A Rival Ransomware Gang Takes Down Clop in a Bizarre Cyber Heist
In a shocking turn of events, ShinyHunters, a financially motivated cybercrime group, has hacked into the operations of rival ransomware gang Clop. The attack, which began on Friday night, resulted in Clop’s Dark Web data leak site being defaced with a message claiming that ShinyHunters had stolen sensitive information and was now extorting Clop for an eight-figure payment.
The attack is significant not just because it highlights the internal conflicts within the cybercrime underworld, but also because it poses additional risks to organizations that were previously targeted by Clop. The group, known for its large-scale data extortion campaigns using zero-day vulnerabilities, had already compromised several high-profile targets in 2023, including Progress Software’s MOVEit file transfer software and Fortra GoAnywhere flaw.
ShinyHunters claimed that it exploited an unauthenticated file upload vulnerability in the Grav CMS used by Clop’s leak site to gain access. The group alleged that it obtained full access to Clop’s server and stole sensitive data, including source code, private keys for its Onion service, and system logs. While these claims have not been independently verified, they raise concerns about the potential exposure of Clop’s victims.
One of the most pressing questions is whether ShinyHunters actually obtained information about Clop’s victims. The group has threatened to publish details about companies that allegedly paid Clop, including payment amounts and Bitcoin addresses, but it remains unclear if this data exists in their possession. If ShinyHunters did obtain victim files, those organizations could potentially face further exposure or even renewed extortion attempts.
The feud between ShinyHunters and Clop is a fascinating example of the internal dynamics within the cybercrime underworld. While some may see these conflicts as beneficial because they distract from legitimate targets, experts caution that stolen information can be resold or reused at any time. As Jon Baker, vice president of threat-informed defense at AttackIQ, notes, “stolen information doesn’t retire.” This means that even if ShinyHunters does not follow through on its threats, the data could still be used for malicious purposes in the future.
For organizations that were previously targeted by Clop, this development serves as a stark reminder of the ongoing risks they face. It is essential to maintain robust security measures and remain vigilant against potential renewed extortion attempts or further exposure of sensitive information. As we continue to navigate the complex world of cyber threats, one thing remains clear: the stakes are high, and the players involved are constantly evolving.
Source: Dark Reading — 2026-09-21