A public feud between two major cyber-extortion brands has turned one of ransomware’s best-known pressure tools into the target.
BleepingComputer reported that ShinyHunters breached Cl0p’s data leak site over the weekend, replacing content on the Tor service with a defacement page and a message aimed at the ransomware gang. The group claimed it exploited an unauthenticated file-upload vulnerability in Grav CMS to place a file on the site before escalating the incident into a wider takeover.
According to BleepingComputer, the defaced page displayed ShinyHunters’ Umbreon-themed branding and a link to the group’s own leak site. The outlet said it confirmed the uploaded file and defacement, but it did not independently verify the broader claims about stolen system logs, source code, or onion service private keys.
The Record from Recorded Future News reported that ShinyHunters used Cl0p’s own leak infrastructure as leverage, setting an eight-figure demand and later adding a demand for a public apology. A short message attributed to Cl0p later appeared on the same leak site, asking ShinyHunters to make contact through an older platform. That response did not settle who controlled the underlying infrastructure.
Reuters reported that ShinyHunters said it broke into Cl0p’s site on Sept. 18, 2026, after finding a weakness in the software and establishing broad control over the infrastructure. Two cybersecurity experts told Reuters the clash appeared genuine, but Reuters said it could not immediately verify ShinyHunters’ account of the feud.
The feud traces back to Oracle E-Business Suite
ShinyHunters says the dispute began around Cl0p’s 2025 Oracle E-Business Suite extortion campaign. The group claims Cl0p used an exploit that ShinyHunters had found first, then threatened ShinyHunters members as the dispute escalated. That origin story remains an allegation from one criminal group.
The underlying Oracle incident was real. Oracle issued a security alert for CVE-2025-61882 on Oct. 4, 2025, describing a critical Oracle E-Business Suite flaw that could be exploited over a network without authentication and could result in remote code execution. The affected products were Oracle E-Business Suite versions 12.2.3 through 12.2.14, and Oracle assigned the issue a CVSS 3.1 score of 9.8.
The Canadian Centre for Cyber Security also warned organizations about CVE-2025-61882 on Oct. 7, 2025, and strongly recommended patching affected Oracle instances. The alert said CISA had added the vulnerability to its Known Exploited Vulnerabilities catalog on Oct. 6, 2025.
Google Threat Intelligence Group and Mandiant tracked a large-scale extortion campaign beginning Sept. 29, 2025, by an actor claiming affiliation with the CL0P brand. Their October 2025 analysis said the actor exploited what may have been CVE-2025-61882 as a zero-day as early as Aug. 9, 2025, with other suspicious activity dating back to July 10. GTIG also said at the time that it did not assess actors associated with UNC6240, also known as Shiny Hunters, were involved in that exploitation activity.
That distinction is important. The rivalry may involve a disputed exploit, but the public technical record does not prove that ShinyHunters carried out the Oracle EBS exploitation that was attributed to the CL0P extortion brand.
Why a hacker-on-hacker breach still matters to businesses
The risk starts with secondary exposure. If a criminal group obtains another gang’s victim records, negotiation logs, payment records, or stolen files, affected organizations can lose control of data they thought had already been handled through incident response, legal review, and disclosure processes.
ShinyHunters has threatened to release information about companies that allegedly paid Cl0p during the Oracle EBS campaign, including payment amounts and associated Bitcoin addresses, according to BleepingComputer and The Record. There is no public confirmation that ShinyHunters has those records. If the records exist and are published, the damage could extend beyond the original breach by exposing internal crisis decisions, ransom negotiations, and payment details.
The episode also shows that leak sites are not just public shaming pages. For extortion crews, they are operational infrastructure. They host victim listings, direct negotiations, display samples, pressure organizations, and signal credibility to other criminals. If that infrastructure is compromised, data tied to victims and the gang’s own operations can become a target.
The onion-key claim is one of the more sensitive unverified details. BleepingComputer reported that ShinyHunters claimed to have obtained Cl0p’s Tor onion private keys. If valid, that would give the attacker the ability to host the same onion address from separate infrastructure. As of Sept. 23, 2026, public reporting had not independently verified that claim.
ShinyHunters and Cl0p use different pressure models
Cl0p has long been associated with mass exploitation of enterprise software vulnerabilities and data-theft extortion. A 2023 FBI and CISA advisory said the CL0P ransomware gang exploited the MOVEit Transfer vulnerability CVE-2023-34362 beginning in May 2023, using a web shell to steal data from underlying databases. The same advisory said CL0P had increasingly preferred data exfiltration over encryption in campaigns beginning in 2021.
ShinyHunters-branded activity has often centred on social engineering, identity compromise, and software-as-a-service data theft. Google Threat Intelligence Group said in January 2026 that ShinyHunters-branded operations had expanded through vishing, credential-harvesting sites, and targeting of SaaS platforms to steal sensitive data and internal communications for extortion. Google also tracks related activity under multiple clusters rather than treating every ShinyHunters-branded claim as one fixed operator set.
For defenders, the distinction changes the search path. A Cl0p-style incident may start with mass exploitation of a vulnerable public-facing enterprise platform. A ShinyHunters-branded incident may start with a help desk call, stolen credentials, OAuth abuse, or a trusted SaaS integration that has more data access than expected.
What security teams should watch now
The immediate risk is not limited to organizations named in the current feud. Security teams at companies previously affected by Cl0p, Oracle EBS exploitation, SaaS data theft, or ShinyHunters-branded extortion should assume that old stolen data can resurface in a new context.
- Past Cl0p exposure: Monitor for renewed references to earlier incidents, negotiation records, payment claims, or old stolen files appearing in new leak-site posts.
- Oracle EBS status: Confirm that affected Oracle E-Business Suite systems received the October 2025 emergency patches and later relevant updates, then review logs against Oracle, Google, and government indicators where available.
- SaaS and identity access: Review privileged SaaS integrations, OAuth tokens, refresh tokens, connected apps, API activity, and unusual bulk data exports. ShinyHunters-branded campaigns have repeatedly focused on cloud data access.
- Extortion verification: Treat criminal claims as untrusted until validated through logs, samples, and incident response evidence. A threat actor using a famous name may be the actual group, an affiliate, a rival, or an opportunistic impersonator.
- Executive and legal readiness: Prepare for the possibility that old extortion communications or payment claims could become public even after the original incident appears closed.
What remains unclear
The true status of Cl0p’s infrastructure remains unclear. A message attributed to Cl0p appeared after the defacement, but that does not prove full recovery of the site or disprove ShinyHunters’ access. The most cautious reading is that a central Cl0p communications channel was disrupted, and control may have been contested during the public exchange.

Tech Help Canada Staff researches, writes, and reviews practical content for business owners and professionals. Our coverage spans business, marketing, SEO, technology, and the tools and systems people use to grow and operate online. We focus on clear, useful information backed by research, hands-on experience, and editorial review. Learn more about our team and editorial standards. Need help with something? Contact Us





