Breaches · 4h ago
ShinyHunters escalated its breach of Cl0p’s dark web leak site on September 18, turning a defacement into an extortion play that reportedly includes stolen private keys, server data, authentication logs, and an eight-figure demand. The messages on the site also named alleged Cl0p operators and said the price would rise if Cl0p did not engage.
The important part is what those records can prove. If the logs really show who connected to the site and the keys really control it, ShinyHunters could use them to tie operators and infrastructure to real activity and to release records showing which companies paid Cl0p, how much, and to what Bitcoin addresses.
For organizations that ever paid Cl0p, the exposure does not end with a defaced page. A leak site built to shame victims can also become evidence against the gang and a source of secondary pressure on the companies already named in its extortion campaigns.
4 sources covering this story
ShinyHunters Hacked Clop. Now What About Clop's Victims?
ShinyHunters breached rival ransomware gang Clop's leak site, threatening to expose victim payment data and raising concerns about secondary data exposure.
The Record from Recorded Future
ShinyHunters cybercrime gang takes over Cl0p ransomware site, demands extortion payment
The ShinyHunters extortion group hijacked the dark web leak site of the prolific Cl0p ransomware gang, according to material posted on the site over the weekend.
ShinyHunters Claim Hack of Rival Ransomware Gang Clop
ShinyHunters has claimed responsibility for hacking the Clop ransomware group, defacing its leak site and alleging theft of key operational data
ShinyHunters hacks Clop leak site, threatens to extort ransomware gang
The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation's data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service.
Part of the PlainSec briefing for 2026-09-21