SHINYHUNTERS has reportedly taken control of the dark-web leak site operated by rival extortion group Clop, also known as Cl0p. The site displayed ShinyHunters’ branding and a message demanding payment, an apology and other concessions from Clop, while threatening to publish information about companies that allegedly paid the group, along with payment amounts and Bitcoin addresses. The claims had not been independently verified in the report.
According to BleepingComputer, the attack began on Friday night when ShinyHunters allegedly exploited an unauthenticated file-upload vulnerability in the site’s Grav CMS to upload a small text file. ShinyHunters later said it had “completely defaced” the site and claimed to possess Clop’s onion keys and private keys, which it said would allow it to continue hosting the same onion address even if Clop removed its access.
The group attributed the dispute to a previous Oracle EBS data-theft campaign and alleged that a Clop representative had issued threats against its members. The incident demonstrates that criminal extortion operations can also leave their own internet-facing infrastructure exposed, although there is no confirmed indication in the report that the conflict has reduced attacks against legitimate organisations.