As cited
Copy frozen at (site build).
ransomware
Clop gets a taste of its own medicine after ShinyHunters hijack leak site
ShinyHunters hijacked Clop's dark web leak site on September 21, 2026, after exploiting a vulnerability in its underlying software, and demanded an eight-figure payment plus interest, claiming Clop had stolen and weaponized a zero-day exploit that ShinyHunters had originally discovered. The takeover displayed a defacement banner and ShinyHunters threatened to publish records of Clop's previous ransom payments and victim identities, with escalating demands every 24 hours of non-response. Clop, one of the most prolific data extortion groups responsible for campaigns including the 2023 MOVEit incident affecting millions, has not publicly responded to the takeover.
Why it matters: Organizations that previously paid Clop ransom should assess exposure if ShinyHunters makes good on threats to publish payment records and Bitcoin addresses, potentially linking their identities to extortion incidents they believed were confidential.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ransomware
Clop gets a taste of its own medicine after ShinyHunters hijack leak site
ShinyHunters hijacked Clop's dark web leak site on September 21, 2026, after exploiting a vulnerability in its underlying software, and demanded an eight-figure payment plus interest, claiming Clop had stolen and weaponized a zero-day exploit that ShinyHunters had originally discovered. The takeover displayed a defacement banner and ShinyHunters threatened to publish records of Clop's previous ransom payments and victim identities, with escalating demands every 24 hours of non-response. Clop, one of the most prolific data extortion groups responsible for campaigns including the 2023 MOVEit incident affecting millions, has not publicly responded to the takeover.
Why it matters: Organizations that previously paid Clop ransom should assess exposure if ShinyHunters makes good on threats to publish payment records and Bitcoin addresses, potentially linking their identities to extortion incidents they believed were confidential.
- Source published
- First seen by Cybersecurity Tracker