CyberSecurity SEE

ShinyHunters Holds Rival Clop for Ransom

ShinyHunters Holds Rival Clop for Ransom

Cybercrime Rivalry: ShinyHunters vs. Cl0p

Authors: Mathew J. Schwartz
Date: September 21, 2026

In a notable turn of events in the realm of cybercrime, two notorious groups—Cl0p and ShinyHunters—have become embroiled in a public rivalry, drawing attention to the competitive and often chaotic nature of cyber extortion. Following a series of conflicting actions, ShinyHunters, known for its audacious tactics, has launched a fierce attack against Cl0p, accusing them of betrayal and demanding a significant ransom for their misdeeds.

The conflict reached a fever pitch on a recent Friday when the data-leak website associated with Cl0p was reportedly defaced. This act of digital sabotage featured a bold proclamation: “Domain Seized By ShinyHunters.” The site was altered to include a list of ShinyHunters’ victims, which now notably included Cl0p itself. This display was coupled with an ominous message directed at Kimberly-Clark, the multinational consumer goods giant, warning them to “make the right decision, don’t be the next headline.” Additionally, ShinyHunters taunted Cl0p with a data leak involving the Florida Department of Motor Vehicles, intensifying the drama surrounding the rivalry.

The tone of the confrontation was brash, reflecting the culture commonly found within ransomware groups. ShinyHunters not only highlighted their upper hand but also issued a staggering ransom demand aimed at Cl0p. The initial ask was labeled as “negotiable,” with a baseline valuation of tens of millions of dollars. ShinyHunters’ communication displayed a mix of bravado and urgency, instructing Cl0p to gather their leadership and act quickly, underscoring the stakes involved. “Clock is ticking moron,” they quipped, while also suggesting that Cl0p secure the services of a translator for effective negotiation.

Cl0p has gained notoriety for its use of ransomware and exploitation of zero-day vulnerabilities to steal and ransom corporate data. The group initially focused on deploying cryptolocking malware but later transitioned to capitalizing on software vulnerabilities in widely utilized applications. Notable victims of Cl0p include various entities using secure file-transfer software like Accellion FTA and GoAnywhere, as well as enterprise resource planning tools such as Oracle E-Business Suite. The group has been linked to an extensive campaign against Oracle users, which peaked last year.

In follow-up communications, ShinyHunters ramped up their demands. They teased Cl0p’s leadership, directing messages specifically to key operators like “Likhogray” and “Tarasov,” issuing a stern ultimatum regarding the finances amassed from the Oracle E-Business Suite campaign. The heat of the exchange emphasized a rapidly escalating competition, as ShinyHunters continued to apply pressure while amplifying their threats.

Since its emergence in 2019, ShinyHunters has built a reputation for brazen tactics that predominantly involve public extortion strategies: they threaten to leak stolen data unless certain conditions are met. The demands typically come with specific deadlines, a method designed to heighten the urgency for potential victims. ShinyHunters has not shied away from using these methods, indicating that the stakes are high for Cl0p, especially since they have yet to respond, adding fuel to ShinyHunters’ relentless pursuit.

Interestingly, the roots of ShinyHunters’ latest aggression seem to stem from Cl0p’s targeting of Oracle E-Business Suite users, a venture that reportedly began in mid-2025 but gained notoriety only in late summer of the same year. Cl0p had previously threatened victims with ransoms reaching up to $50 million for the release of stolen data, underscoring their operational ambition in the cyber extortion landscape.

The competitive landscape in cybercrime has become increasingly intricate, as evidenced by the shifting alliances and rivalries. ShinyHunters’ claims that they have actually pilfered substantial amounts of Cl0p’s proprietary code and data have created a palpable tension. They assert that they are continuing to analyze this information for further leverage in their ongoing campaign against Cl0p.

Information about the operators of Cl0p reveals a layered network of individuals involved in high-level cybercrime. One notable figure mentioned is “j0nny,” believed to be a significant player in Cl0p’s operations on Russian-speaking cybercrime forums. Alongside “j0nny,” individuals like Likhogray Maxim Alexandrovich and Andrei Vladimirovich Tarasov have been implicated, highlighting the diverse backgrounds of those involved in this cybercriminal ecosystem.

As law enforcement agencies continue to combat cybercrime on a global scale, the rivalry between ShinyHunters and Cl0p serves as a fascinating case study. It illustrates not just the evolving tactics of cybercriminals but also the intricate power dynamics that can unfold within the cybercrime domain. The public exposure of their conflicts may further complicate their operations and could potentially draw the attention of regulators and law enforcement who seek to dismantle such enterprises.

In summary, the escalating feud between ShinyHunters and Cl0p is more than a mere squabble among criminals; it exemplifies the shifting landscape of cyber extortion and the lengths to which groups will go to assert dominance in a high-stakes environment. With ongoing developments, this rivalry is sure to capture attention in both the cybersecurity community and beyond.

Source link

Exit mobile version