The escalating dispute between ShinyHunters and the Cl0p ransomware gang has taken another turn, with Cl0p apparently regaining the ability to publish on its compromised dark web site and posting a message asking ShinyHunters to make contact.
Hackread.com observed the latest change on 21 September 2026. Cl0p’s onion address, previously taken over and repurposed by ShinyHunters, displayed a short message from the ransomware gang directed at ShinyHunters.
BookSecurity Audits - “Shiny Hunters, we're trying to reach you. Your email does not work. Come online on the old platform; no
Cl0p ransomware gang’s message for ShinyHunters (Image credit: Hackread.com)
The development comes days after ShinyHunters compromised Cl0p’s data leak site (DLS) and replaced its normal content with ShinyHunters’ own material. The takeover went beyond changing the site's appearance. During the compromise, visitors accessing Cl0p’s onion address could download Salesforce-related data that ShinyHunters had also made available through its own leak site.
Hackread.com directly observed the takeover and reported on 19 September that Cl0p’s normal DLS had been replaced by ShinyHunters content. However, the message alone does not establish whether Cl0p has fully regained control of the underlying infrastructure or whether ShinyHunters retains access.
ShinyHunters Demands Eight-Figure Payment - Before Cl0p’s latest message appeared, ShinyHunters had been using the compromised site to issue demands directly to the ransomware gang.
In a 19 September message observed by Hackread.com, ShinyHunters demanded what it described as an eight-figure payment and instructed Cl0p to contact the group by email. The message included a deadline and a threat directed at Cl0p if the group refused to engage.
BookSecurity Audits - The demand escalated on 20 September. ShinyHunters addressed two individuals it identified as “Likhogray & Tarasov” and told them to get their boss, referred to as “j0nny,” to respond.
ShinyHunters said it wanted money Cl0p allegedly made from its Oracle E-Business Suite campaign, plus an additional amount and interest. The group also threatened to disclose information it claims to possess about companies that paid Cl0p, including the amounts involved and Bitcoin addresses allegedly used for the payments.
Hackread.com has not independently verified whether ShinyHunters possesses those records.
ShinyHunters’ message to Cl0p ransomware on the compromised site of the group (Image credit: Hackread.com)
Reuters reported on 21 September that ShinyHunters described the incident as part of a longer dispute involving an Oracle E-Business Suite zero-day. According to ShinyHunters’ account to Reuters, it discovered the vulnerability first, while Cl0p subsequently used the flaw in attacks against organizations. Reuters said it could not independently establish the accuracy of ShinyHunters’ account of how the dispute began.
Public Apology Added to Demands - ShinyHunters updated its message again on September 21, adding another condition. The group said its demands would increase for every 24 hours that Cl0p failed to engage and demanded that Cl0p issue a public apology directly to ShinyHunters.
The continuing messages showed that ShinyHunters retained the ability to publish content through Cl0p’s onion site at that point. That changed later when the ShinyHunters material disappeared, and the short message apparently written by Cl0p appeared in its place.
Cl0p’s request for ShinyHunters to “come online” suggests it is trying to establish contact with the group. The message does not identify the “old platform” it wants ShinyHunters to use.
ShinyHunters Site Outage Was Unrelated - Another question arose after ShinyHunters’ own onion site became unavailable for several hours. Hackread.com contacted ShinyHunters to ask whether the outage was connected to the attack against Cl0p. The group said it was not.
BookSecurity Audits - “Our onion domain is accessible. Please try a new circuit. There was a few-hour downtime due to network issues unrelated to the Cl0p incident. We are dealing with a lot of routine and scheduled maintenance on our infrastructure. Thank you.”
ShinyHunters - The site subsequently returned online. ShinyHunters did not address Hackread.com’s other questions about the extent of its access to Cl0p’s infrastructure, whether it had taken data from Cl0p, or whether it controlled additional systems.
A Dispute Between Two Major Cybercrime Groups - The confrontation is unusual because both sides are established cybercrime operations. Cl0p has operated since at least 2019 and has been responsible for major data-theft campaigns involving vulnerabilities in enterprise file-transfer software, including Accellion FTA, GoAnywhere MFT, and MOVEit Transfer.
Its 2023 MOVEit campaign affected thousands of organizations and tens of millions of individuals. More recently, Cl0p exploited Oracle E-Business Suite vulnerabilities to steal data from organizations using the enterprise software.
MasterCoding Skills - ShinyHunters, meanwhile, has been linked to numerous data-theft and extortion operations and has been particularly active in campaigns involving cloud services and enterprise platforms. For now, Cl0p is publicly attempting to reach ShinyHunters, while the extent of either group’s control over the compromised infrastructure remains unclear.
This article is shared at no charge for educational and informational purposes only.
Red Sky Alliance is a Cyber Threat Analysis and Intelligence Service organization. We provide indicators of compromise information (CTI) via a notification service (RedXray) or an analysis service (CTAC). For questions, comments, or assistance, please contact the office directly at 1-844-492-7225 or feedback@redskyalliance.com
- Reporting: https://www.redskyalliance.org/
- Website: https://www.redskyalliance.com/
- LinkedIn: https://www.linkedin.com/company/64265941
Weekly Cyber Intelligence Briefings:
REDSHORTS - Weekly Cyber Intelligence Briefings
https://register.gotowebinar.com/register/5207428251321676122
[1] https://hackread.com/clop-ransomware-responds-shinyhunters-demands/#google_vignette
Comments