team on the possibility that payment details could surface through channels entirely outside your control, and prepare a response before you are forced to react to a leak. Do not wait for ShinyHunters' deadline to pass or for your name to appear on a list you have no way of preventing from being published.
More broadly, build the assumption of eventual disclosure into every future ransom decision, not just this one. A payment made today under confidential terms with one threat actor could become public tomorrow because a second, unrelated attacker broke into the first one's systems. That changes the calculus on paying at all, and it strengthens the case for incident response plans that assume every ransom decision will eventually become public knowledge, on a timeline you do not get to choose. Bring that assumption into the room the next time a tabletop exercise or a real negotiation puts a ransom payment on the table, because the price of getting it wrong is no longer just the ransom itself.



