SHINYHUNTERS has claimed it hacked the Clop ransomware group, defacing Clop’s dark-web leak site on the evening of 18 September 2026. The site displayed the message “THIS SITE HAS BEEN PWN3D BY SHINYHUNTERS”, a Pokémon ASCII image and a link to ShinyHunters’ own leak site. ShinyHunters said it had stolen private keys and server data used to operate Clop’s ransomware activities.
According to Bleeping Computer, the stolen files may include activity records, authentication logs and IP addresses of Clop members who accessed the service, potentially helping to identify them. ShinyHunters reportedly issued Clop a ransom demand and said it intended to extort the group. The claims have not been independently confirmed in the supplied report.
The incident appears to be the latest development in a feud between the two criminal groups that began in 2025, involving competing claims over vulnerabilities in Oracle E-Business Suite servers, including zero-day CVE-2025-61882. KnowBe4’s lead CISO adviser Javvad Malik said the episode showed that cybercriminal groups operate as competing businesses driven by trust, reputation and money, rather than as a coordinated ecosystem.
ShinyHunters has also claimed campaigns involving Salesforce Experience Cloud, Canvas Learning Management System and healthcare company McKesson. Clop, active since 2019, has been linked to attacks including the MOVEit Transfer and MoveIT Cloud exploitation campaign and a December 2025 University of Phoenix breach that affected nearly 3.5 million people.