Cybercriminal group ShinyHunters has breached and defaced the dark-web leak site operated by the Clop ransomware gang, turning a long-running feud between two major extortion groups into a direct attack on criminal infrastructure.
The breach began on Friday night when ShinyHunters allegedly exploited an unauthenticated file-upload flaw in the content management system used by Clop’s Tor site. A small text file containing a warning to Clop was first uploaded before the entire site was later replaced with ShinyHunters branding.
BleepingComputer independently confirmed that the file had been uploaded to Clop’s infrastructure and later verified that the leak site itself had been defaced.
ShinyHunters is now claiming that it stole internal server data and intends to extort Clop in return.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
Clop’s own leak site was turned against it
Ransomware groups commonly operate dark-web leak sites to pressure victims.
When companies refuse to pay, stolen files may be published on these sites to increase reputational and legal pressure.
Clop has used this model in several major data-theft campaigns.
This time, however, the gang’s own infrastructure became the target.
According to BleepingComputer, ShinyHunters first placed a text message on Clop’s server warning the rival group not to threaten it. Hours later, Clop’s site was replaced with a page showing ShinyHunters’ Umbreon logo and a link to its own Tor service.
The defacement itself has been independently verified.
What happened beyond that is less certain.
ShinyHunters claims it stole server logs and private keys
ShinyHunters told BleepingComputer that it obtained “full access” to Clop’s server.
The group claims to have stolen source code, Grav CMS plugins, system logs and other internal data. It also says it copied files from the server’s /var/log directory.
Such logs can contain information about system activity, authentication attempts and potentially IP addresses that connected to the server.
That could be particularly sensitive for a ransomware operation that depends heavily on anonymity.
ShinyHunters also claims it obtained the private keys linked to Clop’s Tor onion service.
If those keys are genuine, they could theoretically allow the attacker to host another service using the same onion address.
BleepingComputer said it had not independently verified the theft of the logs, source code or Tor private keys. Those claims should therefore be treated as statements from ShinyHunters rather than established facts.
What an onion private key actually does
Tor services use special .onion addresses that allow websites to operate without revealing their normal internet location.
A private key is one of the cryptographic elements that proves control over that onion identity.
In simple terms, it is similar to possessing the master credential that allows a site operator to prove that a particular onion address belongs to them.
If ShinyHunters genuinely obtained Clop’s private keys, the risk goes beyond simply defacing the existing server.
The group could potentially recreate the same onion identity elsewhere, making it difficult for visitors to know which infrastructure is genuinely controlled by Clop.
That would be an unusually serious compromise for a cybercrime group whose business depends on maintaining a trusted extortion portal.
Rivalry reportedly dates back to Oracle attacks
ShinyHunters says the attack was retaliation for threats allegedly made by a Clop representative.
According to the group, the dispute intensified during Clop’s 2025 campaign targeting Oracle E-Business Suite systems.
Clop exploited multiple vulnerabilities during that operation, including the critical CVE-2025-61882 flaw, to steal data from organisations and pressure them for payment.
Around the same period, an alliance calling itself Scattered Lapsus$ Hunters, which included ShinyHunters, leaked a proof-of-concept exploit that Oracle later said resembled one used in the Clop attacks.
ShinyHunters has claimed that the exploit originally belonged to it and was obtained by Clop without permission.
The group further alleges that a Clop representative later issued personal and violent threats against its members. BleepingComputer has not independently verified those claims, and Clop had not responded publicly at the time of reporting.
Extortion groups are increasingly attacking each other
The incident is unusual, but it reflects a broader shift in the cybercrime ecosystem.
Ransomware and extortion groups often compete for victims, affiliates, leaked exploits and stolen credentials. Their infrastructure can therefore become attractive targets to rival criminals, researchers and law-enforcement agencies alike.
ShinyHunters itself has been linked to a long list of corporate data-theft and extortion campaigns, including attacks involving Salesforce customers and major global organisations.
Clop, meanwhile, has repeatedly targeted enterprise software and file-transfer systems to steal large volumes of corporate data.
The latest clash is striking because it reverses the usual extortion model.
Instead of threatening a company with stolen data, ShinyHunters says it now plans to threaten another cybercrime gang with data allegedly stolen from its own infrastructure.
The group told BleepingComputer that it plans to give Clop 72 hours to make contact.
Whether that threat results in payment, retaliation or further leaks remains unclear.
What this means for you: The incident does not directly target ordinary users, but it shows that ransomware groups themselves can suffer major security failures. For organisations, it is another reminder that stolen corporate data may circulate between multiple criminal groups long after the original breach.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics