Extortionists Extorting Extortionists
In an unusually public feud, the ShinyHunters cybercrime gang hijacked the dark web leak site belonging to the Cl0p ransomware operation over the weekend, defacing it with a banner claiming ownership of the domain and posting extortion demands aimed squarely at Cl0p itself.
The Demand
ShinyHunters set an unspecified eight-figure payment demand, framed as "2.333%" of Cl0p's claimed net worth — implying Cl0p's holdings run into the hundreds of millions. The group threatened to increase the demand daily the longer Cl0p waited to pay, and later tacked on a requirement for a public apology. One posted message read: "Clock is ticking moron. Kindly excuse our unprofessionalism." Another threatened to release Cl0p's own payment records if the group didn't comply. ShinyHunters also demanded a cut of proceeds from Cl0p's recent Oracle E-Business Suite extortion campaign.
By Monday, Cl0p had posted a response on its own (now ShinyHunters-controlled) site attempting to re-establish contact through its original communication channel.
Where the Feud Came From
ShinyHunters claims the dispute originated from Cl0p's unauthorized reuse of a vulnerability that ShinyHunters had publicized, compounded by threats made against a ShinyHunters member. Whatever the precise origin, the public nature of the takeover — banner defacement, taunting messages, a running financial demand — is a departure from the usual dynamic between ransomware crews, which tend to compete quietly rather than seize each other's infrastructure outright.
Who's Involved
ShinyHunters is a data-theft and social-engineering-focused extortion group rather than a traditional technical intrusion crew. It has been behind a string of high-profile breaches through 2026, including the disruption of U.S. school systems via an education platform breach in May, the theft of more than four million medical device user records in April, and earlier attacks against Carnival Cruise Line, Ticketmaster, AT&T, and Rockstar Games.
Cl0p is one of the most financially successful ransomware brands of the past several years, having earned hundreds of millions of dollars primarily by exploiting zero-day vulnerabilities in enterprise file-transfer software — including Cleo, MOVEit, GoAnywhere, and Accellion — rather than through conventional ransomware deployment.
Why This Matters
Public infighting between major cybercrime brands is rare enough to be notable on its own, but it also underscores something defenders should keep in mind: these are not disciplined, unified organizations — they're loose, opportunistic networks with internal rivalries, grudges, and inconsistent operational security, and that instability occasionally spills out into public view. It doesn't change the underlying risk that either group poses to victims, but it's a reminder that "ransomware gang" branding often obscures a much messier reality underneath.
References
- The Record — ShinyHunters Cybercrime Gang Takes Over Cl0p Ransomware Site, Demands Extortion Payment