ShinyHunters allegedly launches Cyber Attack on Clop Ransomware Group leading to Data Theft

In an unusual development within the cybercrime ecosystem, members of the ShinyHunters ransomware group have allegedly launched a cyberattack against the Tor-based leak website operated by the Clop ransomware group. The incident appears to represent an uncommon case of one cybercriminal operation directly targeting another, with the attackers reportedly attempting to steal sensitive information and disrupt Clop’s infrastructure.

According to preliminary findings, ShinyHunters appears to have gained unauthorized access to parts of Clop’s infrastructure and subsequently defaced the ransomware group’s leak website. The compromised website was reportedly modified to display messages and branding associated with ShinyHunters, effectively replacing Clop’s original content with the attackers’ own statements.

The incident reportedly went beyond simple website defacement. Initial information suggests that ShinyHunters may have obtained a substantial amount of data associated with Clop’s operations, including source code, system logs, plugins, and Tor service keys. If confirmed, the theft of such information could provide valuable insight into the technical infrastructure and operational methods used by the ransomware group.

ShinyHunters also reportedly issued an extortion demand against Clop, giving the group a 72-hour deadline to respond. The ransom demand is believed to have been in the double-digit millions of dollars, adding another layer to what appears to be an ongoing dispute between the two cybercriminal organizations.

The alleged attack is reportedly connected to disagreements surrounding the theft and handling of data from Oracle E-Business Suite environments. Both ShinyHunters and Clop have been associated with high-profile data theft campaigns, making competition and disputes over compromised information particularly significant. In this case, the conflict appears to have escalated from a disagreement over stolen data into a direct attack on another ransomware group’s infrastructure.

The incident highlights an unusual aspect of the modern ransomware landscape: cybercriminal groups are not always operating independently or cooperating with one another. Rivalry over victims, stolen data, access, and financial gains can create conflicts even among criminal organizations. Such disputes can potentially expose infrastructure and operational information that would otherwise remain hidden from security researchers and law enforcement.

At the same time, the reported compromise of Clop’s Tor infrastructure could have wider implications if the stolen material includes authentic operational credentials or cryptographic keys. Security researchers may be able to use such information to better understand the group’s infrastructure, while law enforcement could potentially gain additional intelligence regarding its activities.

However, the full extent of the compromise and the authenticity of the stolen information remain to be independently established. Details circulating about the incident should therefore be treated as preliminary until they can be corroborated through additional technical evidence.

If confirmed, the incident would stand out as a rare example of a ransomware group turning its capabilities against another member of the cybercrime ecosystem, demonstrating that the increasingly sophisticated ransomware underground can be as competitive and adversarial internally as it is toward its victims. 

Join our LinkedIn group Information Security Community!

Naveen Goud
Naveen Goud is a writer at Cybersecurity Insiders covering topics such as Mergers & Acquisitions, Startups, Cyber Attacks, Cloud Security and Mobile Security

No posts to display