ShinyHunters Claims Control of Rival cL0p’s Dark Web Site

The420.in Staff
5 Min Read

A dispute between two prolific cybercrime groups has spilled into the open after ShinyHunters claimed it hacked the dark web site of rival group cL0p, turning a long-running disagreement over a software exploit into an unusual confrontation between cybercriminal operations.

What Did ShinyHunters Claim?

ShinyHunters, a digital extortion group associated with aggressive data-theft campaigns, said it broke into cL0p’s dark web site after discovering a vulnerability in cL0p’s software.

The group claimed it used the weakness to establish wide-ranging control over cL0p’s infrastructure. ShinyHunters went as far as saying, We basically own them now.”

When the cL0p dark web site was visited on Sunday, it was unreachable. However, a screenshot preserved by a cybercrime research platform showed the message Domain Seized By ShinyHunters.”

cL0p did not publicly respond to the claims. Two cybersecurity experts said the confrontation appeared to be genuine.

Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise

Why Are the Groups Fighting?

The dispute is linked to the alleged theft last year of a software exploit involving a previously unknown vulnerability in Oracle’s E-Business Suite.

Such vulnerabilities, commonly known as zero-days, are highly valued by cybercriminals because organisations initially have no time to patch a flaw that was previously unknown.

ShinyHunters said it had discovered the zero-day first, while cL0p later used the E-Business Suite vulnerability to steal data.

The confrontation has since expanded beyond the original disagreement. ShinyHunters said cL0p threatened to reveal the identities of several members of its rival group. ShinyHunters, in response, threatened to disclose details about cL0p’s internal operations.

The account provided by ShinyHunters about the feud could not immediately be independently established.

How Serious Is the Cybercrime Feud?

Cybersecurity specialists described the public confrontation as unusual. One threat intelligence manager said disputes between criminal groups on the dark web do occur.

Another security researcher said he had not previously seen one cybercrime group openly attack another in this manner, describing the situation as two criminal groups fighting each other.

The episode shows how rivalries within the cybercrime ecosystem can extend beyond competition for targets and stolen data into attacks against the infrastructure used by other criminal groups.

What Is cL0p Known For?

cL0p is described as a Russian-speaking cybercrime group known for identifying and exploiting vulnerabilities in enterprise software.

In 2023, the group exploited a vulnerability in MOVEit file-management software and stole data affecting tens of millions of people across more than 600 companies.

More recently, cL0p claimed it had stolen large volumes of data from nearly 50 companies worldwide.

Its reputation has been closely linked to finding software vulnerabilities that can provide access to large numbers of corporate targets.

What Is ShinyHunters Known For?

ShinyHunters has also been associated with large-scale data theft. The group attracted attention in April over a claim involving millions of business records from video game developer Rockstar Games.

It was also linked to a May attack involving education tool Canvas that caused widespread disruption across US schools.

This month, AI company Anthropic said it had caught hackers linked to ShinyHunters attempting to use its tools.

What Happens After the Claimed Takeover?

The full impact of the alleged compromise of cL0p’s infrastructure remains unclear. The available information does not establish how much access ShinyHunters obtained, how long any access lasted or whether the claimed takeover extended beyond the dark web site.

The incident nevertheless marks a rare public escalation between two prominent cybercrime groups, with their dispute moving from competing claims over an exploit to alleged infrastructure compromise and threats to expose each other’s operations.

The420 View

The ShinyHunters-cL0p clash shows that cybercrime groups are not only attacking businesses and institutions but can also target each other’s infrastructure. The bigger concern is the value placed on undisclosed software vulnerabilities.

When zero-day flaws become assets in criminal rivalries, organisations using widely deployed enterprise software can remain exposed before a weakness is discovered and fixed.

About the author — Ayesha Aayat writes on cybercrime, digital safety, and emerging online threats. Her work focuses on public awareness, legal clarity, and technology-driven risks.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected