Cybercrime Showdown: ShinyHunters Hijacks Cl0p's Dark Web Leak Site in Extortion Bid
In an unprecedented move, the **ShinyHunters** extortion group has reportedly seized control of the notorious **Cl0p** ransomware gang's dark web leak site. This audacious act has turned the tables, with **ShinyHunters** now using **Cl0p's** own platform to issue an eight-figure extortion demand and threaten to expose the ransomware group's past victims and financial dealings.
The digital underworld is witnessing a rare display of inter-gang warfare as **ShinyHunters**, a group typically known for social engineering and data extortion, has hijacked the dark web leak site belonging to the prolific **Cl0p** ransomware gang.
For years, **Cl0p** has leveraged this site to publicly shame its victims and coerce them into paying ransoms. Now, the tables have turned, with **ShinyHunters** using the very same platform to target **Cl0p** itself.
### The Takeover and Extortion Demands
The defaced site prominently displayed a banner announcing its seizure by **ShinyHunters**. Messages purportedly from **ShinyHunters** detailed an unspecified eight-figure extortion demand, cheekily described as "2.333%" of **Cl0p's** estimated net worth, implying the ransomware group boasts holdings in the hundreds of millions.
"I hope you can pay that much because that is the demand, negotiable. Get your bosses in front of the white board in the war room. Clock is ticking moron. Kindly excuse our unprofessionalism," read one of the notices.
**ShinyHunters** threatened to escalate their demands every 24 hours that **Cl0p** failed to respond. By Monday, these demands had expanded to include a public apology from **Cl0p**.
### Targeting Cl0p's Operations and Operators
A message posted on Sunday went further, naming three individuals identified as **Cl0p** operators, all previously mentioned in public reporting. **ShinyHunters** also demanded proceeds from **Cl0p's** recent campaign targeting **Oracle's E-Business Suite**, a widely used business platform that prompted warnings from **Oracle**, the **FBI**, and cybersecurity agencies in the UK and Singapore.
This feud reportedly stems from **Cl0p's** unauthorized use of a vulnerability and threats against a **ShinyHunters** member. **ShinyHunters** had previously released a proof-of-concept exploit for the **Oracle** vulnerability on Telegram.
As part of their extortion attempt, **ShinyHunters** is threatening to release sensitive records detailing which companies paid **Cl0p**, the amounts paid, and the **Bitcoin** addresses involved.
### Cl0p's Response
By Monday, the defaced site was replaced with a message seemingly from **Cl0p** itself: "Shiny Hunters we trying to reach you Your email does not work. Come online old platform no email[.]"
### A History of High-Profile Attacks
Both groups have a history of significant cyberattacks. **ShinyHunters** has been implicated in disrupting schools across the U.S. in May through an attack on a widely used education platform and stealing information from over 4 million individuals in an April attack on the world's largest medical device company.
Other notable victims of **ShinyHunters** include **Carnival Cruise Line**, **Ticketmaster**, **AT&T**, **McGraw Hill**, **ADT**, and gaming company **Rockstar**.
**Cl0p** is believed to have amassed hundreds of millions of dollars by exploiting previously unknown vulnerabilities in widely used file-transfer products from companies such as **Cleo**, **MOVEit**, **GoAnywhere**, and **Accellion**.