CYBERSECURITYTRACKER
TRACKING7,333 stories in this site build1,537 vulnerability news stories in this site build
Permanent story citation

Clop gets a taste of its own medicine after ShinyHunters hijack leak site

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8019

As cited

Copy frozen at (site build).

ransomware

Clop gets a taste of its own medicine after ShinyHunters hijack leak site

ShinyHunters hijacked Clop's dark web leak site on September 21, 2026, after exploiting a vulnerability in its underlying software, and demanded an eight-figure payment plus interest, claiming Clop had stolen and weaponized a zero-day exploit that ShinyHunters had originally discovered. The takeover displayed a defacement banner and ShinyHunters threatened to publish records of Clop's previous ransom payments and victim identities, with escalating demands every 24 hours of non-response. Clop, one of the most prolific data extortion groups responsible for campaigns including the 2023 MOVEit incident affecting millions, has not publicly responded to the takeover.

Why it matters: Organizations that previously paid Clop ransom should assess exposure if ShinyHunters makes good on threats to publish payment records and Bitcoin addresses, potentially linking their identities to extortion incidents they believed were confidential.

VendorsOracleProgress Software
Actorsclop
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

Clop gets a taste of its own medicine after ShinyHunters hijack leak site

ShinyHunters hijacked Clop's dark web leak site on September 21, 2026, after exploiting a vulnerability in its underlying software, and demanded an eight-figure payment plus interest, claiming Clop had stolen and weaponized a zero-day exploit that ShinyHunters had originally discovered. The takeover displayed a defacement banner and ShinyHunters threatened to publish records of Clop's previous ransom payments and victim identities, with escalating demands every 24 hours of non-response. Clop, one of the most prolific data extortion groups responsible for campaigns including the 2023 MOVEit incident affecting millions, has not publicly responded to the takeover.

Why it matters: Organizations that previously paid Clop ransom should assess exposure if ShinyHunters makes good on threats to publish payment records and Bitcoin addresses, potentially linking their identities to extortion incidents they believed were confidential.

VendorsOracleProgress Software
Actorsclop
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary