All Posts
No items found.
1
min read

When Criminals Hack Criminals: ShinyHunters' Breach of Clop and What It Reveals About the Ransomware Underground

Published on
September 23, 2026
Table of Contents

ShinyHunters breaching Clop's dark web infrastructure has exposed a trust model that has been degrading across the Ransomware-as-a-Service (RaaS) ecosystem for years. The criminal organizations demanding operational security from their victims cannot maintain it themselves. For security teams, the breach creates a second-order problem: organizations that previously paid Clop a ransom may now face exposure from a different adversary holding their negotiation records.

Clop is not a minor player. Clop has been active since 2019 and built one of the ransomware ecosystem's most mature and repeatable mass-exploitation playbooks [1]. In January 2023, the group exploited CVE-2023-0669, a zero-day in GoAnywhere MFT, compromising approximately 130 victims over 10 days through data exfiltration with no lateral movement required beyond the platform itself [2]. Later that year, Clop exploited CVE-2023-34362 in MOVEit Transfer, a campaign that drew a CISA advisory and affected organizations globally [2]. More recently, Clop conducted a ransomware attack and data breach against the University of Phoenix in December 2025, affecting nearly 3.5 million people [1]. This is a group with a documented track record of high-volume, zero-day-enabled data theft. That track record is now precisely what makes the exposure of its internal data consequential.

On the evening of September 18, 2026, ShinyHunters defaced Clop's Tor data leak site, replacing it with the group's signature Umbreon ASCII artwork and the message "THIS SITE HAS BEEN PWN3D BY SHINYHUNTERS" [3]. The entry point was an unauthenticated file upload vulnerability in Grav CMS [3]. The technique appears consistent with CVE-2024-27921, a previously disclosed file-upload path traversal vulnerability in Grav, although the specific CVE used in the Clop compromise has not been publicly confirmed [4]. Security research into that vulnerability class reveals important context: CVE-2024-27921 alone produces limited impact, but chained with CVE-2024-34082 (a Server-Side Template Injection flaw enabling account takeover), password reset poisoning via a manipulated HTTP Host header, and abuse of Grav's built-in Scheduler feature, an unauthenticated attacker can achieve full remote code execution on the server [4]. Grav stores all credentials and password reset tokens in flat YAML files with no database backend, so file-read access translates directly to account takeover without cracking a single password [4]. Clop was running its extortion infrastructure on this stack, unpatched, publicly exposed.

ShinyHunters claims to have taken source code, system logs, Grav CMS plugins, and the private keys for Clop's Tor onion service [3]. If the onion private keys are valid, ShinyHunters could operate a site at Clop's existing .onion address from servers they control, enabling impersonation of Clop's negotiation infrastructure [3]. BleepingComputer confirmed the defacement and the uploaded file independently but could not verify the data theft claims [3]. ShinyHunters gave Clop 72 hours to make contact before threatening to publish what they took on their own leak site [3]. The stolen system logs from /var/log could potentially expose IP addresses of individuals who connected to Clop's infrastructure [3] — information with obvious value to law enforcement and rival groups alike.

ShinyHunters is not an unsophisticated actor stumbling into criminal targets. The group exploited a Snowflake contractor's compromised machine to access approximately 165 Snowflake customer accounts including Ticketmaster and Santander, using credentials stolen by infostealer malware, some dating to 2020 [5]. A subsequent supply-chain attack via stolen OAuth tokens cascaded a single Salesloft Drift token compromise to roughly 760 downstream Salesforce customer organizations [6]. The group exploited Oracle PeopleSoft zero-day CVE-2026-35273, a 9.8 CVSS-scored remote code execution flaw, against over 100 organizations across approximately 300 instances [6]. Their recruitment infrastructure actively solicits insider access across finance, insurance, aviation, and telecom sectors [6]. This is a threat actor that selects targets methodically and maintains multi-vector capability. Clop's leak site was not an accidental find — it was a deliberate choice, preceded by a feud originating in 2025 over disputed ownership of a zero-day exploit used in Clop's Oracle E-Business Suite campaign [1], [3].

