ShinyHunters hijacks Cl0p's leak site and demands an eight-figure payment
The group is threatening to expose Cl0p's payment records, including the companies that paid and the Bitcoin addresses used.
By Ryan Merket · Published
Primary source: Recorded Future News
Why it matters
The hijack exposes the fragility of criminal leak-site infrastructure, while the threatened release of payment records creates a second breach risk for Cl0p victims.

ShinyHunters hijacked Cl0p's Tor-based leak site over the weekend and repurposed the ransomware gang's publishing infrastructure for an extortion demand against Cl0p itself, according to Recorded Future News.
The site, which Cl0p has used to identify victims and pressure them into paying, displayed a banner saying the domain had been seized by ShinyHunters. The rival group demanded an unspecified eight-figure payment, threatened to increase the price every 24 hours and later added a public apology to its terms.
The intrusion began late Friday when ShinyHunters exploited what it described as an unauthenticated file-upload flaw in Grav CMS, the software running Cl0p's site. BleepingComputer independently confirmed that ShinyHunters uploaded a file to Cl0p's server and subsequently replaced the site with its own page.
ShinyHunters also claims it obtained Cl0p's source code, server logs, CMS plugins and the private keys for its Tor onion service. Those claims have not been independently verified. Valid onion keys would allow ShinyHunters to operate another server at Cl0p's existing Tor address, extending the compromise beyond the original web server.
An extortion site changes hands
ShinyHunters described its initial demand as 2.333% of its own claimed net worth and said the resulting amount reached eight figures. Neither the group's claimed holdings nor the requested payment can be independently confirmed.
The demand later expanded to include proceeds from Cl0p's 2025 campaign against Oracle E-Business Suite customers. ShinyHunters threatened to publish the names of companies that paid Cl0p, the amounts they paid and the Bitcoin addresses that received the funds.
By Monday, September 21st, the defacement had been replaced with a message apparently written by Cl0p. The message said Cl0p was trying to make contact and that the email address supplied by ShinyHunters did not work. The sequence leaves control of the onion address uncertain, even as ShinyHunters claims it possesses the keys required to retain it.
The threatened disclosure creates a separate problem for organizations that negotiated with Cl0p. Companies sometimes pay cybercriminals in an attempt to prevent publication of stolen data. If ShinyHunters obtained authentic payment records, those transactions and negotiations could now become material for another extortion campaign. ShinyHunters has not published evidence establishing that it holds those records.
The Oracle dispute behind the attack
ShinyHunters says the feud began during Cl0p's 2025 attacks on Oracle E-Business Suite customers. The group claims it discovered an exploit that Cl0p later used without authorization and says a Cl0p representative subsequently threatened one of its members.
The attribution is less settled than ShinyHunters' account suggests. Google's Threat Intelligence Group and Mandiant tracked a large Cl0p-branded extortion campaign beginning on September 29th, 2025, after finding evidence of intrusions dating to July and August. Google's researchers said they did not assess that actors associated with ShinyHunters were involved in the early exploitation activity.
ShinyHunters and affiliated actors publicly released an exploit in October 2025. Oracle's security advisory included hashes associated with that code among its indicators of compromise for CVE-2025-61882, a critical Oracle E-Business Suite vulnerability that enabled remote code execution without authentication.
The technical record remained muddy after disclosure. VulnCheck's 2026 exploit report said researchers reproduced the ShinyHunters exploit and found behavior matching Oracle's indicators, while concluding that the leaked code likely mapped more closely to a second flaw, CVE-2025-61884. That uncertainty leaves ShinyHunters' claim of ownership over the exploit unproven.
Cl0p built its business around finding or acquiring vulnerabilities in widely deployed enterprise software, stealing data at scale and using its leak site as the enforcement mechanism. ShinyHunters' takeover targeted that mechanism directly. The verified damage so far is the defacement and loss of control over published content. The larger risk depends on whether ShinyHunters' claims about server logs, onion keys and ransom-payment records are genuine.