ShinyHunters Turns the Tables on Cl0p in Rare Cybercrime Extortion Feud
In an unusual confrontation between two major cybercrime operations, the ShinyHunters extortion group has claimed responsibility for taking control of the dark web leak site operated by the prolific Cl0p ransomware and extortion gang.
The incident effectively turned Cl0p’s own extortion infrastructure against it.
Cl0p’s leak site, historically used to publish the names and data of organisations that refused to pay extortion demands, was reportedly defaced over the weekend with a message stating “Domain Seized By ShinyHunters.” The site subsequently became inaccessible. Reuters reported that cybersecurity researchers considered the confrontation genuine, although Cl0p has not publicly confirmed the incident.
ShinyHunters Demands Payment From Cl0p

After gaining control of the site, ShinyHunters reportedly posted messages demanding an eight-figure payment from Cl0p.
The group described the initial demand as 2.333% of its claimed net worth, implying that ShinyHunters believes Cl0p holds assets worth hundreds of millions of dollars.
The demands were subsequently escalated. ShinyHunters threatened to increase its demands every 24 hours that Cl0p failed to respond and later added a requirement for a public apology.
The group also threatened to release information it claims to have obtained from Cl0p, including:
- Companies that allegedly paid Cl0p extortion demands
- The amounts allegedly paid
- Bitcoin addresses allegedly associated with the payments
- Information relating to Cl0p’s internal operations
These claims have not all been independently verified and should therefore be treated as allegations by ShinyHunters rather than established facts.
The irony is notable: a site designed by Cl0p to pressure organisations into paying extortion demands was itself allegedly converted into an extortion platform targeting its operators.
The Oracle E-Business Suite Connection
The origins of the dispute reportedly go back to Cl0p’s exploitation of an Oracle E-Business Suite vulnerability in 2025.
Cl0p was associated with attacks exploiting CVE-2025-61882, a critical Oracle E-Business Suite vulnerability that enabled unauthenticated remote code execution. Exploitation was observed in August 2025, with Cl0p subsequently linked to a large-scale data theft campaign.
ShinyHunters has claimed that the exploit was originally obtained by its side of the cybercrime ecosystem and that Cl0p subsequently obtained and used it without authorisation.
The history surrounding the exploit is complicated. ShinyHunters and associated actors publicly released an exploit for the Oracle vulnerability, while Oracle’s indicators of compromise subsequently identified the same exploit archive. BleepingComputer reported that the exploit released by the group matched the exploit used in the Cl0p attacks.
There have also been reports that the exploit was offered for sale in underground forums, including claims of a price around US$70,000. However, the precise chain of custody for the exploit and how it came into Cl0p’s possession remains disputed.
What is considerably less disputed is the impact of the campaign. Cl0p used the Oracle EBS vulnerability in a large-scale data theft and extortion operation targeting numerous organisations.
ShinyHunters now appears to be seeking compensation from Cl0p for what it claims was the unauthorised use of the exploit, as well as threatening to expose details of the resulting extortion operation.
From Rivals to Victims
The incident highlights an unusual feature of the cybercrime ecosystem: criminal groups are not necessarily operating in isolation.
Access brokers, exploit developers, ransomware operators, data extortion groups and initial-access actors can have overlapping relationships, with vulnerabilities, malware, credentials and stolen information sometimes being traded or shared between groups.
The Oracle EBS dispute demonstrates how competition
over an exploit can potentially develop into a much broader conflict.
In this case, the dispute has reportedly progressed from accusations over exploit ownership to one group gaining access to another group’s infrastructure and threatening to expose its financial operations.
Reuters described the confrontation as an unusually direct public clash between major cybercrime groups.
ShinyHunters Activity
ShinyHunters is primarily associated with large-scale data theft and extortion rather than traditional ransomware deployment.
The group has been involved in several significant campaigns during 2026, including attacks affecting the education sector and major organisations. Recent reporting has linked ShinyHunters to victims and campaigns involving organisations such as McKesson, ReliaQuest, Logitech, Ralph Lauren, Vimeo, 7-Eleven and Udemy.
The group has also been associated with the compromise of education technology provider Instructure, with ShinyHunters claiming to have stolen large volumes of information affecting thousands of educational organisations.
Australasia has so far appeared to receive considerably less attention from ShinyHunters than some other regions, although Australian organisations have been targeted or named in activity associated with Cl0p.
Cl0p’s Australian Victims in 2026
Cl0p has continued to name Australian organisations on its leak infrastructure during 2026. The following organisations were listed as Australian victims in the supplied victim data:
| Company | Domain | Date | Industry | Country |
|---|---|---|---|---|
| Midland (Australia) | midlandind.com.au | 13 Aug 2026 | Automotive and Industrial Parts | AU |
| Omni Tanker | omnitanker.com | 12 Aug 2026 | Chemicals / Transportation | AU |
| Whole IT | wholeit.com.au | 30 Jan 2026 | Information Technology | AU |
| NextPhaze | nextphaze.com.au | 28 Jan 2026 | Cybersecurity / Information Technology | AU |
| ETTO Australia | ettoaustralia.com | 28 Jan 2026 | Retail / Cosmetics | AU |
| Hale Road Tavern | thehaleroad.com.au | 28 Jan 2026 | Food and Beverage | AU |
| MRA Group | mragroup.com.au | 28 Jan 2026 | Oil and Gas Equipment and Services | AU |
| Podiatry Western Australia | podiatrywa.com.au | 28 Jan 2026 | Professional Services | AU |
| RMW Hospitality Group | rmwgroup.com.au | 28 Jan 2026 | Hospitality | AU |
| Ventnor | ventnor.com.au | 28 Jan 2026 | Capital Markets / Finance | AU |
| Y Architecture Studio | y-architecture.studio | 28 Jan 2026 | Architecture | AU |
| Skye Excavations | skyeexcavations.com.au | 28 Jan 2026 | Construction | AU |
| Roberts Designs | robertsdesigns.com.au | 27 Jan 2026 | Industrial Distribution | AU |
The presence of an organisation on a ransomware or extortion leak site should not, by itself, be interpreted as confirmation that the organisation paid a ransom or that every claim made by the threat actor is accurate.
Cl0p’s Track Record
Cl0p has become particularly associated with exploiting vulnerabilities in widely deployed enterprise file-transfer and business applications.
Previous campaigns involving MOVEit, GoAnywhere and Accellion resulted in large numbers of organisations being targeted and substantial quantities of data being stolen.
More recently, Cl0p has continued its strategy of exploiting vulnerabilities in enterprise software rather than relying solely on conventional ransomware deployment. Its victims have included major organisations such as Shell, GE, Harley-Davidson and Zebra Technologies.
This makes the alleged ShinyHunters compromise particularly notable.
Rather than attacking a conventional corporate target, ShinyHunters appears to have targeted the infrastructure behind another highly capable cybercrime operation.
Criminal-on-Criminal Extortion
The incident demonstrates that cybercriminal groups themselves can become targets of the same tactics they use against businesses.
Cl0p’s leak site was built around public exposure and financial pressure. ShinyHunters has now allegedly used that same platform to publicly pressure Cl0p.
Whether ShinyHunters ultimately releases the information it claims to possess remains to be seen. The most significant potential disclosure would be evidence of Cl0p’s extortion revenues, including alleged payment amounts and cryptocurrency addresses.
For defenders, however, the incident provides another reminder that cybercrime infrastructure is itself vulnerable. The same weaknesses exploited against legitimate organisations can potentially be used against threat actors when their infrastructure is exposed.
More information is expected as the ShinyHunters–Cl0p dispute develops.
