ShinyHunters Just Hacked a Rival Ransomware Gang's Leak Site, and That Should Worry You Too
Cybersecurity

ShinyHunters Just Hacked a Rival Ransomware Gang's Leak Site, and That Should Worry You Too

ShinyHunters broke into Clop's dark web leak site through an unpatched Grav CMS upload flaw, defaced it, and claims to hold Clop's private onion keys and server logs, escalating a feud that started over stolen exploit code from last year's Oracle campaign.

PublishedSeptember 20, 2026
Read time6 min read
Share

One extortion gang breaches another

On September 19, ShinyHunters announced it had fully compromised the dark web leak site operated by Clop, one of the most prolific ransomware and extortion groups of the past several years, responsible for mass-exploitation campaigns against MOVEit, GoAnywhere, and Oracle E-Business Suite customers. The attackers defaced the site, replacing it with Pokemon-themed ASCII art and a taunting message: "THIS SITE HAS BEEN PWN3D BY SHINYHUNTERES #Skids10p, Maybe don't try to threaten us next time." The access method was almost mundane for a group with this level of notoriety: an unauthenticated file upload vulnerability in Grav CMS, the content management system running Clop's leak site, that let attackers upload a small file and parlay it into complete server compromise.

ShinyHunters claims the haul includes Clop's source code and CMS plugins, system logs from /var/log containing authentication data and IP addresses, and, most consequentially, Clop's Tor onion service private keys. Controlling those keys would let ShinyHunters impersonate or redirect Clop's own leak site infrastructure even if Clop tries to cut off their access. The group has stated its intent plainly: "Going to extort them," giving Clop a 72-hour window to make contact before demands go public on ShinyHunters' own leak site, an extortion gang extorting an extortion gang, using the same dark web infrastructure and threat language victims normally see aimed at themselves.

A feud with a paper trail

This is not a random beef. ShinyHunters alleges the conflict originates in Clop's October 2025 mass-exploitation campaign against Oracle E-Business Suite customers, claiming Clop used exploit code that ShinyHunters itself developed or possessed, without credit or compensation. According to the reporting, tensions since then have escalated well past the usual trash talk between rival criminal brands, including alleged death threats attributed to Clop representatives. Whatever the precise sequence, the result is two of the more capable extortion operations in the ecosystem now actively working to burn each other down using real technical compromise rather than just public posturing.

The irony is hard to miss. Clop has spent years building a reputation around mass-exploiting unpatched enterprise software, MOVEit, GoAnywhere, and Oracle among them, to steal data at scale. Its own leak site apparently ran a content management system with an unauthenticated upload vulnerability sitting exposed, the exact class of mistake Clop has profited from repeatedly when enterprises make it. There is a lesson in that symmetry for defenders: even sophisticated, well-resourced threat actors skip basic patch hygiene on their own infrastructure, which should temper any assumption that an adversary's tooling or operational security is inherently more disciplined than a typical enterprise's.

Why gang-on-gang chaos is a defender's problem too

It is tempting to read this as pure entertainment, criminals attacking criminals, with no direct bearing on enterprise risk. That reading misses the operational consequences. Ransomware negotiation, however distasteful, has historically operated on a grim but somewhat predictable logic: pay or don't, and the data's fate rests with a single identifiable actor. When rival gangs are actively stealing each other's stolen data, leak site infrastructure, and even negotiation channels, that predictability breaks down. A victim organization negotiating with Clop today has no assurance that the data Clop holds will not end up republished, resold, or weaponized by ShinyHunters regardless of what Clop agrees to.

This kind of internecine conflict also tends to accelerate a gang's timeline for monetizing whatever data it is sitting on, since compromised infrastructure and threatened reputational damage create pressure to cash out faster rather than negotiate patiently. Organizations currently in extortion negotiations with Clop, or that have unresolved exposure from its prior campaigns, should treat this development as a reason to accelerate their own incident response and legal posture rather than assume the status quo holds. The stability defenders have learned to plan around in ransomware negotiations is eroding as the criminal ecosystem fragments and turns on itself.

The fragmentation trend this fits into

This incident lands inside a broader shift in the ransomware and extortion ecosystem this year: fewer monolithic, brand-name gangs operating with internal discipline, and more overlapping crews, affiliates, and splinter groups that share tooling, poach victims, and increasingly turn on each other. ShinyHunters itself has been linked to multiple simultaneous extortion campaigns against different victim classes over the past year, operating less like a single organization and more like a loose brand that different actors invoke opportunistically. Clop's breach fits that pattern: a rival with overlapping history and resentment over shared exploit code, using the same infrastructure-compromise playbook Clop itself is known for.

For threat intelligence teams, that fragmentation makes attribution and negotiation both harder. A ransom note signed by one gang no longer guarantees that gang alone controls the outcome, and a payment made in good faith to one operator provides no assurance against a second group republishing the same data under a different banner. Enterprises building ransomware response playbooks should explicitly account for this multi-actor risk rather than modeling negotiations as a two-party transaction between the victim and a single, stable adversary.

What this means for incident response planning

For CISOs and legal teams, the practical implication is that any existing exposure to Clop, whether from the Oracle campaign or prior incidents, needs a fresh look now rather than a wait-and-see approach, since the assumptions underlying any prior negotiation or risk assessment may no longer hold if a second group has access to the same stolen data. Incident response retainers and outside counsel should be briefed on this development specifically, because it changes the calculus around notification timing and public disclosure if previously stolen data resurfaces through a different leak site entirely.

More broadly, this is a reminder that threat intelligence programs need to track the criminal ecosystem's internal dynamics, not just individual group TTPs, because a rival group's breach of a ransomware operator's infrastructure can directly change a victim organization's risk posture overnight. It also reinforces a point that keeps recurring across this category: basic web application hygiene, patched CMS software, authenticated upload endpoints, still separates the compromised from the uncompromised, whether the target is a Fortune 500 company or a ransomware gang's own dark web presence.

Tagged#news#security#cybersecurity#breach#cisa#ransomware#zero-day#supply-chain#ai-security#shinyhunters#clop#ransomware-gangs#grav-cms#dark-web#clop-leak-site#grav-cms-flaw#ransomware-rivalry