ShinyHunters expose une guerre interne du cybercrime
ShinyHunters, a prolific cybercrime group, is embroiled in a complex internal conflict and external battles within the cybercrime ecosystem. The group is actively managing a sophisticated data leak infrastructure, including multiple mirrors and a file queue system, while simultaneously engaging in a public feud with Cl0p-_- and threatening to expose their financial dealings. Notably, the group’s dark web address is now redirecting to ShinyHunters’ site, fueling speculation about a strategic alliance or a deliberate attempt to undermine Cl0p-_. Furthermore, ShinyHunters is directly challenging the FBI, denying accusations of compromising FBI services and demanding a retraction of a security bulletin, highlighting a broader struggle for control and narrative within the cybercrime world.
ShinyHunters, a highly active cybercrime group operating for over a year, is currently embroiled in a complex web of internal disputes and external conflicts within the cybercrime landscape. The group is meticulously managing a robust data leak infrastructure, utilizing multiple Content Delivery Network (CDN) mirrors and a sophisticated file queue system to distribute stolen data. They’ve implemented a ‘PoW’ (Proof of Work) system within their queue, dynamically adjusting download speeds based on traffic to prevent server overload and encourage users to rotate between mirrors. Users are advised to switch mirrors when speeds slow down, and ShinyHunters claims to maintain backups of all leaked data across multiple servers, primarily in Russia.
Between June and September 2026, the group engaged in a series of maintenance operations, including a 24-hour server downtime on June 20th, followed by the deployment of three new mirrors. They also implemented torrent links as a future distribution method. On July 25th, all CDN mirrors experienced another disruption, with ShinyHunters assuring users that data remained intact. Two days later, on July 27th, the mirrors were restored, but the synchronization of content was incomplete, and torrents were prepared for distribution, urging users to share files once available.
September 2026 saw a significant escalation. ShinyHunters asserted that this activity has no connection to Cl0p--_- (a rival group), despite the fact that Cl0p’s dark web address is now redirecting to ShinyHunters’ site. This redirection, coupled with ShinyHunters’ denial of any collaboration, fuels speculation about a strategic maneuver or a deliberate attempt to undermine Cl0p-_. The group is actively managing a battle for control and narrative within the cybercrime world.
Adding to the drama, ShinyHunters issued a direct challenge to the FBI. On September 20th, they released a statement claiming that they have compromised FBI services and possess sensitive data on FBI agents and candidates. They demanded a retraction of a security bulletin issued by the FBI. The group vehemently denies these accusations, asserting that their actions are not financially motivated and demanding direct contact with journalists. This escalation represents a significant shift in the group’s strategy, moving beyond simply leaking data to actively shaping the narrative and challenging law enforcement agencies.
Furthermore, ShinyHunters is now threatening the FBI directly, demanding a change or removal of the bulletin. They claim to have compromised FBI services and possess sensitive data on FBI agents and candidates. The group vehemently denies these accusations, asserting that their actions are not financially motivated and demanding direct contact with journalists. The final message seeks to control its public image by questioning the FBI’s reporting and offering to provide direct contact information. This multifaceted approach – data leakage, strategic redirection, and direct confrontation – underscores ShinyHunters’ ambition and its willingness to engage in a high-stakes battle for dominance within the cybercrime ecosystem.
