Ransomware is a business with one thing to sell, and that thing is silence. A company pays, and the gang holding its files promises not to publish them. Over the weekend the gang that has collected more of those promises than almost any other lost control of the website it publishes on.
ShinyHunters, an extortion crew, told Reuters it broke into Clop's dark web site on Friday after finding a hole in the gang's own software. BleepingComputer has the detail: an unauthenticated file upload flaw in Grav CMS, the content system running the leak site, used to drop a small text file onto Clop's server. The file told Clop not to try threatening them next time. The site itself came back as a page of ASCII art of Umbreon, the Pokemon ShinyHunters uses as a logo, over the line “rooting your systems since '19”.
What is confirmed, and what is only claimed
BleepingComputer downloaded that file from Clop's own Tor site and saw the defaced page for itself. Nothing beyond those two things has been confirmed by anyone outside ShinyHunters. The group says it took server logs, source code and the private keys to Clop's onion address, and told BleepingComputer that holding those keys means being kicked out would not matter, because it could host the same address itself. It plans to post a message on its own leak site giving Clop 72 hours to make contact. “We basically own them now,” it told Reuters.
Where the grudge started
Both sides trace the fight to one campaign. In October 2025 Clop exploited flaws in Oracle's E-Business Suite software, including a zero-day tracked as CVE-2025-61882, and used them to take data it could then extort companies over. A zero-day is a flaw the defenders have had no days to fix, which is what makes one worth stealing. ShinyHunters says it found that one first, and a group including it leaked a proof-of-concept exploit that Oracle later confirmed matched the one used in Clop's attacks. Clop got data from more than 100 companies out of the campaign, on a Google analyst's estimate.
Clop is not a small operator. Its 2023 attack on the MOVEit file management software took data on tens of millions of people from more than 600 companies, and last month it claimed large volumes from nearly 50 more, Philips, Shell, Fiserv and GE among them. As the argument ran on, it threatened to name several ShinyHunters members, and ShinyHunters threatened to publish how Clop works.
“It is rare I get to see these criminals fight each other,” Joe Roosen, senior director of security research at SpyCloud, told Reuters. Clop has answered neither outlet. Reuters found the site unreachable on Sunday, a day after a screenshot kept by the research platform eCrime.ch showed it reading “Domain Seized By ShinyHunters”. That is the counterparty on the other end of a ransom negotiation: a firm with rivals, grudges and software of its own left unpatched.