ShinyHunters vs Cl0p: The Cybercrime Feud Explained - The Story So Far

ShinyHunters has turned its feud with Cl0p into a public extortion demand. The site takeover is documented; claims about stolen payment records remain unverified. Previous victims have reason to keep watching.

Share
ShinyHunters vs Cl0p: The Cybercrime Feud Explained - The Story So Far

Cl0p's leak site is usually a place where other organisations are put under pressure. This time, the demand was aimed at Cl0p itself.

ShinyHunters says it compromised its rival's dark web infrastructure and is demanding payment, while threatening to publish information about companies that allegedly paid Cl0p. The visible takeover is supported by independent reporting. The claims about stolen internal records and wider access are not.

There has already been another turn. On 21 September, Hackread reported a message apparently from Cl0p asking ShinyHunters to get in touch. That suggests somebody could publish a response through the site. It does not establish that Cl0p has recovered exclusive control, or that ShinyHunters has lost access.

For organisations previously caught in either group's campaigns, that distinction matters more than the insults. A criminal dispute can create another reason to publish information that a victim thought had stopped circulating. It is a possibility to prepare for, not a fresh breach to announce without evidence.

A website is not the whole operation

Reuters reported that ShinyHunters claimed to have broken into Cl0p's site on Friday, 18 September, after finding a vulnerability in its software. The group described much broader control over its rival's infrastructure. Cl0p did not respond to Reuters' requests for comment before that report appeared.

There is evidence of the website intrusion beyond the attacker's account. BleepingComputer confirmed an uploaded file on Cl0p's server and then observed the site displaying ASCII artwork of Umbreon, the mascot associated with ShinyHunters. It did not independently verify the group's claims to have taken source code, server logs or the private keys for Cl0p's onion service.

A defacement screenshot with ASCII artwork and ShinyHunters lettering. It shows a changed page, not wider infrastructure access.

Those are different levels of access. Changing a page proves an ability to change what visitors see. It does not, on its own, prove access to a payment history, a victim archive or every system behind the operation. Nor does an outage establish who caused it.

The same caution applies to the apparent reply. Hackread saw a request for contact on 21 September after the ShinyHunters material disappeared. Its reporting explicitly leaves control of the underlying infrastructure unresolved. A familiar address and a new message are not a complete account of who is running the service.

The bill points back to Oracle

The demands have moved beyond a defacement. A message dated 19 September demanded what ShinyHunters described as an eight-figure payment. The following update sought money it alleged Cl0p had earned from its Oracle E-Business Suite campaign, plus additional payment and interest. By 21 September, the group was demanding a public apology and threatening to increase its demand for every 24 hours without engagement, according to Hackread's reporting.

ShinyHunters told Reuters that the dispute began with an Oracle EBS zero-day it says it discovered first and Cl0p subsequently obtained. It also alleged that Cl0p had threatened to expose members' identities. Reuters could not establish the accuracy of that account.

The history of the exploit and the history of this feud should therefore stay separate. Cl0p's Oracle campaign is not proof that ShinyHunters owned the exploit, and an extortion message is not evidence of a debt. What the messages show is the story ShinyHunters is using to justify its demand.

There is no independently established exact ransom amount in the material reviewed for this article. An eight-figure boast is not a figure to turn into a precise headline by reverse-engineering the speaker's claimed wealth.

A captured extortion message addressed to Cl0p. It demands payment but does not establish access to internal records.

Previous victims enter the argument

The threat with the clearest relevance outside the feud is the proposed disclosure of alleged payment records. ShinyHunters says it could name companies that paid Cl0p, identify the amounts and publish the Bitcoin addresses involved. Hackread has not independently verified that it possesses those records.

If genuine records were released, previous victims could face renewed scrutiny or further approaches from extortionists. That is ZDW's assessment of the possible consequence, not evidence that those records have changed hands or that another payment demand has reached any particular company.

It also changes how a leak-site entry should be interpreted. If a rival can publish through the site, its contents cannot simply be assigned to the group normally associated with the address. Analysts need to distinguish the service being used, the claimed publisher and the provenance of the material. Otherwise an infrastructure dispute becomes an attribution error in somebody else's intelligence report.

The useful response is to preserve the dated claims and compare any later assertions with an existing incident record. A missing listing, a restored page or a quiet negotiation channel should not be treated as proof that stolen information was deleted.

A separate claim about Kimberly-Clark

A screenshot supplied to ZDW places a Kimberly-Clark listing beside the message to Cl0p. It alleges compromise of a Snowflake instance and displays a claimed compressed data volume of 257GB+. Neither the platform claim nor the volume has been verified by ZDW. A download button does not authenticate the contents behind it, and ZDW has not accessed them.

The image also displays an update date of 22 September 2026 on the Kimberly-Clark card. That is later than this article's review date of 21 September. The discrepancy remains unexplained and prevents using that label as a confirmed publication date.

The listing is worth separating from the feud precisely because they appear together. Sharing a page does not establish a shared intrusion, a link to Oracle EBS or a confirmed release of Kimberly-Clark data. The screenshot records an allegation. It cannot settle it.

Two captured leak-site cards, stacked for readability. The Kimberly-Clark card displays a date later than this review.

The victims remain exposed

There is an obvious temptation to enjoy watching an extortion group receive its own treatment. For a response team, the more useful question is whether information from an earlier incident could now be used by somebody else.

Keep that possibility in the case assessment without promoting it to a confirmed event. Preserve public claim metadata through approved intelligence channels, brief the existing incident-response contacts where there is a relevant prior exposure, and verify any new approach against known case details. Do not download a claimed victim archive just to see whether the gang is telling the truth.

Nothing in the reporting establishes that Cl0p's victims have recovered their data, that copies have been destroyed or that its extortion activity has ended. The website changed. The obligations to the people whose information was taken did not.

A captured follow-up message addressed to Cl0p. Its countdown increases pressure without verifying the underlying claims.

Update - 22 September 2026: ShinyHunters changes the payment terms

The argument has moved from a demand for contact to a dispute over where that contact should happen. New screenshots supplied to ZDW show a response attributed to ShinyHunters, with an update label dated 22 September. The earlier message attributed to Cl0p said ShinyHunters' email was not working and asked it to return to an old platform. Hackread had already reported that contact request on 21 September.

ShinyHunters says it no longer has access to that platform and insists that Cl0p make contact on its terms. It also alleges that Cl0p threatened to hand it over to police. The screenshots do not independently establish that threat or identify the platform.

The more consequential change is in the payment terms. Claiming another 24 hours have passed, ShinyHunters now demands Bitcoin that is "traceable, linked to your previous activity" and says it wants the world to see Cl0p pay. Read alongside the message's boasts, that appears intended to make payment a public humiliation as well as a transfer of money. It is a demand, not evidence of a transaction.

Captured messages attributed to Cl0p and ShinyHunters. A contact dispute develops into a demand for publicly traceable payment.

The same message brings Qilin into the taunting exchange and suggests asking it for a loan. That is not evidence of a financial arrangement or an operational relationship between the groups.

None of the supplied images shows a payment address, a completed transfer or a settlement. Nor do they resolve who controls Cl0p's infrastructure or whether the claimed internal records are genuine. For previous victims, the distinction remains the same: preserve new claims, but do not treat a criminal's boast as confirmation that another disclosure has happened.