"THIS SITE HAS BEEN PWN3D BY SHINYHUNTERS" — the line, plastered across Clop's dark web leak site on the evening of 18 September, announced an uncommon intramural strike in the criminal ecosystem of ransomware and extortion.
The defacement and ShinyHunters' claims
The Clop ransomware group's data leak site was altered to display that message and a Pokémon ASCII artwork background, and it included a link to ShinyHunters' own data leak site. According to reporting first published by Bleeping Computer, ShinyHunters claimed to have stolen private keys and server data used to operate Clop's ransomware services. The group said the files included logs and information that could reveal activity tied to Clop's infrastructure.
Ransom, extortion, and an unusual target
ShinyHunters, despite being another criminal extortion gang, treated Clop as it would any corporate victim: the attackers reportedly left a ransom note telling Clop to contact them. When asked by Bleeping Computer what they planned to do with the access, the attacker replied, "going to extort them." The incident therefore involves not only a public shaming and data claim but also a demand for payment inside the criminal economy.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildThe feud rooted in CVE-2025-61882 and Oracle E-Business Suite
Observers trace the confrontation to a rivalry that began in 2025 over competing claims of ownership of vulnerabilities in Oracle E‑Business Suite servers. Both groups apparently used the zero-day identified as CVE-2025-61882 to steal data from organizations in blackmail and extortion campaigns, and that overlap in tooling and opportunity helped fuel a broader dispute between the gangs.
What the stolen server data could expose about Clop operatives
ShinyHunters told Bleeping Computer the files they took could reveal activity, authentication logs and even the IP addresses of Clop members who connected to the service. Those categories of information, if authentic, could be used to identify individual operators or otherwise map elements of Clop's operational infrastructure. The attackers claimed possession of private keys as well as server data — material that would be operationally valuable inside and outside of criminal markets.
What McKesson, the University of Phoenix, and security teams should watch
- McKesson — ShinyHunters has recently claimed an attack on McKesson, the wholesale medical supplies and pharmaceutical distributor that serves more than 40,000 corporate and institutional customers; any further disclosure by ShinyHunters of techniques, tooling or stolen keys could affect how investigations and incident responses are scoped.
- University of Phoenix — Clop was responsible for a December 2025 ransomware attack and data breach that affected nearly 3.5 million people; information purportedly taken from Clop could intersect with evidence in that and other incidents tied to the group.
- Security teams — As Javvad Malik, lead CISO advisor at KnowBe4, told the reporting: "This is a useful reminder that cybercriminal groups are not a single, coordinated ecosystem; they are competitive businesses driven by trust, reputation and money." Malik added that double-crossing and betrayal are credible threats inside criminal networks and that defenders must understand the motivations and behaviors of attackers as well as their technology.
ShinyHunters has been among the most active extortion groups of 2026, claiming campaigns against Salesforce Experience Cloud and Canvas Learning Management System in addition to the alleged McKesson attack. Clop, active since 2019, has a record of disruptive incidents including the 2025 University of Phoenix breach and multiple 2023 attacks exploiting a MOVEit vulnerability.
The episode — a gang-on-gang defacement, claims of private keys and server logs, and an explicit plan to extort a rival — underscores that criminal cyberactivity can produce internal conflict as readily as it does external harm. Whether the stolen materials will be independently verified, used to identify operators, or leveraged for further extortion remains the practical question left on the table; investigators, incident responders and affected organizations will be watching any subsequent disclosures closely.




