Urgent.News

What's breaking now, across thousands of outlets.

Tech

Clop gets a taste of its own medicine after ShinyHunters hijack leak site

Rival crew demands eight figures and threatens to expose companies that paid to keep quiet

Clop gets a taste of its own medicine after ShinyHunters hijack leak site

Clop, a prominent data extortion group, has faced a backlash after rival crew ShinyHunters infiltrated its leak site and demanded a ransom. On September 19, Clop's dark web leak site was seized by ShinyHunters, who displayed a "DOMAIN SEIZED BY SHINYHUNTERS" banner and claimed control of Clop's infrastructure. ShinyHunters alleges that they discovered a zero-day vulnerability in the software powering Clop's leak site, which allowed them to access its systems.

The crew has demanded an eight-figure payment, representing 2.333 percent of their own net worth, and threatened to publish the names of companies that allegedly paid Clop. ShinyHunters has warned that its demands will increase daily if Clop fails to comply. The incident has tarnished Clop's reputation, as leak sites are meant to showcase an extortion group's stolen data and control.

ShinyHunters believes that having Clop's leak site hijacked is not embarrassing enough and has threatened to publish records of previous ransom payments. The dispute between the two cybercriminal groups began with Clop's attacks on Oracle E-Business Suite customers last year, where ShinyHunters claims they discovered a zero-day exploit first.

Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in Tech

Keep Free Lanes Off the Signed Webhook Path

The billing webhook stalled for forty-one silent seconds. The payment provider sent the same event again. A free-lane agent was still classifying intent. The worker then granted store credit twice.

  • Free lanes must not be on signed webhook paths
  • Duplicate deliveries discovered before dawn
  • Public endpoint on preemptible free server

More from Monday 21 September →