www.infosecurity-magazine.com 21 Sept 2026, 12:30 UTC

ShinyHunters Claims It Hacked and Extorted Clop Ransomware Group

ShinyHunters Claims It Hacked and Extorted Clop Ransomware Group
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Status Unknown
Threat Actor

SHINYHUNTERS has claimed it hacked the Clop ransomware group, defacing Clop’s dark-web leak site on the evening of 18 September 2026. The site displayed the message “THIS SITE HAS BEEN PWN3D BY SHINYHUNTERS”, a Pokémon ASCII image and a link to ShinyHunters’ own leak site. ShinyHunters said it had stolen private keys and server data used to operate Clop’s ransomware activities.

According to Bleeping Computer, the stolen files may include activity records, authentication logs and IP addresses of Clop members who accessed the service, potentially helping to identify them. ShinyHunters reportedly issued Clop a ransom demand and said it intended to extort the group. The claims have not been independently confirmed in the supplied report.

The incident appears to be the latest development in a feud between the two criminal groups that began in 2025, involving competing claims over vulnerabilities in Oracle E-Business Suite servers, including zero-day CVE-2025-61882. KnowBe4’s lead CISO adviser Javvad Malik said the episode showed that cybercriminal groups operate as competing businesses driven by trust, reputation and money, rather than as a coordinated ecosystem.

ShinyHunters has also claimed campaigns involving Salesforce Experience Cloud, Canvas Learning Management System and healthcare company McKesson. Clop, active since 2019, has been linked to attacks including the MOVEit Transfer and MoveIT Cloud exploitation campaign and a December 2025 University of Phoenix breach that affected nearly 3.5 million people.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline