Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2964+ Articles
168+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. ShinyHunters Hijacks Cl0p's Ransomware Leak Site, Demands Extortion Payment
ShinyHunters Hijacks Cl0p's Ransomware Leak Site, Demands Extortion Payment
NEWS

ShinyHunters Hijacks Cl0p's Ransomware Leak Site, Demands Extortion Payment

ShinyHunters seized Cl0p's dark web leak site, defaced it, and is demanding an eight-figure payment plus a public apology.

Dylan H.

News Desk

September 21, 2026
3 min read

Extortionists Extorting Extortionists

In an unusually public feud, the ShinyHunters cybercrime gang hijacked the dark web leak site belonging to the Cl0p ransomware operation over the weekend, defacing it with a banner claiming ownership of the domain and posting extortion demands aimed squarely at Cl0p itself.


The Demand

ShinyHunters set an unspecified eight-figure payment demand, framed as "2.333%" of Cl0p's claimed net worth — implying Cl0p's holdings run into the hundreds of millions. The group threatened to increase the demand daily the longer Cl0p waited to pay, and later tacked on a requirement for a public apology. One posted message read: "Clock is ticking moron. Kindly excuse our unprofessionalism." Another threatened to release Cl0p's own payment records if the group didn't comply. ShinyHunters also demanded a cut of proceeds from Cl0p's recent Oracle E-Business Suite extortion campaign.

By Monday, Cl0p had posted a response on its own (now ShinyHunters-controlled) site attempting to re-establish contact through its original communication channel.


Where the Feud Came From

ShinyHunters claims the dispute originated from Cl0p's unauthorized reuse of a vulnerability that ShinyHunters had publicized, compounded by threats made against a ShinyHunters member. Whatever the precise origin, the public nature of the takeover — banner defacement, taunting messages, a running financial demand — is a departure from the usual dynamic between ransomware crews, which tend to compete quietly rather than seize each other's infrastructure outright.


Who's Involved

ShinyHunters is a data-theft and social-engineering-focused extortion group rather than a traditional technical intrusion crew. It has been behind a string of high-profile breaches through 2026, including the disruption of U.S. school systems via an education platform breach in May, the theft of more than four million medical device user records in April, and earlier attacks against Carnival Cruise Line, Ticketmaster, AT&T, and Rockstar Games.

Cl0p is one of the most financially successful ransomware brands of the past several years, having earned hundreds of millions of dollars primarily by exploiting zero-day vulnerabilities in enterprise file-transfer software — including Cleo, MOVEit, GoAnywhere, and Accellion — rather than through conventional ransomware deployment.


Why This Matters

Public infighting between major cybercrime brands is rare enough to be notable on its own, but it also underscores something defenders should keep in mind: these are not disciplined, unified organizations — they're loose, opportunistic networks with internal rivalries, grudges, and inconsistent operational security, and that instability occasionally spills out into public view. It doesn't change the underlying risk that either group poses to victims, but it's a reminder that "ransomware gang" branding often obscures a much messier reality underneath.


References

  • The Record — ShinyHunters Cybercrime Gang Takes Over Cl0p Ransomware Site, Demands Extortion Payment

Related Reading

  • ShinyHunters Breach Infinite Campus Threatens 11 Million Student Records
  • Instructure Reaches Ransom Agreement With ShinyHunters to Stop 365TB Canvas Leak
#ShinyHunters#Cl0p#Ransomware#Extortion#Cybercrime

Related Articles

ShinyHunters Hacks Clop Leak Site, Threatens to Extort Ransomware Gang

ShinyHunters defaced Clop's Tor leak site and claims to have stolen its onion service private keys, threatening to extort the ransomware gang.

5 min read

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

Threat actors linked to the Cl0p ransomware group are actively exploiting chained pre-authentication vulnerabilities in PTC Windchill and FlexPLM...

5 min read

ADT Confirms Data Breach After ShinyHunters Leak Threat

Home security giant ADT has confirmed a data breach after the ShinyHunters extortion group threatened to publish stolen data unless a ransom is paid,...

5 min read
Back to all News