ShinyHunters vs. Clop: Unfolding Cybercriminal Feud Raises Risk for Security Teams Worldwide
ShinyHunters and Clop's Cybercriminal Feud Puts Security Teams on High Alert
A public clash between two of the most notorious cybercriminal groups — ShinyHunters and Clop — escalated dramatically on September 19, 2026, when ShinyHunters defaced Clop's leak site and demanded an eight-figure payment.
Security leaders are warning that while watching criminal gangs battle each other may feel like poetic justice, the chaos created by this feud poses serious and evolving risks for organizations worldwide. When threat actors turn on each other, tactics shift rapidly and unpredictably — and businesses caught in the crossfire rarely emerge unscathed.
How the Feud Between Two Cybercriminal Giants Unfolded
The roots of this conflict trace back to August 10, 2025, when a Telegram channel associated with ShinyHunters advertised a large cache of vulnerabilities. Among them was an exploit targeting the path /OA_HTML/configurator/UiServlet — a server-side request forgery function with significant destructive potential.
On October 3, 2025, ShinyHunters reshared the post and claimed the vulnerability was the same one Clop had used against Oracle's E-Business Suite. A member of the group told BleepingComputer that the exploit was originally theirs and that they leaked it publicly because Clop had taken it and was using it "in an unsuccessful way."
That grievance simmered for nearly a year before boiling over. On September 19, 2026, ShinyHunters defaced Clop's leak site by exploiting an unauthenticated file upload flaw in Grav — the content management system hosting the site. The group framed the attack as direct retaliation for an alleged threat of violence made by a Clop representative during the Oracle campaign.
Two Groups, Two Distinct but Dangerous Methodologies
Understanding how each group operates is critical context for security teams. Ian Gray, VP of Intelligence at Flashpoint, outlined the distinct but overlapping methods both groups employ.
"Clop has distinguished itself by finding and exploiting zero-day vulnerabilities in widely deployed enterprise data-handling platforms — file transfer applications like Accellion, MOVEit and Cleo, and most recently Oracle E-Business Suite," Gray explained. "The most recent iteration of ShinyHunters has gone after a softer target: weaknesses in how organizations verify identity, using voice phishing against IT help desks and abusing session tokens to reach data in software-as-a-service platforms."
These approaches reflect a broader pattern in modern cybercrime. Understanding how ransomware attacks are structured and deployed helps organizations anticipate where they are most exposed — whether through unpatched enterprise software or compromised identity verification processes.
Escalating Demands and an Uncertain Power Shift
ShinyHunters has not been subtle about its ambitions since the site defacement. The group issued a demand for an eight-figure payment and added a requirement for a public apology as of September 21, 2026 — with the stakes reportedly increasing daily.
The Claim That Could Reshape Dark Web Extortion
Perhaps most alarming is ShinyHunters' claim that it holds the private keys to Clop's onion service. If verified, this would allow ShinyHunters to operate a site at Clop's exact dark web address. Past victims of Clop's extortion campaigns could then face pressure from a second threat actor wielding the same data as leverage — effectively meaning organizations could be extorted twice for a single breach they had no part in causing.
Gray urged caution in interpreting these claims. "ShinyHunters clearly demonstrated access and succeeded in publicly embarrassing a major extortion group," he said. "But we haven't seen evidence that it obtained the negotiation records, payment data or other material that would give it the leverage it claims. We'll continue to watch as this feud unfolds."
The situation echoes the kind of power struggle familiar to fans of crime dramas — the depiction of criminal hierarchies crumbling under internal conflict in The Wire, for example — except the consequences here ripple directly into corporate boardrooms and government agencies.
Why Organizations Cannot Afford to Look Away
Security professionals are unanimous on one point: a war between criminal groups does not reduce risk for everyone else. If anything, it amplifies it.
Pierre-Loïc Kuhn, Cybersecurity Specialist at Filigran, put it plainly. "Organizations must stay on high alert because when rival groups clash, tactics shift rapidly and the threat landscape evolves faster than ever," he said.
A Structural Shift in the Ransomware Economy
Jeff Wichman, Senior Director of Breach Preparedness and Response at Semperis, predicted that hacker-on-hacker conflict will intensify in the months ahead. "Hacker-on-hacker crime is poetic justice against the criminal gangs that have been causing years of pain by ransoming public and private organizations," Wichman said. He added that threat actors frequently fall victim to the same phishing emails and scams they deploy against others — a direct result of poor security hygiene within their own criminal operations.
Wichman also pointed to a structural shift in the ransomware economy. "The barrier to entry into the ransomware economy is lower than ever and the number of low-skilled threat actors continue to enter the industry," he noted. "We can expect the egos and personal disputes between rival gangs to lead to more hacker-on-hacker crime in the months ahead."
This lowered barrier to entry is closely tied to the growth of Crime-as-a-Service models in cybercrime, which have made sophisticated attack capabilities accessible to actors who would previously have lacked the technical skills to deploy them independently.
Three Immediate Priorities for Security Teams
For security leaders monitoring this situation, three immediate priorities emerge from the available intelligence:
- Audit identity verification processes. ShinyHunters has specifically targeted IT help desks through voice phishing and exploited session tokens — vulnerabilities that many organizations have not fully addressed.
- Patch enterprise platforms without delay. Clop's track record of targeting file transfer and data-handling applications means unpatched systems remain a critical exposure point.
- Monitor dark web activity. If ShinyHunters does gain control of Clop's onion service address, organizations previously targeted by Clop may face renewed extortion attempts from a new actor using old data.
Staying Ahead of a Rapidly Shifting Threat Landscape
Robust threat management strategies for evolving cyber risks have never been more relevant. The unpredictability created when major criminal groups turn on one another demands that organizations move beyond reactive postures and invest in continuous monitoring, rapid patch cycles, and layered identity controls.
The ShinyHunters and Clop feud is a reminder that the cybercriminal ecosystem is neither stable nor predictable. Security teams that treat this conflict as a spectator sport do so at their organization's peril. Staying informed and maintaining rigorous defensive postures remains the most reliable protection as this situation continues to develop.
For the latest reporting on cybercriminal group activity and dark web developments, Krebs on Security provides in-depth, regularly updated coverage from one of the most respected independent cybersecurity journalists.