Gang-on-Gang Hack Hits Clop Leak Site
ShinyHunters claims it stole private keys and server data from rival Clop, defacing the ransomware group's dark web leak site.
A ransomware gang's public-facing leak site is normally where its victims' data gets displayed. On the evening of 18 September, one of those sites instead became the evidence board in a fight between two criminal crews. Clop's dark web data leak page was defaced with a message reading "THIS SITE HAS BEEN PWN3D BY SHINYHUNTERS," and the background was swapped for ASCII artwork of a Pokémon.
ShinyHunters says it pulled off the intrusion against a fellow cybercriminal operation, and the defacement was the visible part of a claim that goes well beyond graffiti. According to the group's own account, it walked away with the private keys and server data used to run Clop's ransomware operations.
The claim left on Clop's page
The defacement came to light on the evening of 18 September. The message left on Clop's site also included a link pointing back to ShinyHunters' own data leak site, turning the compromised page into a redirect of sorts for anyone who stumbled onto it.
The alleged gang-on-gang attack was first reported by Bleeping Computer. ShinyHunters told that publication it had taken files that could expose activity records, authentication logs and even the IP addresses of Clop members who connected to the service.
If accurate, that material would not be a database of victims. It would be a window into the people running the operation — the kind of records that could be used to identify members of the Clop ransomware gang. There is no independent confirmation of the theft beyond the claims ShinyHunters made to Bleeping Computer.
A ransom note for another gang
Despite Clop being another criminal hacking outfit, ShinyHunters is treating the group like any other victim. The crew has issued a ransom note telling Clop to make contact.
When Bleeping Computer asked what the attackers planned to do with the access they had to Clop, the reply was blunt. The attacker reportedly said, "going to extort them."
That response frames the whole incident as an extortion campaign aimed at an extortion campaign — one crew applying the same leverage model it uses on corporate victims to a rival that runs on the same logic.
Where the feud started
The attack appears to be the latest stage in a feud between the two criminal extortion groups that began in 2025. The row centered on competing claims over ownership of vulnerabilities in Oracle E-Business Suite servers.
That dispute included the zero-day tracked as CVE-2025-61882, which both groups used to steal data from organizations in blackmail and extortion campaigns. The overlap put the two crews in direct competition over the same pool of exploitable systems and, by extension, the same pool of potential victims.
Rival claims over who found or controlled a given flaw are difficult to adjudicate from the outside, and the source material does not say how the dispute was resolved — only that it set the two groups against each other.
An analyst's read on criminal rivalries
The defacement drew a broader observation about how these groups relate to one another.
"This is a useful reminder that cybercriminal groups are not a single, coordinated ecosystem; they are competitive businesses driven by trust, reputation and money," said Javvad Malik, lead CISO advisor at KnowBe4.
Malik extended the point to the mechanics of alliances built inside that world.
"When relationships are built on deception and fear, double-crossing and betrayal is always a credible threat. For defenders, it reinforces the need to understand not just the technology, but the motivations and behaviors of the people behind the attacks."
— Javvad Malik, lead CISO advisor at KnowBe4
ShinyHunters' year of high-profile claims
ShinyHunters is one of the most prolific cyber extortion groups of 2026, with significant campaigns against users of commonly deployed software-as-a-service providers. Two named in the source material are Salesforce Experience Cloud and Canvas Learning Management System.
The group has also claimed an attack on American healthcare giant McKesson, which wholesales medical supplies and pharmaceutical distribution to over 40,000 corporate and institutional customers. A McKesson data breach incident was separately the subject of a 1 September 2026 report.
Those claims sit alongside the Clop defacement as part of the same broad pattern of activity attributed to the group over the past year.
Clop's long record
Clop has been active since 2019 and has been tied to a range of disruptive cyber-attacks. One of the more recent incidents involved a ransomware attack and data breach against the University of Phoenix which affected nearly 3.5 million people in December 2025.
The group was also behind several ransomware attacks against major companies in 2023, carried out by exploiting a security vulnerability in MOVEit Transfer and MOVEit Cloud.
Those two data points — a long operational history and a mass-exploitation campaign — describe a group that has been a persistent presence in the extortion economy for years, which is part of what makes the defacement notable.
The numbers behind the story
- 40,000 — corporate and institutional customers served by McKesson, the healthcare giant ShinyHunters has claimed to attack
- 3.5 million — people affected by the December 2025 ransomware attack and data breach against the University of Phoenix attributed to Clop
- 2019 — the year Clop began operating
- 2025 — the year the feud between the two groups began
- 18 September — the date the Clop leak site defacement came to light
The CVE-2025-61882 identifier ties the feud's origin to a specific Oracle E-Business Suite zero-day that both groups used in extortion campaigns.
What the incident says about the criminal economy
For defenders, the Clop defacement is a reminder that the groups targeting their organizations are not a monolith. They compete, they hold grudges, and they sometimes turn on each other using the same techniques they apply to corporate victims.
The claim that authentication logs and IP addresses were taken adds a second layer. If such records exist and are genuine, they could expose the operational security of Clop's members — a category of exposure that ransomware operators typically work hard to avoid, since their own identities are the asset that keeps them out of law enforcement's reach.
The source material does not establish whether ShinyHunters has published any of the material it says it stole, or whether Clop has responded. What is documented is the defacement itself, the claim of stolen keys and server data, and the ransom note.
Organizations that have found themselves in Clop's crosshairs — including through the MOVEit flaws — may see little immediate change in their own risk posture. But the incident does underline that the threat landscape is populated by competing actors whose internal conflicts can produce unexpected disruptions, and whose claims should be treated with the same scrutiny as any other unverified assertion from a criminal group.
For now, the visible outcome is a defaced page and a public threat between two crews. Whether the stolen data amounts to a genuine operational compromise of Clop, or a reputation play aimed at a rival, is not something the available reporting can settle.
Sources
- Infosecurity Magazine Original source
- Bleeping Computer Also reporting
Continue Reading
Rust Developers Hit by Fake Job Call Scam
Rust team members and crate owners are being targeted by attackers who pose as recruiters to hijack credentials and push malicious packages.
Jade Sleet's macOS backdoors hit IT vendor
SentinelOne tied North Korea's Jade Sleet to an India-based IT services breach that deployed two Rust macOS backdoors on a DevOps engineer's MacBook.
CrowdSec Ties Code Theft to TanStack Flaw
CrowdSec says about 300 repositories were hit and links the theft to a May 2026 TanStack supply chain attack.