ShinyHunters hijacked the dark web site of cybercrime gang Cl0p, set an eight-figure extortion demand, describing the amount as "2.333%" of Cl0p's net worth
First reported by Therecord.media ·
The risk of data theft for companies paying ransoms increases as this information is now available for other threat actors to exploit.
The cybercrime group ShinyHunters has successfully hijacked the dark web leak site of the Cl0p ransomware gang, using it to issue its own extortion demands. ShinyHunters defaced Cl0p's site with a banner announcing the seizure and posted messages detailing an unspecified eight-figure ransom, which they described as "2.333%" of Cl0p's estimated net worth. The demands, which escalate daily, have expanded to include a public apology and proceeds from Cl0p's recent Oracle E-Business Suite campaign. ShinyHunters claims the feud began over Cl0p's unauthorized use of a vulnerability and threats against a ShinyHunters member, and they are threatening to release details of companies that have paid Cl0p. Cl0p later posted a message stating they were attempting to contact ShinyHunters through an offline platform.
This event represents a significant escalation in inter-gang rivalries within the cybercrime ecosystem, moving beyond traditional victim targeting to direct attacks on other criminal organizations. The fact that ShinyHunters, known more for social engineering, could successfully compromise and leverage Cl0p's established leak site indicates potential vulnerabilities even within sophisticated criminal infrastructure.
The targeting of Cl0p, a gang responsible for numerous high-profile breaches, by another criminal group highlights the growing complexity and volatility of the cybercrime landscape. This internal conflict could lead to shifts in the ransomware market, potentially disrupting operations and creating new opportunities for other threat actors or law enforcement.
AI-written summary. May contain errors.