Oracle: Clop gets a taste of its own medicine after ShinyHunters hijack leak site

Oracle: Clop gets a taste of its own medicine after ShinyHunters hijack leak site

Clop Ransomware Gang Hit by Extortion Demand from Rival ShinyHunters

Over the weekend, the notorious Clop ransomware group found itself on the receiving end of an extortion attack after rival cybercrime crew ShinyHunters hijacked its dark web leak site. The takeover, first noticed on Friday, saw Clop’s site defaced with a bold "DOMAIN SEIZED BY SHINYHUNTERS" banner, accompanied by a taunting tagline.

ShinyHunters claimed to have exploited a vulnerability in the software powering Clop’s site, gaining extensive access to its infrastructure. The group told Reuters it now effectively "owns" Clop, though Clop has not publicly responded. Security researchers confirmed the breach appears legitimate, with The Register verifying the defaced site.

The feud stems from Clop’s 2023 attacks on Oracle E-Business Suite (EBS) customers, where ShinyHunters alleges Clop stole and weaponized a zero-day exploit it had discovered first. On September 19, ShinyHunters demanded an eight-figure payout later escalating to "all the money" made from the EBS campaign, plus interest. The group also threatened to expose companies that paid Clop, including ransom amounts and Bitcoin addresses.

By September 21, ShinyHunters intensified its demands, warning of daily increases in the ransom and demanding a public apology. The escalation underscores the high stakes: if ShinyHunters publishes payment records, it could undermine Clop’s reputation for secrecy, potentially exposing past victims who believed their deals remained confidential.

Clop, known for high-profile attacks like the 2023 MOVEit campaign which breached thousands of organizations and compromised millions of records now faces reputational damage. Leak sites are critical for extortion groups to prove control over stolen data; having one hijacked by a rival is a severe blow.

ShinyHunters, itself linked to major data theft and extortion operations, has vowed to keep raising the price until Clop responds. The incident marks a rare case of cybercriminals turning the tables on one another, with potential fallout for both the attackers and their past victims.

Source: https://www.theregister.com/cyber-crime/2026/09/21/clop-gets-a-taste-of-its-own-medicine-after-shinyhunters-hijack-leak-site/5297702

Oracle TPRM report: https://www.rankiteo.com/company/dsp-oracle-e-business-suite

"id": "dsp1790000861",
"linkid": "dsp-oracle-e-business-suite",
"type": "Cyber Attack",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Past victims of Clop ransomware '
                                              'attacks',
                        'industry': 'Cybercrime',
                        'name': 'Clop Ransomware Gang',
                        'type': 'Cybercriminal Organization'}],
 'attack_vector': 'Exploitation of vulnerability in dark web leak site '
                  'software',
 'data_breach': {'data_exfiltration': 'Potential exposure of past ransom '
                                      'payments and victim details',
                 'personally_identifiable_information': 'Potential exposure of '
                                                        'victim identities and '
                                                        'payment details',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Infrastructure access details',
                                              'Potential ransom payment '
                                              'records',
                                              'Victim details']},
 'date_detected': '2024-09-20',
 'date_publicly_disclosed': '2024-09-20',
 'description': "Over the weekend, the Clop ransomware group's dark web leak "
                'site was hijacked by rival cybercrime crew ShinyHunters, who '
                'defaced the site and demanded an extortion payout. '
                'ShinyHunters claimed to have exploited a vulnerability in '
                "Clop's site software, gaining extensive access to its "
                "infrastructure. The feud stems from Clop's 2023 attacks on "
                'Oracle E-Business Suite customers, where ShinyHunters alleges '
                'Clop stole and weaponized a zero-day exploit it had '
                'discovered first. ShinyHunters demanded an eight-figure '
                "payout, escalating to 'all the money' made from the EBS "
                'campaign, plus interest, and threatened to expose companies '
                'that paid Clop.',
 'impact': {'brand_reputation_impact': 'Severe reputational damage to Clop due '
                                       'to site hijacking and exposure threats',
            'data_compromised': "Clop's infrastructure access, potential "
                                'exposure of past ransom payments and victim '
                                'details',
            'operational_impact': "Disruption of Clop's extortion operations, "
                                  'potential loss of victim trust',
            'payment_information_risk': 'Potential exposure of Bitcoin '
                                        'addresses and ransom payment details',
            'systems_affected': "Clop's dark web leak site and associated "
                                'infrastructure'},
 'initial_access_broker': {'entry_point': "Vulnerability in Clop's dark web "
                                          'leak site software',
                           'high_value_targets': "Clop's infrastructure and "
                                                 'victim data'},
 'investigation_status': 'Ongoing',
 'motivation': ['Financial gain',
                'Revenge for stolen exploit',
                'Reputational damage'],
 'post_incident_analysis': {'root_causes': 'Exploitation of zero-day '
                                           "vulnerability in Clop's dark web "
                                           'site software by ShinyHunters'},
 'ransomware': {'data_exfiltration': 'Potential exposure of past ransom '
                                     'payments and victim details',
                'ransom_demanded': "Eight-figure payout (escalated to 'all the "
                                   "money' made from EBS campaign + interest)"},
 'references': [{'date_accessed': '2024-09-20', 'source': 'Reuters'},
                {'date_accessed': '2024-09-20', 'source': 'The Register'}],
 'threat_actor': ['Clop Ransomware Gang', 'ShinyHunters'],
 'title': 'Clop Ransomware Gang Hit by Extortion Demand from Rival '
          'ShinyHunters',
 'type': 'Extortion, Ransomware, Cybercriminal Feud',
 'vulnerability_exploited': "Zero-day exploit in Clop's dark web site software"}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.