News

ShinyHunters Just Hijacked Cl0p’s Dark Web Site. Here’s the Beef Behind It.

ShinyHunters Just Hijacked Cl0p's Dark Web Site

When criminals fall out, they don’t call lawyers. They go after each other’s infrastructure.

On September 19, 2026, ShinyHunters, one of the most active data extortion groups operating today, claimed to have seized cl0p’s dark web site, a Russian-speaking cybercrime gang with a long track record of large-scale enterprise software exploitation.

By Sunday the 20th, cl0p’s site was unreachable. A screenshot preserved by cybercrime research platform eCrime.ch showed cl0p’s page displaying three words: “Domain Seized By ShinyHunters.”

ShinyHunters confirmed the action to Reuters in an online chat. “We basically own them now,” the group said.

Cl0p did not respond to requests for comment. Two independent cybersecurity researchers told Reuters the confrontation appeared genuine.

What Started the Fight

According to ShinyHunters, the dispute traces back to a software vulnerability, specifically, a zero-day in Oracle’s E-Business Suite (EBS), the enterprise platform used by large companies globally for finance, HR, and operations.

A “zero-day” is a vulnerability the software vendor doesn’t know about yet, meaning there have been zero days to patch it. These exploits are among the most valuable tools in a criminal hacker’s arsenal because they grant access before any defence exists.

ShinyHunters claims it discovered the Oracle EBS flaw first. Cl0p allegedly obtained it and used it without permission. A Google analyst estimated cl0p leveraged the vulnerability to steal data from more than 100 companies.

The dispute quietly festered. Cl0p allegedly threatened to reveal the identities of ShinyHunters members, a serious threat in criminal communities where anonymity is everything. ShinyHunters countered by threatening to expose cl0p’s internal operations. When ShinyHunters eventually found a vulnerability in cl0p’s own infrastructure, they didn’t just threaten. They used it.

Who These Groups Are

Both parties here have documented, significant track records, not hypothetical threats or minor actors.

Cl0p is considered one of the most technically sophisticated ransomware-adjacent groups operating. Their signature move is finding critical vulnerabilities in widely used enterprise software and exploiting them at scale. In 2023, they leveraged a flaw in MOVEit file transfer software to steal data on tens of millions of people from over 600 organisations simultaneously, the same MOVEit incident that touched CenterPoint Energy among many others. Just last month, cl0p claimed to have exfiltrated data from nearly 50 companies including Philips, Shell, Fiserv, and GE.

ShinyHunters has been equally active. In April 2026, they claimed millions of business records from Rockstar Games, the developer of Grand Theft Auto. In May, a hack connected to them disrupted Canvas, an education platform used across US schools. In August, they posted claims about Streamlabs, the streaming software used by millions of Twitch creators we covered in our Twitch data leak piece. And in September, Anthropic’s threat intelligence report explicitly flagged ShinyHunters-linked actors trying to misuse Claude.

These are not small operations.

What “Seizing” a Dark Web Site Actually Means

The hijack isn’t simply defacement. ShinyHunters says it found a vulnerability in cl0p’s software and used it to gain “wide-ranging control” over the group’s infrastructure. That means more than just changing the landing page.

Controlling a rival’s dark web infrastructure could mean access to their operator communications, victim negotiation logs, cryptocurrency wallet addresses, and internal tools. Joe Roosen, senior director of security research at SpyCloud, told Reuters this kind of move is genuinely unusual: “I rarely get to see these criminals fight each other.” Brandon Parsons, a threat intelligence manager at Ascent Solutions, was more blunt: “Street beefs on the dark web are a real thing.”

The public nature of the move is what makes it significant. Criminal groups typically handle disputes through internal channels or by quietly withdrawing. Publicly defacing a rival’s infrastructure and speaking to reporters about it is a deliberate escalation, designed to humiliate and undermine cl0p’s credibility with potential ransomware victims and criminal clients alike.

Why Law Enforcement Might Be Quietly Pleased

A practical observation in this story deserves attention.

When criminal groups publicly feud, they leak information about each other. ShinyHunters’ account of how cl0p obtained the Oracle zero-day, what companies it hit, and how cl0p’s internal operations work is more detailed than prosecutors typically get through conventional investigation.

The same dynamic surfaced in the Ransom Cartel case we covered: criminal infrastructures depend on internal trust, and when that breaks down, the resulting exposure often travels in multiple directions at once.

Neither group has released internal documents from the other publicly yet. Whether this feud stays contained or continues to produce leaks that reach researchers and law enforcement remains the story to watch.

Frequently Asked Questions

What happened between ShinyHunters and cl0p?

ShinyHunters exploited a vulnerability in cl0p’s software on September 19, 2026, gaining control over their dark web infrastructure and displaying a seizure notice on cl0p’s site.

What caused the feud?

ShinyHunters accuses cl0p of stealing a zero-day exploit targeting Oracle’s E-Business Suite that ShinyHunters claims to have discovered first. Cl0p used it to breach 100+ companies.

Is this confirmed?

Two independent security researchers told Reuters the confrontation appeared genuine. Reuters could not independently verify ShinyHunters’ account of the original dispute.

Has cl0p responded?

No. Cl0p did not respond to repeated requests for comment.

Written by Muhammad Anas

Contributing writer at DarkWebDecoded.com covering dark web security, scam alerts, and privacy tools.

📋 Latest Articles

View all →
How to Use Ahmia Search Engine
Guides

How to Use Ahmia Search Engine: A Safe, Step-by-Step Guide

Most search engines can’t see the Tor network at all. Google doesn’t index .onion sites, and neither does…

Sep 21, 2026
7 min read
Telegram Credential Leak Channels
Data Breaches

Top 5 Telegram Credential Leak Channels: How Stolen Logins Are Traded

Telegram is no longer just a messaging app for chatting and sharing files. Security researchers have found that…

Sep 18, 2026
5 min read
dark web fraud intelligence banking
News

Nasdaq Verafin and Q6 Cyber Are Watching the Dark Web So Your Bank Doesn’t Have to Wait

Nasdaq Verafin partnered with Q6 Cyber on August 27, 2026, to feed dark web intelligence on stolen checks,…

Sep 17, 2026
8 min read
CenterPoint Energy Data Breach
News

CenterPoint Energy Data Breach: 7.49 Million Records Posted on the Dark Web

CenterPoint Energy confirmed a data breach in an SEC Form 8-K filing on September 15, 2026, after a…

Sep 17, 2026
8 min read
Gabbie Gonzalez Pleads Not Guilty in Dark Web Murder Plot Against Jack Avery
News

Gabbie Gonzalez Pleads Not Guilty in Dark Web Murder Plot Against Jack Avery

TikTok influencer Gabbie Gonzalez, her father Francisco Gonzalez, and her ex-boyfriend Kai Cordrey all pleaded not guilty on…

Sep 17, 2026
7 min read
Dark Web Intelligence Market
News

The Dark Web Intelligence Market Is Growing at 21% Per Year. Here’s Why.

The dark web intelligence market, estimated at $0.92 billion in 2026 by The Business Research Company, is projected…

Sep 16, 2026
11 min read
0 0 votes
Article Rating
Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted