
ShinyHunters Hijacks Cl0p Leak Site With Eight-Figure Demand and Payment Ledger Threats
ShinyHunters exploited an ongoing feud to seize Cl0p's infrastructure and threaten payment data exposure. Evidence from the defaced site and prior campaign timelines shows direct tactical convergence on Oracle flaws. This increases risk of secondary leaks affecting organizations that paid Cl0p ransoms.
The takeover replaced Cl0p's standard victim-naming page with a banner claiming domain seizure and messages naming three known Cl0p operators while demanding proceeds from the recent Oracle campaign plus an unspecified eight-figure sum calculated at 2.333 percent of claimed net worth. Demands escalated to include a public apology, with threats to release Bitcoin addresses and payer identities if unmet. The site briefly returned Monday with a Cl0p message seeking contact via old channels. This incident reveals operational overlap between the groups on the same zero-day, contradicting prior separation of their tactics. ShinyHunters' public PoC release preceded Cl0p's exploitation, suggesting either shared tooling or direct theft rather than independent discovery. Contract and procurement records show both groups targeting overlapping enterprise platforms without state attribution evidence. The feud exposes a pattern of intra-ecosystem targeting where data extortion groups leverage social engineering against ransomware operators to extract ledgers that could expose downstream victims.
ShinyHunters: Will publish at least one Cl0p payment ledger within 14 days if no public settlement is reached.
Sources (3)
- [1]The Record(https://therecord.media/shinyhunters-clop-cyberattack-website)
- [2]Oracle Security Alert(https://www.oracle.com/security-alerts/)
- [3]Recorded Future Analysis(https://www.recordedfuture.com/)