Skip to content

Cybercrime Feud Erupts on Dark Web as ShinyHunters Claims It Hijacked Rival Gang cl0p’s Site

Getting your Trinity Audio player ready...

Cybercrime Feud Erupts on Dark Web as ShinyHunters Claims It Hijacked Rival Gang cl0p’s Site

A rare public spectacle has been playing out in the usually secretive world of ransomware gangs and data extortion groups over the weekend, after one of the internet’s most notorious cybercrime outfits claimed it had broken into and seized control of a rival gang’s dark web infrastructure, turning what had reportedly been a quiet, long-simmering rivalry into an open confrontation.

ShinyHunters, a digital extortion group known for aggressive, large-scale data theft campaigns, told Reuters it broke into the dark web site belonging to cl0p, a prolific Russian-speaking cybercrime gang, on Friday. According to ShinyHunters, the group discovered a vulnerability in cl0p’s own software and used it to gain wide-ranging control over the rival gang’s infrastructure. In an online chat with Reuters, the group put it bluntly: they said they basically owned cl0p now. When Reuters tried to visit cl0p’s dark web site on Sunday, it was unreachable. A day earlier, according to a screenshot preserved by cybercrime research platform eCrime.ch, the site displayed a blunt message of its own: “Domain Seized By ShinyHunters.” Cl0p did not respond to repeated requests for comment from Reuters.

The dispute reportedly traces back to a shared prize both groups apparently wanted credit for. Cl0p had used a vulnerability in Oracle’s E-Business Suite software to steal data from what a Google threat analyst estimated was more than 100 companies. ShinyHunters, however, told Reuters it had actually discovered that same zero-day vulnerability first, a claim that, if true, would mean cl0p essentially beat its rival to exploiting a flaw ShinyHunters believed it found on its own. That disagreement over credit apparently festered into something more serious. According to ShinyHunters, cl0p threatened to expose the identities of several of its members in response to the dispute, and ShinyHunters says it fired back with its own threat to reveal details of cl0p’s internal operations. Reuters noted it could not independently verify ShinyHunters’ account of exactly how the feud escalated, since almost everything known about the situation currently comes from one side of the conflict.

Real More:  Why older tech is sometimes safer from hackers

Two cybersecurity researchers who spoke about the incident said the clash appeared to be genuine rather than some kind of elaborate hoax or publicity stunt. Joe Roosen, senior director of security research at SpyCloud, said it’s rare to actually witness cybercriminal groups turn on each other this openly, calling the situation a real twist. Separately, Brandon Parsons, a threat intelligence manager at Ascent Solutions, noted that rivalries and outright conflicts between dark web groups, sometimes referred to informally as street beefs, are a real and recurring phenomenon in this world, even if they rarely spill out into public view the way this one has.

Understanding why this particular spat is drawing attention requires knowing who’s actually involved. Cl0p ranks among the most prolific and technically sophisticated cybercrime groups currently operating, built largely around its skill at finding and exploiting vulnerabilities in enterprise software used by large organizations. Its most infamous campaign came in 2023, when it exploited a flaw in the widely used MOVEit file transfer software to steal data belonging to tens of millions of people across more than 600 companies, one of the largest mass-exploitation campaigns in recent memory. Just last month, cl0p claimed to have stolen large volumes of data from nearly 50 companies worldwide through the Oracle E-Business Suite vulnerability at the center of this current dispute, with victims reportedly including Philips, Shell, Fiserv and GE.

Real More:  Boston Scientific Says Cyberattack Likely to Hurt 2026 Sales, Profit as Company Now Expects to Miss Full-Year Guidance

ShinyHunters operates on a similarly aggressive scale. The group claimed responsibility in April for stealing millions of business records from Rockstar Games, the studio behind the Grand Theft Auto franchise, and was linked in May to a hack centered on the education platform Canvas that disrupted operations at schools across the United States. Both groups, in other words, are established, high-profile players within the cybercrime ecosystem rather than fringe operations, which is part of what makes a public feud between them notable to researchers who track this space closely.

It’s worth putting this incident in the context of how dark web criminal infrastructure typically meets its end. Historically, when a major cybercrime forum or gang’s site goes dark or gets seized, it’s almost always the result of coordinated law enforcement action, the kind of takedown that agencies like the FBI have carried out repeatedly against forums including BreachForums and RAMP in recent years, often accompanied by official seizure notices and, occasionally, a bit of pointed trolling aimed at the forum’s operators. A rival criminal group claiming credit for taking down another gang’s infrastructure, rather than a government agency, is a genuinely unusual variation on that pattern, and it raises questions about how much operational security even sophisticated, experienced cybercrime groups actually maintain against each other, separate from whatever defenses they’ve built against law enforcement and corporate security teams.

Real More:  Global Ransomware Attack Update: Hospitals and Energy Giants Hit in Coordinated 2026 Cyber Offensive

Whether this feud produces any further public escalation, including the kind of identity exposures both sides have reportedly threatened, remains to be seen. For now, what’s confirmed is limited to what ShinyHunters itself has told Reuters and the visual evidence of cl0p’s inaccessible site, leaving outside observers to watch and wait to see whether one of the cybercrime underworld’s most closely guarded rivalries stays contained to threats, or turns into the kind of mutual exposure that neither group would typically want directed at itself.

Leave a Comment