ShinyHunters Hacked Clop. Now What About Clop’s Victims?

A Ransomware Rivalry Escalates: ShinyHunters Hacks Clop, Raises Concerns for Victims

In a shocking turn of events, financially motivated cybercrime group ShinyHunters has breached and defaced the Dark Web site of notorious ransomware gang Clop. The attack not only exposed Clop’s internal data but also raised alarms about potential renewed extortion attempts against victim organizations.

ShinyHunters is known for its data theft and extortion attacks, often collaborating with other cybercriminal groups like Scattered Spider and Lapsus$. Clop, on the other hand, has been responsible for large-scale ransomware campaigns that exploit zero-day vulnerabilities in software applications. The group’s most notable campaigns include a massive 2023 attack that exploited a vulnerability in Progress Software’s MOVEit file transfer software and another campaign targeting Fortra GoAnywhere.

The breach occurred last week when ShinyHunters allegedly exploited an unauthenticated file upload vulnerability in the Grav CMS used by Clop’s leak site. The attackers claimed to have obtained full access to the server, stealing source code, system logs, private keys for the Onion service, and other sensitive data. However, these claims have not been independently verified.

The aftermath of the breach has seen ShinyHunters taunting Clop with messages on their Dark Web site, demanding an eight-figure payment in Bitcoin and threatening to release information about companies that allegedly paid ransomware to Clop. The attackers referenced Clop’s extortion campaign targeting customers affected by a critical Oracle E-Business Suite (EBS) zero-day vulnerability last fall.

The true extent of the breach remains unclear, but one concern is whether ShinyHunters obtained any information about Clop’s victims. While there is no concrete evidence that they have this data, the threat to release sensitive information about companies that paid ransomware to Clop raises alarms for victim organizations. This could lead to renewed extortion attempts or further exposure of sensitive information.

Experts agree that while cybercriminal feuds can be seen as a positive development, as they may divert attention away from legitimate businesses, it is essential to consider the potential consequences for victims. “Stolen information doesn’t retire,” notes Jon Baker, vice president of threat-informed defense at AttackIQ. This highlights the ongoing risks associated with data breaches and the importance of protecting sensitive information.

As this situation unfolds, organizations that paid ransomware to Clop should be on high alert for any potential renewed extortion attempts or exposure of sensitive information. It is crucial for these companies to take proactive measures to protect their data and reputation.


Source: Dark Reading — 2026-09-21