Skip to main content
Emerging ThreatsMalware & Ransomware

Rivals Hijack Clop's Leak Site, Demand Eight-Figure Payout

Dark-web setting with defaced webpage and seized domain banner on screen.

"We basically own them now," ShinyHunters told Reuters after the rival crew posted a large "DOMAIN SEIZED BY SHINYHUNTERS" banner and the tagline "rooting your systems since '19 ;)" on Clop's dark-web leak site.

ShinyHunters' claimed seizure and how it surfaced

The takeover surfaced over the weekend when Clop's leak site was defaced and repurposed to host demands. ShinyHunters told Reuters it broke into the site on Friday by exploiting a vulnerability in the software powering the site, and the crew claimed that exploit gave it extensive access to Clop's infrastructure. The Register also viewed the defaced site and reported that ShinyHunters was actively posting demands and updates there. Clop has not responded publicly; two security researchers speaking to Reuters said the clash appeared genuine.

The demands: an eight-figure payout, publication threats, and a public apology

ShinyHunters has used the hijacked page to press a financial and reputational claim. On September 19 it demanded an eight-figure payment, saying the sum represented "2.333 percent of its own net worth." A later update escalated the terms to "all the money you made off the EBS campaign plus more AND WITH INTEREST." The crew further threatened to identify companies that allegedly paid Clop, and to publish the sums and Bitcoin addresses involved. On September 21 ShinyHunters warned its demands would increase every 24 hours until Clop responded and added that it wanted a public apology.

The backstory: a feud tied to Oracle E‑Business Suite activity

ShinyHunters framed the confrontation as a settling of scores tied to last year's attacks on Oracle E‑Business Suite (EBS) customers. The crew claims it discovered the relevant zero‑day first, only for Clop to obtain the exploit and use it against corporate networks; ShinyHunters says it now wants a share of the proceeds from those operations. Those assertions come from ShinyHunters' own posts and statements; the Register and Reuters relayed the claims, but the record of payment or exploit provenance remains unverified in public reporting.

Why the hijack matters to Clop's operations and reputation

Leak sites are designed to serve two purposes for extortion groups: demonstrate possession of stolen materials, and signal operational control. Having a leak site seized and used against the extortionist undermines both functions. The Register observed ShinyHunters turning Clop's platform into the vehicle for its demands, a visible affront to Clop’s presumptive operational security and credibility. Beyond the immediate embarrassment, ShinyHunters' claimed broader access raises the possibility that internal records — including evidence of prior ransom negotiations or payments — could be exposed, though those claims remain unverified.

What this means for technologists, affected enterprises, and regulators

  • Technologists and security teams: will watch claims of a software vulnerability in Clop's leak-site platform and the assertion of "extensive access" for indicators that could validate or refute the intrusion, while also noting the public escalation cadence ShinyHunters says it will follow (increasing demands every 24 hours).
  • Affected enterprises and procurement leaders: may be attentive to ShinyHunters' threat to publish identities, sums and Bitcoin addresses if they believed paying Clop kept negotiations private — a potential reputational and contractual exposure if those records exist and are released.
  • Regulators and incident responders: could find the episode relevant because it touches on disclosure, third‑party extortion practices, and the question of how payment-related records are treated if an extortion actor itself is compromised and those records are published; for now, the key facts about payments and published evidence remain claims rather than verified disclosures.

Clop is described in reporting as one of the most prolific data extortion groups, with a history of exploiting enterprise‑software flaws to steal data and extract payments — most notably during the 2023 MOVEit campaign, which affected thousands of organizations and exposed information belonging to tens of millions of people. ShinyHunters, too, has an extensive rap sheet and has been linked to numerous large‑scale data theft and extortion campaigns. In this rare role reversal, one extortion group is publicly extorting another; whether the episode yields verifiable disclosures of ransom payments or infrastructure access remains the pivotal open question.

The visible taunting and escalating timetable set by ShinyHunters make two things clear: the dispute is public, and the terms are simple and binary — respond or pay, or face an escalating price and the threat of published names and transaction details. Whether Clop will reply, meet the demand, or counter by reclaiming its site is not yet known. The short record established so far is one of a cyber‑criminal rivalry played out on the same dark-web stage the gangs use against others.

Original reporting: The Register — Clop gets a taste of its own medicine after ShinyHunters hijack leak site