The hacking and extortion collective ShinyHunters has launched a cyber-attack against the Clop ransomware operation, a rival criminal organization, and is now demanding payment to avoid leaking stolen data. The breach came to light on the evening of September 18, when Clop's dark web data leak site was defaced with a message reading "THIS SITE HAS BEEN PWN3D BY SHINYHUNTERS" and the background replaced with ASCII artwork of a Pokémon. ShinyHunters asserted it had captured private keys and server data that power Clop's ransomware infrastructure, treating the criminal gang like any conventional victim by issuing a ransom demand.

ShinyHunters told Bleeping Computer, which first reported the gang-on-gang assault, that it had obtained files potentially containing activity records, authentication logs, and IP addresses of Clop operatives who accessed the service. Such information could be weaponized to unmask individual members of the Clop ransomware operation. When asked by the publication what it intended to do with its access to Clop's systems, the attacker responded, "going to extort them." The defaced Clop website also displayed a link directing visitors to ShinyHunters' own data leak platform.

The assault on Clop represents the most recent episode in an ongoing dispute between the two criminal extortion operations that started in 2025, according to the report. The conflict originated from conflicting assertions over who controlled vulnerabilities in Oracle E-Business Suite servers, including the zero-day CVE-2025-61882, which both groups exploited to extract data from targets in blackmail and extortion operations. "This is a useful reminder that cybercriminal groups are not a single, coordinated ecosystem; they are competitive businesses driven by trust, reputation and money," said Javvad Malik, lead CISO advisor at KnowBe4. "When relationships are built on deception and fear, double-crossing and betrayal is always a credible threat."

ShinyHunters has emerged as one of 2026's most active cyber extortion collectives, with major campaigns targeting users of widely adopted software-as-a-service platforms such as Salesforce Experience Cloud and Canvas Learning Management System. The group also recently claimed responsibility for breaching American healthcare giant McKesson, which distributes wholesale medical supplies and pharmaceuticals to more than 40,000 corporate and institutional clients. Meanwhile, the Clop ransomware operation has operated since 2019 and executed numerous high-profile attacks, including a December 2025 ransomware assault and data breach at the University of Phoenix that impacted nearly 3.5 million individuals. Clop also orchestrated several ransomware strikes against prominent corporations in 2023 by weaponizing a security flaw in MOVEit Transfer and MoveIT Cloud. For security professionals, the incident highlights how understanding the motivations and conduct of threat actors—not just their technical capabilities—remains essential for defense planning. Organizations may find themselves inadvertently benefiting when criminal groups turn on each other, though relying on infighting among adversaries is no substitute for robust protective measures.