When criminals fall out, they don’t call lawyers. They go after each other’s infrastructure.
On September 19, 2026, ShinyHunters, one of the most active data extortion groups operating today, claimed to have seized cl0p’s dark web site, a Russian-speaking cybercrime gang with a long track record of large-scale enterprise software exploitation.
By Sunday the 20th, cl0p’s site was unreachable. A screenshot preserved by cybercrime research platform eCrime.ch showed cl0p’s page displaying three words: “Domain Seized By ShinyHunters.”
ShinyHunters confirmed the action to Reuters in an online chat. “We basically own them now,” the group said.
Cl0p did not respond to requests for comment. Two independent cybersecurity researchers told Reuters the confrontation appeared genuine.
What Started the Fight
According to ShinyHunters, the dispute traces back to a software vulnerability, specifically, a zero-day in Oracle’s E-Business Suite (EBS), the enterprise platform used by large companies globally for finance, HR, and operations.
A “zero-day” is a vulnerability the software vendor doesn’t know about yet, meaning there have been zero days to patch it. These exploits are among the most valuable tools in a criminal hacker’s arsenal because they grant access before any defence exists.
ShinyHunters claims it discovered the Oracle EBS flaw first. Cl0p allegedly obtained it and used it without permission. A Google analyst estimated cl0p leveraged the vulnerability to steal data from more than 100 companies.
The dispute quietly festered. Cl0p allegedly threatened to reveal the identities of ShinyHunters members, a serious threat in criminal communities where anonymity is everything. ShinyHunters countered by threatening to expose cl0p’s internal operations. When ShinyHunters eventually found a vulnerability in cl0p’s own infrastructure, they didn’t just threaten. They used it.
Who These Groups Are
Both parties here have documented, significant track records, not hypothetical threats or minor actors.
Cl0p is considered one of the most technically sophisticated ransomware-adjacent groups operating. Their signature move is finding critical vulnerabilities in widely used enterprise software and exploiting them at scale. In 2023, they leveraged a flaw in MOVEit file transfer software to steal data on tens of millions of people from over 600 organisations simultaneously, the same MOVEit incident that touched CenterPoint Energy among many others. Just last month, cl0p claimed to have exfiltrated data from nearly 50 companies including Philips, Shell, Fiserv, and GE.
ShinyHunters has been equally active. In April 2026, they claimed millions of business records from Rockstar Games, the developer of Grand Theft Auto. In May, a hack connected to them disrupted Canvas, an education platform used across US schools. In August, they posted claims about Streamlabs, the streaming software used by millions of Twitch creators we covered in our Twitch data leak piece. And in September, Anthropic’s threat intelligence report explicitly flagged ShinyHunters-linked actors trying to misuse Claude.
These are not small operations.
What “Seizing” a Dark Web Site Actually Means
The hijack isn’t simply defacement. ShinyHunters says it found a vulnerability in cl0p’s software and used it to gain “wide-ranging control” over the group’s infrastructure. That means more than just changing the landing page.
Controlling a rival’s dark web infrastructure could mean access to their operator communications, victim negotiation logs, cryptocurrency wallet addresses, and internal tools. Joe Roosen, senior director of security research at SpyCloud, told Reuters this kind of move is genuinely unusual: “I rarely get to see these criminals fight each other.” Brandon Parsons, a threat intelligence manager at Ascent Solutions, was more blunt: “Street beefs on the dark web are a real thing.”
The public nature of the move is what makes it significant. Criminal groups typically handle disputes through internal channels or by quietly withdrawing. Publicly defacing a rival’s infrastructure and speaking to reporters about it is a deliberate escalation, designed to humiliate and undermine cl0p’s credibility with potential ransomware victims and criminal clients alike.
Why Law Enforcement Might Be Quietly Pleased
A practical observation in this story deserves attention.
When criminal groups publicly feud, they leak information about each other. ShinyHunters’ account of how cl0p obtained the Oracle zero-day, what companies it hit, and how cl0p’s internal operations work is more detailed than prosecutors typically get through conventional investigation.
The same dynamic surfaced in the Ransom Cartel case we covered: criminal infrastructures depend on internal trust, and when that breaks down, the resulting exposure often travels in multiple directions at once.
Neither group has released internal documents from the other publicly yet. Whether this feud stays contained or continues to produce leaks that reach researchers and law enforcement remains the story to watch.
Frequently Asked Questions
What happened between ShinyHunters and cl0p?
ShinyHunters exploited a vulnerability in cl0p’s software on September 19, 2026, gaining control over their dark web infrastructure and displaying a seizure notice on cl0p’s site.
What caused the feud?
ShinyHunters accuses cl0p of stealing a zero-day exploit targeting Oracle’s E-Business Suite that ShinyHunters claims to have discovered first. Cl0p used it to breach 100+ companies.
Is this confirmed?
Two independent security researchers told Reuters the confrontation appeared genuine. Reuters could not independently verify ShinyHunters’ account of the original dispute.
Has cl0p responded?
No. Cl0p did not respond to repeated requests for comment.