ShinyHunters apparently breached rival ransomware gang Clop last week, and the incident could pose additional risks to victim organizations caught in the middle.

ShinyHunters is a financially motivated cybercrime group known primarily for data theft and extortion attacks. The group’s identity has become increasingly fluid, with researchers observing ties to and collaboration with cybercriminals associated with the Scattered Spider and Lapsus$ collectives.

Clop, meanwhile, is a notorious ransomware gang best known for large-scale data extortion campaigns, particularly involving zero-day vulnerabilities. Clop actors were behind the massive 2023 campaign that exploited a zero-day in Progress Software’s MOVEit file transfer software, as well as a similar campaign that targeted a Fortra GoAnywwhere flaw that same year.

Over the weekend, ShinyHunters defaced Clop’s Dark Web data leak site with a message: “DOMAIN SEIZED BY SHINYHUNTERS.” As first reported by BleepingComputer, ShinyHunters claimed the attack began on Friday night when it exploited an unauthenticated file upload vulnerability in the Grav CMS used by Clop’s leak site.

Related:Cybercriminals Are Hiding New Malware in Torrents for Popular Films

ShinyHunters vs. Clop: Cybercrime Feud

ShinyHunters claimed it obtained full access to Clop’s leak site server and stole source code, Grav CMS plug-ins, system logs, private keys for its Onion service, and other data. Those data-theft claims have not been independently verified.

The attackers continued to leave messages on Clop’s site taunting the ransomware group and attempting to extort it. On Sept. 19, a message attributed to ShinyHunters demanded an unspecified eight-figure payment in Bitcoin and directed Clop to contact an Onionmail address.

On Sept. 20, the attackers wrote on Clop’s page, “I want all the money you made off the EBS campaign plus more AND WITH INTEREST, before I start releasing information regarding the companies that paid you, how much, and to what Bitcoin address.”

The reference to “EBS” likely references Clop’s extortion campaign targeting customers affected by the critical Oracle E-Business Suite (EBS) zero-day vulnerability CVE-2025-61882 last fall. Public feuds and attacks between cybercriminal groups aren’t uncommon; earlier this year, two emerging ransomware groups, 0APT and KryBit, hacked one another and leaked internal data.

What About the Ransomware Victims?

ShinyHunters’ effort does not appear to have yet resulted in a payment, as the defacement message included a note dated today. “Every 24 hours you fail to engage with us the demands increase. The demand now includes a mandatory apology issued directly to me PUBLICLY,” the latest note read.

Related:Vectra AI Launches Ascent to Help Address New Era of AI-Driven Attacks

However, Dark Reading confirmed that, as of this writing, Clop’s leak site removed the defacement message and now displays a plain text note, possibly from Clop itself, claiming ShinyHunters’ email address does not work.

On one hand, cybercriminals feuds could be seen as a positive, because as Malwarebytes’ Pieter Arntz noted in a blog post, “The good news is that while they are after each other, they probably have less time to attack legitimate businesses.”

On the other hand, it’s unknown whether ShinyHunters obtained any information about Clop’s victims. At this time, ShinyHunters has not provided proof that it has this data in its possession. That said, ShinyHunters has already threatened to publish information about companies that allegedly paid Clop, including payment amounts and Bitcoin addresses. If ShinyHunters obtained additional information tied to Clop’s victims, those organizations could potentially face further exposure or even renewed extortion attempts.

Jon Baker, vice president of threat-informed defense at AttackIQ, tells Dark Reading that there’s no proof yet that ShinyHunters actually obtained Clop’s victim files, but a larger point is that “stolen information doesn’t retire.”

Related:EY Survey Finds Autonomous AI Implementation Outpaces Oversight

“[Stolen data] sits on servers run by the original group, its affiliates and its infrastructure providers, and every copy is another chance for theft, resale or exposure,” he says. “A company can spend years accountable for data it can no longer locate or control.”

Similarly, Darren Guccione, CEO and cofounder at Keeper Security, said the fundamental problem behind this is that “you can’t rely on criminals to honor agreements” even if you paid a ransom.

“Paying for deletion assumes the criminal will destroy the data, but you’re negotiating with someone whose business model is deception and theft,” Guccione says. “Once data leaves an organization’s control, there’s no mechanism to verify it was destroyed, no audit trail and no recourse if the promise is broken.”

It remains to be seen whether ShinyHunters actually obtained Clop victim information or not. This public feud, however, illustrates a risk that begins the moment data is exfiltrated: An organization may remain responsible for information that is now stored on infrastructure it cannot secure, audit, or even locate.





Source link

#

No responses yet

Leave a Reply

Your email address will not be published. Required fields are marked *