Why Ransomware Gangs Are Launching Cyber Attacks on Each Other | #ransomware | #cybercrime


The cybercrime ecosystem has always been competitive, but recent events suggest that competition between ransomware and data-extortion groups is taking a more aggressive turn.

A striking example emerged in September third week of 2026, when the ShinyHunters cybercrime group claimed to have breached the infrastructure of rival ransomware group Clop and taken control of its dark-web leak site. The incident turned the tables on a criminal organization that normally uses extortion as a weapon against its victims. 

A cybercrime feud has erupted between two notorious hacking groups, ShinyHunters and Clop, following ShinyHunters’ claim that it hijacked Clop’s dark web site.

ShinyHunters, known for large-scale data thefts, said it exploited a vulnerability in cl0p’s infrastructure to seize control. Clop’s website displayed a message stating “Domain Seized by ShinyHunters” before becoming inaccessible. Cybersecurity experts confirmed the authenticity of the conflict, noting its rare public nature. The feud reportedly stems from a dispute over a stolen “zero-day” exploit in Oracle’s E-Business Suite. 

ShinyHunters claims Clop misappropriated the exploit, which cl0p allegedly used to hack data from over 100 companies. In retaliation, threats of exposing rival members and operational secrets escalated the conflict. Both groups have been involved in significant cyberattacks: Clop’s recent breaches include data theft from Shell, GE, and others, while ShinyHunters targeted Rockstar Games and U.S. Educational platforms. The unfolding feud marks an unusual and public confrontation between major cybercrime syndicates.

This raises an important question: why are cybercriminal groups launching attacks against one another?

Competition for Money and Resources

At its core, ransomware is a business driven by money. Cybercriminal groups compete for valuable vulnerabilities, stolen data, affiliates, victims, and access to compromised networks. When one group believes another has taken an exploit, victim, or other valuable resource, conflict can emerge.

In the ShinyHunters–Clop dispute, ShinyHunters alleged that Clop had improperly obtained and used a zero-day vulnerability associated with Oracle’s E-Business Suite. ShinyHunters subsequently claimed responsibility for compromising Clop’s leak site and demanded payment from its rival. These claims cannot all be independently verified, but cybersecurity researchers cited by Reuters said the confrontation appeared genuine. 

Trust is in short Supply

Unlike legitimate businesses, ransomware groups cannot rely on courts, contracts, or regulators to resolve disputes. Their operations exist outside the law, meaning disagreements have to be settled through reputation, threats, or technical retaliation.

This creates an unusual situation in the cybercrime ecosystem: criminals have to cooperate with people they cannot necessarily trust. Affiliates may move between ransomware groups, stolen vulnerabilities can change hands, and sensitive information about criminal operations can become a bargaining chip.

An attack against another cybercriminal group can therefore serve multiple purposes. It can provide access to valuable intelligence, disrupt a competitor, expose operational weaknesses, or simply demonstrate technical superiority.

The Dark Web becomes a Battleground

The ShinyHunters–Clop incident also demonstrates how reputation matters in cybercrime. Clop’s leak site was part of its extortion infrastructure, used to pressure victims by threatening to publish stolen information. Having that site taken over by a rival effectively turned Clop’s own extortion mechanism against it. 

There is potentially an even greater consequence for victims. If stolen information from a ransomware group’s infrastructure is obtained by another criminal group, data concerning negotiations, payments, or victims could potentially be exposed or used for further extortion. That means organizations previously targeted by one cybercrime group may face additional risks when criminal groups fight among themselves.

Where could this Cannibalistic Cycle Lead?

The growing professionalization of cybercrime means ransomware groups increasingly operate like competing businesses, complete with specialized skills, partnerships, infrastructure, and financial incentives. As the ecosystem becomes more crowded, attacks between groups could become another method of eliminating competitors or acquiring valuable assets.

However, this internal conflict does not necessarily mean ransomware itself will disappear. Cybercrime groups have repeatedly demonstrated their ability to reorganize, rebrand, and form new partnerships when disrupted. 

Ransomware hackers are increasingly rebranding to elude enhanced cybersecurity defenses and law enforcement. This tactic, while not new, has become more frequent due to AI and automated tools making it easier to trace known hacker patterns. Rebranded groups adopt new names, infrastructure, payment systems, and communication methods to avoid detection. Experts cite a rise in ransomware attacks globally—from 1,186 in 2024 to 1,885 in the last three months—underscoring the threat’s growth.

Groups like GodDamn Ransomware, Helix, and others have shown continuity with earlier groups (e.g., Beast, Monster, BlackFile), suggesting rebranding rather than new actors. Cybercriminals use similar tactics, often disabling security systems and using deepfakes and social engineering to infiltrate networks. Rebranding is also a marketing tactic in dark web markets to attract buyers. Enforcement can backfire, with targeted groups like Evil Corp simply changing names to avoid sanctions. Analysts emphasize the need for organizations to stay flexible and adaptive, as the cybercrime ecosystem doesn’t shrink—it evolves.”

The ShinyHunters–Clop confrontation therefore offers a revealing glimpse into the darker side of the ransomware economy. When criminals become both attackers and targets, the boundaries of cyber warfare become increasingly blurred. For defenders, the episode is another reminder that compromised criminal infrastructure can contain valuable intelligence—but may also create new risks for the organizations caught in the middle.

Join our LinkedIn group Information Security Community!



Click Here For The Original Source.

——————————————————–

..........

.

.