{
  "id": 8954184,
  "title": "Cybercrime civil war brewing? ShinyHunters reportedly hacks Cl0p ransomware gang and threatens further damage",
  "url": "https://urgent.news/2026/09/21/cybercrime-civil-war-brewing-shinyhunters-reportedly-hacks-cl0p",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-21T16:05:00.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/security/cybercrime-civil-war-brewing-shinyhunters-reportedly-hacks-cl0p-ransomware-gang-and-threatens-further-damage"
  },
  "original_language": "en",
  "account": "Cl0p, a notorious cybercriminal gang, has reportedly fallen victim to an attack by ShinyHunters, another infamous data leak collective. The attack has raised concerns about the potential escalation of a \"cyber war\" between criminal groups. ShinyHunters has stolen sensitive information from Cl0p, including source code, Grav CMS plugins, system logs, and onion service keys. The gang has also defaced Cl0p's website using a flaw in the Grav CMS, displaying their logo, taunts, and a message threatening further action. The stolen data includes system activity records, authentication logs, and IP addresses associated with connections to the server. ShinyHunters has given Cl0p 72 hours to pay a ransom or face having all their files leaked online. While it is uncertain whether this incident will lead to the identification of individual Cl0p members, the act of doxxing could potentially disrupt the group's infrastructure.",
  "summary": "Cl0p's website was defaced and its data stolen in attack.",
  "key_points": [
    "ShinyHunters allegedly hacked Cl0p ransomware gang.",
    "Attack exposed Cl0p's sensitive data and defaced website.",
    "Cl0p given 72 hours to pay ransom or face data leak."
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}