"Clop and ShinyHunters have occupied two very different but related corners of the extortion ecosystem," Ian Gray, VP of Intelligence at Flashpoint, said — and that distinction is the through-line of a feud now spilling into public defacement, bold demands and technical claims that could reverberate for past victims.
Clop versus ShinyHunters: divergent approaches to extortion
Flashpoint’s assessment sketches two distinct playbooks. Clop is described as exploiting zero-day vulnerabilities in widely deployed enterprise data‑handling platforms and file‑transfer applications — cited examples include Accellion, MOVEit and Cleo, and most recently Oracle E‑Business Suite — to steal data and threaten leak unless paid. By contrast, the most recent iteration of ShinyHunters targets weaknesses in identity verification: voice phishing against IT help desks and abusing session tokens to reach data in software‑as‑a‑service platforms. Clop’s communications, Flashpoint says, have been subdued; ShinyHunters has been boisterous and public about its purported access and grievances.
The Oracle exploit trail: /OA_HTML/configurator/UiServlet and October 2025 posts
On August 10, 2025, the Telegram channel "scattered lapsu$ hunters – The Com HQ SCATTERED SP1D3R HUNTERS," associated with actors tracked as ShinyHunters, advertised a large number of vulnerabilities. The post included an image showing a request to the path /OA_HTML/configurator/UiServlet, targeted by a server‑side request forgery function in an exploit script. On October 3, 2025, the actor shared the post again, claiming it was the same vulnerability Clop used against Oracle. Flashpoint noted that the exploit contains Python scripts that allow an attacker to run arbitrary commands or open a reverse shell on a vulnerable system.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageSeptember 19, 2026 defacement and an escalating ransom
The dispute resurfaced on September 19, 2026, when ShinyHunters defaced Clop’s leak site. ShinyHunters said it gained access through an unauthenticated file upload flaw in Grav, the content management system hosting the site, and framed the action as retaliation for a threat of violence it alleges a Clop representative made during the Oracle campaign. The demand issued by ShinyHunters escalated daily: an eight‑figure payment, and as of September 21 a public apology added on top. ShinyHunters also claims to hold the private keys to Clop’s onion service, nif that holds up, it could stand up a site at Clop’s exact address, leaving past Clop victims facing a second actor with the same leverage over the same data.
What investigators and reporters have been able to verify
BleepingComputer reported that a member of "Scattered LAPSUS$ Hunters" told the outlet the exploit was originally theirs and that they leaked it because Clop had taken it and was using it "in an unsuccessful way." Flashpoint, while noting ShinyHunters "clearly demonstrated access and succeeded in publicly embarrassing a major extortion group," also stated, "we haven’t seen evidence that it obtained the negotiation records, payment data or other material that would give it the leverage it claims. We’ll continue to watch as this feud unfolds."
Those two threads — public boasting and a lack of confirmed evidence for claimed leverage — frame the immediate intelligence picture: visible attacks and technical claims on one hand, and no verified access to negotiation or payment records on the other.
How technologists, affected enterprises, and threat actors are likely to react
- Technologists and security teams: Pierre‑Loïc Kuhn, Cybersecurity Specialist at Filigran, warned, "Organizations must stay on high alert, because when rival groups clash, tactics shift rapidly and the threat landscape evolves faster than ever." Teams will be watching for rapid shifts in exploitation techniques (for example, the move from zero‑days to identity‑verification abuse) and for claims that enable impersonation of extortion infrastructure.
- Affected enterprises and procurement leaders: Jeff Wichman, Senior Director at Semperis, predicted the trend of hacker‑on‑hacker crime will continue, noting that low barriers to entry and low‑skilled actors increase the likelihood of ego‑driven disputes. Organizations that were victims of Clop or similar actors now face the possibility of a second actor exploiting the same data if claims about private keys and site impersonation prove true.
- Adversaries and threat actors: The public feud underscores that criminal groups themselves are vulnerable to the same lapses they exploit in others — and that intra‑gang disputes can produce new, unpredictable tactics. Wichman observed that "threat actors often fall victim to the same phishing emails and scams they use against their innocent victims" and that personal disputes will likely produce more hacker‑on‑hacker incidents in coming months.
The ShinyHunters–Clop feud is more than a smear campaign: it demonstrates how rivalries among extortion groups can surface technical claims (private keys, exploit code, unauthenticated file uploads) that, if true, create fresh risks for organizations already harmed. Flashpoint’s warning — that it has seen no evidence ShinyHunters obtained negotiation or payment records — remains a critical hinge in the story. The next concrete things to watch are proof of the private‑key claim and any verifiable disclosure of negotiation/payment data; until then, the public face‑off is an escalation in theater and technique that security teams should track closely.
Source: Why Security Needs to Stay Alert in the ShinyHunters, Clop Feud — Security Magazine




