news.mlab.sh
Back to the feed
threat-intel

ShinyHunters Hacked Clop. Now What About Clop's Victims?

CriticalCVSS 9.8
Summary

ShinyHunters, a cybercrime group known for data theft and extortion, successfully hacked Clop, a notorious ransomware gang's Dark Web leak site. The attack resulted in the defacement of Clop's site and claims that ShinyHunters stole valuable data, including source code, private keys, and potentially information about Clop's victims, including payment details. While the extent of ShinyHunters' data acquisition remains unverified, the incident highlights a persistent risk: stolen data doesn't disappear and can be exploited repeatedly, leaving organizations vulnerable to renewed extortion attempts.

ShinyHunters, a financially motivated cybercrime group primarily known for data theft and extortion attacks, successfully breached Clop’s Dark Web site last week. The incident has led to the defacement of Clop’s leak site, with ShinyHunters leaving a message stating, "DOMAIN SEIZED BY SHINYHUNTERS." ShinyHunters claims to have gained full access to Clop’s server and stolen source code, Grav CMS plug-ins, system logs, private keys for its Onion service, and other data. These claims have not been independently verified.

ShinyHunters continued to taunt Clop’s site, demanding an unspecified eight-figure payment in Bitcoin and threatening to release information about companies that allegedly paid Clop, including payment amounts and Bitcoin addresses. On September 20th, Clop’s page was updated with a note, possibly from Clop itself, claiming ShinyHunters’ email address does not work.

This incident is linked to Clop’s previous campaigns, including the 2023 exploit of Progress Software’s MOVEit file transfer vulnerability (CVE-2025-61882) and a similar attack targeting Fortra GoAnywher. The reference to "EBS" likely refers to Clop’s extortion campaign targeting customers affected by the Oracle E-Business Suite (EBS) zero-day vulnerability.

While the extent of ShinyHunters’ data acquisition remains unverified, the incident underscores a significant ongoing risk. As Malwarebytes’ Pieter Arntz noted, cybercriminal feuds can be a positive, as they reduce the time available for attacks against legitimate businesses. However, the fundamental problem is that stolen data doesn’t retire. It sits on servers run by the original group, its affiliates and its infrastructure providers, and every copy is another chance for theft, resale or exposure.

Jon Baker, vice president of threat-informed defense at AttackIQ, stated that "stolen data doesn't retire." He emphasized that organizations remain accountable for information that is now stored on infrastructure they cannot secure, audit, or even locate. Darren Guccione, CEO and cofounder at Keeper Security, added that "you can't rely on criminals to honor agreements" even if you paid a ransom, highlighting the deceptive nature of the criminal underworld.

**Companies:** Clop **Threat Actors:** ShinyHunters **Malware:** N/A **Sectors:** N/A **Countries:** N/A **Products:** MOVEit, Fortra GoAnywher, Oracle E-Business Suite (EBS) **Tags:** ransomware, data theft, Dark Web, cybercrime, exploit

Read the full article at Dark Reading