The prolific hacking collective ShinyHunters has launched an attack on rival cyber criminals Clop amid a long-running feud between the gangs.
ShinyHunters hijacked the dark web data leak site of the Clop ransomware group last Friday, leaving behind the message: “THIS SITE HAS BEEN PWN3D BY SHINYHUNTERS… Maybe don’t try to threaten us next time.”
The ShinyHunter group, which has previously carried out major attacks on Google, Microsoft and Ticketmaster, claimed to have also stolen private data from Clop’s ransomware operations.
The hackers demanded an eight-figure payment to prevent the publication of the stolen information, which reportedly included access to Clop’s server and source codes.
“We are still downloading and reviewing [the data],” ShinyHunters told BleepingComputer, who first reported the incident.
ShinyHunters said the ongoing feud between the two groups dates back to a data theft campaign last year.
The attack saw Clop exploit vulnerabilities in Oracle E-Business Suite servers, allowing them to steal data from companies.
ShinyHunters claim the exploit used in the attacks belonged to them and had been used by Clop to carry out a lucrative ransomware campaign without permission.

The ideal summer spot? Away from scams.
Get All-in-One Protection for Your Digital Life
LEARN MORE
ADVERTISEMENT

The ideal summer spot? Away from scams.
Get All-in-One Protection for Your Digital Life
LEARN MORE
ADVERTISEMENT
A ransomware attack is where hackers seize control of a company or person’s data, lock them out, and demand payment to restore access.
“ShinyHunters appears to be seeking revenge for the Oracle EBS campaign, in which Clop claimed around 120 victims,” Rebecca Moody, head of data research at Comparitech, told The Independent.
“To date, the companies involved – 35 have confirmed the claims so far – have issued data breach notifications to nearly 4 million people. That’s a lot of data. So, if the exploit was rightly ShinyHunters, this goes some way to explaining why it’s out for revenge.
“What is of concern is another hacking group potentially having access to another group’s victims. This doubles the chances of data being leaked.”
Ms Moody noted that this has happened before when Change Healthcare was hacked in February 2024, compromising sensitive information for over 100 million US citizens.
Hackers known as ALPHV/BlackCat claimed the attack and received a $22 million ransom to delete the stolen data, however another group called RansomHub also claimed to be in possession of the data.
The House Committee on Energy and Commerce later estimated that a third of Americans had their sensitive health information leaked to the dark web as a result of the attack.
