The ShinyHunters extortion group hacked the notorious Cl0p ransomware group’s leak site this week, demanding a significant ransom and threatening to leak information about the latters’ ransomware proceeds.
ShinyHunters made the hacking public on September 20, defacing Cl0p’s dark web leak site with a message demanding a large ransom figure. The message, addressed to leading members of the Cl0p group, demanded the latter to transfer all the proceeds of the money they extracted from victims of the Oracle E-Business Suite zero-day hack.
“I want all the money you made off the EBS campaign plus more AND WITH INTEREST. before I start releasing information regarding the companies that paid you, how much, and to what Bitcoin address. My phone book contains all major financial media outlets. CLOCK IS TICKING! LETS GET THE BALL ROLLING!,” the message read.
ShinyHunters added that the amount it demanded from Cl0p represented 2.333% of its net worth, but did not state the exact amount of the ransom figure.
“I hope you can pay that much because that is the demand, negotiable. Get your bosses in front of the white board in the war room. Clock is ticking moron. Kindly excuse our unprofessionalism,” the group added.
ShinyHunters posted on Cl0p’s dark web leak site on September 21 that any delay in responding to its ransom demand would make the demand go higher. The group also demanded a public apology from Cl0p for failing to respond to its demand in time.
After Cl0p ransomware operators expressed their inability to contact ShinyHunters on its email address, the latter posted angry messages on the leak site, stating that threats like reporting it to the police won’t work.
👀 Cinema.
Cl0p responded to ShinyHunters and Shiny responded back. Lul
“RESPONSE: Its spelt *ShinyHunters, with no space, moron. I told you to bring an English interlocutor. You’re a rat. You attempted to intimidate me by saying you’ll hand me over to the police. You contact… pic.twitter.com/sqOViiqqIY
— Dark Web Informer (@DarkWebInformer) September 21, 2026
“Another 24 hours passed. The new demands now include: Make sure to have MY money in Bitcoins, traceable, linked to your previous activity, ready so the whole world can see that I walk all over you and your other Russian buddies,” the group said.
It appears that ShinyHunters has detailed knowledge of how much money the Cl0p ransomware group extracted from victims after carrying out zero-day attacks targeting Oracle’s E-Business Suite application. The group reportedly victimised more than a hundred organisations worldwide, including Harvard University, the University of Phoenix, The Washington Post, Schneider Electric, Broadcom, Estee Lauder companies, Cox Enterprises, Abbott, and Humana.
