ShinyHunters defaces Clop leak site, threatens to name ransom payers
The ShinyHunters group has hijacked Clop's dark web leak site and threatened to publish records of which organisations paid ransoms during the Oracle E-Business Suite campaign.
Ada
Writer

The ShinyHunters extortion group has defaced the dark web data leak site operated by the Clop ransomware gang and is attempting to extort Clop itself, threatening to publish records identifying organisations that paid ransoms during Clop's Oracle E-Business Suite campaign.
The compromise was first reported by BleepingComputer on 19 September and has since been covered by Dark Reading and The Record. Several of the claims made by ShinyHunters about what it took remain unverified.
How the site was compromised
ShinyHunters told BleepingComputer the attack began on the Friday night, using what it described as an unauthenticated file upload flaw in Grav CMS, the content management system behind Clop's leak site. The group uploaded a small text file carrying a taunting message and a link to its own leak site. BleepingComputer confirmed the file had been uploaded to Clop's server and could be downloaded from the Tor site.
Several hours later the wider defacement appeared, replacing the page with ASCII artwork of the Pokémon character ShinyHunters uses as a logo. A researcher told BleepingComputer the same artwork was used in a 2020 defacement of HackForums that ShinyHunters also claimed at the time. Dark Reading reported the page carried a banner declaring the domain seized.
ShinyHunters claims it obtained full access to the server and took source code, Grav CMS plugins, system logs and the contents of the system log directory, which could include authentication records and the IP addresses of anyone who connected. It also claims to hold the private keys for Clop's Tor onion service, which would let it run a site at the same onion address on infrastructure it controls.
BleepingComputer independently confirmed the defacement and the uploaded file, but did not verify the claims about stolen logs, source code or onion keys.
Demands escalate over several days
After the initial report, ShinyHunters added Clop to its own leak site and began posting daily updates. It opened with an unspecified eight-figure demand and said the figure would rise every 24 hours Clop failed to respond. By the Monday the demands had expanded to include a public apology.
The threat that matters beyond the two groups came next. ShinyHunters said it would release information about companies that allegedly paid Clop during the Oracle E-Business Suite campaign, including the amounts paid and the associated Bitcoin addresses.
On 21 September a short message appeared on Clop's own hijacked site, apparently from Clop, saying ShinyHunters' email address was not working and asking the group to make contact another way. ShinyHunters rejected the request and repeated its demand.
The origin of the feud
The dispute traces back to October 2025, when Clop exploited several flaws in Oracle E-Business Suite servers, including the zero-day tracked as CVE-2025-61882, to steal data for extortion. Around the same time, actors operating as Scattered Lapsus$ Hunters, including ShinyHunters, published a proof-of-concept exploit that Oracle later confirmed matched the one used in the Clop attacks.
ShinyHunters has said the exploit was originally its own and that Clop used it without permission. It told BleepingComputer that a Clop representative later sent threatening messages, including a threat to its life, and that the defacement was retaliation. BleepingComputer said it had not verified those allegations and had contacted Clop for comment.
The Oracle E-Business Suite attacks prompted warnings from Oracle, the FBI and cyber security agencies in the United Kingdom and Singapore, according to The Record.
What it means for organisations caught in between
There is no evidence at this stage that ShinyHunters holds any data about Clop's victims. Dark Reading noted that the group has not produced proof, and its threat to publish payment records is so far only a threat.
The episode nonetheless illustrates a problem that applies to every organisation that has had data taken. Jon Baker of AttackIQ told Dark Reading that "stolen information doesn't retire", noting that copies sit across the original group's servers, its affiliates and its infrastructure providers, and each copy is a further opportunity for theft or exposure. Darren Guccione of Keeper Security made a related point to the same publication: a payment for deletion depends on the word of a party whose business is deception, with no way to verify destruction and no recourse if the promise is broken.
Feuds between criminal groups are not new. Pieter Arntz of Malwarebytes wrote in a blog post cited by Dark Reading that while the groups are occupied with each other they have less time to attack legitimate businesses.
Whether ShinyHunters actually obtained anything relating to Clop's victims remains unknown.