Back to blog

Blog Post

Beacon: ShinyHunters Hacks Cl0p Leak Site

Share on social

Sep 24, 2026

Lorem ipsum

Table of contents

Share on social

Join the newsletter
Beacon: ShinyHunters Hacks Cl0p Leak Site

Top Story This Week:

ShinyHunters Hacks Cl0p Leak Site

Ransomware gang ShinyHunters breached the data leak site run by Cl0p, defacing it and claiming to have pulled source code, system logs and the private keys to Cl0p's onion service. The group says it exploited an unauthenticated file-upload flaw in Grav CMS to plant a taunting message before fully replacing the site with its own branding.

ShinyHunters has since posted daily threats on its own leak site, demanding an eight-figure payment that rises each day Cl0p stays silent, along with a public apology and the release of details on companies that allegedly paid Cl0p during its 2025 Oracle E-Business Suite campaign. Cl0p briefly responded on its hijacked site asking to be contacted through another channel, but ShinyHunters rejected this and kept up the pressure.

ShinyHunters says the attack is payback for threats a Cl0p member allegedly made after a dispute over the Oracle exploit the two groups both claim credit for. (Read more in BleepingComputer.)

Why it Matters

Cl0p and ShinyHunters have followed noticeably different paths. Cl0p has become closely associated with exploiting zero-day vulnerabilities in widely used enterprise software to steal data at scale, while ShinyHunters has historically relied more heavily on stolen credentials, social engineering and the abuse of cloud and SaaS platforms. But those distinctions are becoming less clear. In June, ShinyHunters were attributed to a campaign that exploited a previously unknown Oracle PeopleSoft vulnerability before Oracle had disclosed it, potentially compromising more than 100 organizations.Both groups have demonstrated an ability to adapt their operations, and that techniques once strongly associated with one threat actor can quickly be adopted by others.

Monitoring changes in ransomware group TTPs and their specific activity can give defenders an earlier indication that the threat they are preparing for has changed, and that their own defensive strategies may need to be reassessed.

What this Means for Practitioners

Tracking ransomware groups shouldn't mean maintaining a static list of threat actors and their known TTPs. Groups change their tactics, adopt new capabilities, target different industries and sometimes disappear altogether, while new groups can emerge to fill the gap. Security teams should therefore regularly reassess the groups most relevant to their organisation and monitor changes in their behaviour.

Treat ransomware-gang leak sites as volatile infrastructure, not fixed reference points. A defaced or hijacked site can briefly expose extra data about past victims.

Watch for opportunistic activity: internal feuds between threat actors can trigger rushed data dumps or rebrands that don't match a group's usual pattern.

What this Means for Security Leaders

Threat intelligence is most valuable when it changes what an organization does. Leaders should make sure intelligence on relevant adversaries is connected to vulnerability and exposure management, risk assessment and security planning, rather than treating it as a separate stream of information for the security team to consume.

Push for continuous, not periodic, monitoring of the ransomware ecosystem so shifts like this one are caught within hours, not at the next quarterly review.

If your organization has ever engaged with Cl0p, consider that payment details could resurface publicly as leverage in this feud.

Discover More

The 2026 ‘Forum Wars’: Deconstructing the Drama

What happens when a threat actor deliberately adopts the identity of a former, fellow, or even rival threat actor in order to benefit from their notoriety? In this blog, we bring you up to date on the 2026 ‘Forum Wars’ playing out across the cybercriminal community, charting the conflict between the key antagonists in this story. Read more.

The Intelligence Hidden in Ransomware Data

Ransomware hasn't gone anywhere, in fact, the threat is continuing to increase. The second half of 2025 saw a 30% increase in victims listed on ransomware leak sites compared to 2024. In this blog, we discuss how the intelligence hidden in ransomware leak sites can give organizations the information they need to secure and protect their assets. Read more.

Lizzie Clark

Author

Lizzie Clark

Marketing Executive at Searchlight Cyber

Lizzie is an experienced IT and cybersecurity marketing professional with six years of specialist experience in the industry. Lizzie produces a range of content - from blogs and long-form articles to newsletters and social media - with a focus on writing that informs and engages technical audiences.

Aggregated dashboards carry in-house collected intelligence on hundreds of groups, with continuously updated tactics, known members, and victims. Set actor-specific alerts to follow a group's activity, and use Ransomware File Explorer to search leak-site file trees for compromised files, before public disclosure. Initial Access Broker listings matching your organization's profile surface preemptively on their own dashboard.

Related Blog Posts

September 22, 2026

Sentinel integration for Searchlight Threat – Monitor

September 22, 2026

Reduce false positives with Email Format Validation

September 22, 2026

New Company Dashboard in Searchlight Threat – Monitor

September 17, 2026

Beacon: AI agents being tested by OpenAI involved in cyber-attack on another service, say researchers

September 16, 2026

How AI Is Collapsing Exploitation Timelines

September 15, 2026

Faster Leaked Credential Search with a rebuilt experience

Never miss a beat

Get all news and updates about Searchlight Cyber, directly in your inbox.

Subscribe
Please enter a valid email address.
Background Gradient