Share on social
Sep 24, 2026
Lorem ipsum

Top Story This Week:
ShinyHunters Hacks Cl0p Leak Site
Ransomware gang ShinyHunters breached the data leak site run by Cl0p, defacing it and claiming to have pulled source code, system logs and the private keys to Cl0p's onion service. The group says it exploited an unauthenticated file-upload flaw in Grav CMS to plant a taunting message before fully replacing the site with its own branding.
ShinyHunters has since posted daily threats on its own leak site, demanding an eight-figure payment that rises each day Cl0p stays silent, along with a public apology and the release of details on companies that allegedly paid Cl0p during its 2025 Oracle E-Business Suite campaign. Cl0p briefly responded on its hijacked site asking to be contacted through another channel, but ShinyHunters rejected this and kept up the pressure.
ShinyHunters says the attack is payback for threats a Cl0p member allegedly made after a dispute over the Oracle exploit the two groups both claim credit for. (Read more in BleepingComputer.)
Why it Matters
Cl0p and ShinyHunters have followed noticeably different paths. Cl0p has become closely associated with exploiting zero-day vulnerabilities in widely used enterprise software to steal data at scale, while ShinyHunters has historically relied more heavily on stolen credentials, social engineering and the abuse of cloud and SaaS platforms. But those distinctions are becoming less clear. In June, ShinyHunters were attributed to a campaign that exploited a previously unknown Oracle PeopleSoft vulnerability before Oracle had disclosed it, potentially compromising more than 100 organizations.Both groups have demonstrated an ability to adapt their operations, and that techniques once strongly associated with one threat actor can quickly be adopted by others.
Monitoring changes in ransomware group TTPs and their specific activity can give defenders an earlier indication that the threat they are preparing for has changed, and that their own defensive strategies may need to be reassessed.
What this Means for Practitioners
Tracking ransomware groups shouldn't mean maintaining a static list of threat actors and their known TTPs. Groups change their tactics, adopt new capabilities, target different industries and sometimes disappear altogether, while new groups can emerge to fill the gap. Security teams should therefore regularly reassess the groups most relevant to their organisation and monitor changes in their behaviour.
Treat ransomware-gang leak sites as volatile infrastructure, not fixed reference points. A defaced or hijacked site can briefly expose extra data about past victims.
Watch for opportunistic activity: internal feuds between threat actors can trigger rushed data dumps or rebrands that don't match a group's usual pattern.
What this Means for Security Leaders
Threat intelligence is most valuable when it changes what an organization does. Leaders should make sure intelligence on relevant adversaries is connected to vulnerability and exposure management, risk assessment and security planning, rather than treating it as a separate stream of information for the security team to consume.
Push for continuous, not periodic, monitoring of the ransomware ecosystem so shifts like this one are caught within hours, not at the next quarterly review.
If your organization has ever engaged with Cl0p, consider that payment details could resurface publicly as leverage in this feud.
Discover More
The 2026 ‘Forum Wars’: Deconstructing the Drama
What happens when a threat actor deliberately adopts the identity of a former, fellow, or even rival threat actor in order to benefit from their notoriety? In this blog, we bring you up to date on the 2026 ‘Forum Wars’ playing out across the cybercriminal community, charting the conflict between the key antagonists in this story. Read more.
The Intelligence Hidden in Ransomware Data
Ransomware hasn't gone anywhere, in fact, the threat is continuing to increase. The second half of 2025 saw a 30% increase in victims listed on ransomware leak sites compared to 2024. In this blog, we discuss how the intelligence hidden in ransomware leak sites can give organizations the information they need to secure and protect their assets. Read more.
Aggregated dashboards carry in-house collected intelligence on hundreds of groups, with continuously updated tactics, known members, and victims. Set actor-specific alerts to follow a group's activity, and use Ransomware File Explorer to search leak-site file trees for compromised files, before public disclosure. Initial Access Broker listings matching your organization's profile surface preemptively on their own dashboard.







