The notorious hacking and extortion group known as ShinyHunters has recently made headlines by claiming responsibility for a cyberattack against the Clop ransomware group, another prominent player in the cybercrime arena. This aggressive maneuver raises intriguing questions about rivalries among criminal organizations that thrive on digital chaos.
The attack, which was revealed on the evening of September 18, involved the defacement of Clop’s dark web data leak site. Prominently displayed on the modified page was a bold message reading, “THIS SITE HAS BEEN PWN3D BY SHINYHUNTERS.” In an artistic twist, the background was altered to feature ASCII artwork of a well-known Pokémon, a nod that highlights the often playful yet malicious nature of cybercriminal culture.
ShinyHunters claimed that during the breach, they managed to extract private keys and server data crucial to Clop’s ransomware operations. More than just a show of digital bravado, the message left on Clop’s site also included a link directing visitors to ShinyHunters’ own data leak site, showcasing their audacious intent to further publicize their achievements.
The attack’s details were first reported by Bleeping Computer, a publication specializing in cybersecurity news. In discussions with the outlet, ShinyHunters asserted they had obtained files that could expose significant vulnerabilities in Clop’s operations. These files reportedly contained authentication logs and could even unmask the IP addresses of Clop members who had connected to their compromised service. This level of information could potentially enable law enforcement and security analysts to identify individuals associated with the Clop ransomware gang, a move that could lead to arrests and dismantling of their operations.
Despite being a fellow criminal hacking entity, ShinyHunters is treating Clop as just another victim, issuing a ransom note urging the Clop members to make contact. When questioned about their intentions with the access gained, ShinyHunters bluntly stated their aim was straightforward: “going to extort them.”
### A Growing Feud Between Rivals
This incident marks a significant chapter in what appears to be an escalating feud between ShinyHunters and Clop. The rivalry dates back to 2025, rooted in conflicts over claims to vulnerabilities in Oracle E-Business Suite servers. This dispute included the usage of a zero-day exploit, designated as CVE-2025-61882, which both gangs had employed in their blackmail and extortion campaigns. Such episodes serve as a reminder that cybercriminal groups operate akin to competitive businesses, driven by a desire for monetary gain and established reputations.
Javvad Malik, a leading CISO advisor at KnowBe4, highlighted the implications of such rivalries, stating, “This is a useful reminder that cybercriminal groups are not a single, coordinated ecosystem; they are competitive businesses driven by trust, reputation, and money.” He emphasized that in a world built on deception and fear, betrayal is a constant threat. For cybersecurity defenders, understanding the motivations and behaviors surrounding these attacks is as important as grasping the technology involved.
ShinyHunters has gained notoriety as one of the most active cyber extortion groups of 2026, launching considerable attacks against notable software-as-a-service providers. Their campaigns have recently included targeting Salesforce Experience Cloud and the Canvas Learning Management System. Furthermore, they have also claimed responsibility for an attack on McKesson, a major U.S. healthcare entity distributing medical supplies and pharmaceuticals to over 40,000 institutional customers.
Conversely, the Clop ransomware group has been operational since 2019, known for executing disruptive cyber-attacks across various sectors. Their history includes a significant ransomware attack and data breach involving the University of Phoenix, which affected nearly 3.5 million individuals in December 2025. Clop has also conducted several high-profile ransomware attacks in 2023, exploiting a security vulnerability in the MOVEit Transfer and MOVEit Cloud services, leading to widespread data breaches.
As these rival gangs continue to clash in the cyber underworld, the implications extend beyond criminal enterprises; they also underscore the ever-evolving landscape of cybersecurity challenges faced by organizations across the globe. Understanding the dynamics of these feuds not only informs cybersecurity professionals but also offers a glimpse into the complexities of digital crime and the intricate relationships that form within this shadowy realm.
