ShinyHunters Hacking Group Targets Clop Ransomware Gang in High-Profile Cyber Feud
On the evening of 18 September, the ShinyHunters hacking and extortion group launched a cyberattack against the Clop ransomware gang, defacing Clop’s dark web data leak site with a taunting message: “THIS SITE HAS BEEN PWN3D BY SHINYHUNTERS.” The site’s background was replaced with ASCII art of a Pokémon, and a link to ShinyHunters’ own leak portal was added.
ShinyHunters claimed to have stolen private keys, server data, and authentication logs from Clop’s ransomware infrastructure, including IP addresses of Clop members potentially exposing their identities. The group issued a ransom demand, instructing Clop to contact them, and confirmed to Bleeping Computer that their goal was to extort the rival gang.
The attack marks the latest escalation in a feud between the two criminal groups, which began in 2025 over competing claims to a zero-day vulnerability (CVE-2025-61882) in Oracle E-Business Suite servers. Both gangs had exploited the flaw in extortion campaigns, leading to a breakdown in trust.
ShinyHunters, one of the most active extortion groups of 2026, has targeted major organizations, including McKesson, a U.S. healthcare distributor serving over 40,000 customers, as well as Salesforce Experience Cloud and Canvas Learning Management System users.
Clop, operational since 2019, has a history of high-profile attacks, including a 2025 breach at the University of Phoenix affecting 3.5 million individuals and 2023 ransomware campaigns exploiting MOVEit Transfer vulnerabilities.
The incident underscores the competitive and volatile nature of cybercriminal ecosystems, where rival groups operate as profit-driven enterprises even turning on one another when disputes arise.
Source: https://www.infosecurity-magazine.com/news/shinyhunters-claim-hack-of-clop/
Oracle cybersecurity rating report: https://www.rankiteo.com/company/oracle
McKesson Corporation cybersecurity rating report: https://www.rankiteo.com/company/mckesson-corporation
"id": "ORAMCK1790001005",
"linkid": "oracle, mckesson-corporation",
"type": "Vulnerability",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Cybercrime',
'name': 'Clop Ransomware Gang',
'type': 'Cybercriminal Organization'}],
'attack_vector': 'Exploitation of internal infrastructure, Defacement',
'data_breach': {'data_exfiltration': 'Yes',
'personally_identifiable_information': 'IP addresses of Clop '
'members',
'sensitivity_of_data': 'High (potential exposure of threat '
"actors' identities)",
'type_of_data_compromised': 'Private keys, server data, '
'authentication logs, IP '
'addresses'},
'date_detected': '2026-09-18',
'date_publicly_disclosed': '2026-09-18',
'description': 'On the evening of 18 September, the ShinyHunters hacking and '
'extortion group launched a cyberattack against the Clop '
'ransomware gang, defacing Clop’s dark web data leak site with '
'a taunting message. ShinyHunters claimed to have stolen '
'private keys, server data, and authentication logs from '
'Clop’s ransomware infrastructure, including IP addresses of '
'Clop members potentially exposing their identities. The '
'attack marks the latest escalation in a feud between the two '
'criminal groups over competing claims to a zero-day '
'vulnerability in Oracle E-Business Suite servers.',
'impact': {'brand_reputation_impact': 'Reputational damage to Clop ransomware '
'gang',
'data_compromised': 'Private keys, server data, authentication '
'logs, IP addresses of Clop members',
'identity_theft_risk': "High (exposure of Clop members' IP "
'addresses)',
'operational_impact': 'Defacement of Clop’s dark web site, '
"potential exposure of Clop members' "
'identities',
'systems_affected': 'Clop’s dark web data leak site, ransomware '
'infrastructure'},
'lessons_learned': 'The incident underscores the competitive and volatile '
'nature of cybercriminal ecosystems, where rival groups '
'operate as profit-driven enterprises and may turn on one '
'another in disputes.',
'motivation': 'Extortion, Rivalry, Financial Gain',
'post_incident_analysis': {'root_causes': 'Feud over competing claims to a '
'zero-day vulnerability '
'(CVE-2025-61882) in Oracle '
'E-Business Suite servers, '
'breakdown in trust between '
'criminal groups'},
'ransomware': {'data_exfiltration': 'Yes',
'ransom_demanded': 'Yes (unspecified amount)'},
'references': [{'source': 'Bleeping Computer'}],
'threat_actor': 'ShinyHunters',
'title': 'ShinyHunters Hacking Group Targets Clop Ransomware Gang in '
'High-Profile Cyber Feud',
'type': 'Cyber Extortion, Hacking, Data Theft'}