The breach fits a pattern that predates this incident by years. Threat intelligence analysis documents the accelerating fragmentation of RaaS trust structures through direct forum evidence [7]:

  • ALPHV defrauded affiliate "notchy" of their share of a $22 million ransom paid by a US healthcare provider, then staged a fabricated law enforcement takedown notice to cover their exit [7].
  • LockBit failed to pay affiliate "michon" $4 million for corporate network access, resulting in LockBit being banned from the XSS and Exploit underground forums [7].
  • DragonForce hacked Blacklock/Mamona R.I.P.'s Tor infrastructure, defaced their sites, and published stolen configuration files before launching a cartel model requiring new affiliates to either produce a referral or post a $10,000 deposit [7].

These are not isolated disputes. They are the operational behavior of an ecosystem where contractual enforcement does not exist and reputation is the only collateral.

The RaaS economic model creates the conditions for this instability. Affiliates typically retain 60–80% of ransom payments under standard program terms [8]. Volume-based extortion economics mean operators accept a fractional success rate across a large victim pool as sufficient for profitability [9]. That model requires stable partnerships at scale. When trust degrades, affiliates defect, transfer victim data between programs, and expose their former operators to multi-party extortion [7]. Ransomware brands have become disposable, with significant churn in active families from month to month [10]. The surface appearance of organized criminal enterprises conceals what is structurally a coalition of freelancers who defect the moment incentives shift.

What this means for organizations previously victimized by Clop requires direct analysis. Clop's operational model was data-first: exfiltrate, threaten publication, negotiate, collect. That process generated records. Victim lists, negotiation transcripts, payment confirmation logs, and communications tied to specific organizations all likely existed on the infrastructure ShinyHunters claims to have accessed. If ShinyHunters' data theft claims are accurate, even partially, any organization that paid Clop a ransom and trusted that the data was deleted is now in an uncertain position. The threat actor holding that data has demonstrated willingness to extort the original holder. The downstream question is whether they will engage previously victimized organizations directly, sell the records, or publish them.

Clop's infrastructure failure is also an operational security indictment. The group exploited enterprise-grade file transfer platforms by chaining zero-days, then ran its own command-and-control and extortion infrastructure on an unpatched commodity CMS with publicly documented unauthenticated file upload vulnerabilities [3], [4]. CVE-2024-27921 was patched in Grav version 1.7.45 [4]. Running a Tor-hosted extortion site on unpatched Grav is not sophisticated tradecraft — it reflects the same operational complacency that sustained impunity tends to produce. When prosecution risk is low and revenue is reliable, patch cadence and infrastructure hygiene receive less attention than the next campaign.

The synthesis across these data points is uncomfortable but precise. Criminal-on-criminal attacks are not a self-correcting mechanism that benefits defenders. They generate a secondary exposure layer for organizations that believed their ransomware incident was closed. They surface operational data that may be monetized in unpredictable directions. And they demonstrate that the RaaS trust model is not merely strained — it is producing adversarial relationships between the same actors simultaneously running active victim extortion campaigns. The organizations most exposed today are not the ones that refused to pay Clop. They are the ones that did.

References

  1. D. Palmer, "ShinyHunters Claim Hack of Rival Ransomware Gang Clop," Infosecurity Magazine, 21-Sep-2026. [Online]. Available: https://www.infosecurity-magazine.com/news/shinyhunters-claim-hack-of-clop/ [Accessed 22 Sep. 2026].
  2. CISA, "#StopRansomware: CL0P Ransomware Gang Exploits CVE-2023-34362 MOVEit Vulnerability," CISA, 2023. [Online]. Available: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-158a [Accessed 2026-04-20].
  3. BleepingComputer, "ShinyHunters hacks Clop leak site, threatens to extort ransomware gang," BleepingComputer, 2026-09-19. [Online]. Available: https://www.bleepingcomputer.com/news/security/shinyhunters-hacks-clop-leak-site-threatens-to-extort-ransomware-gang/ [Accessed 22 Sep. 2026].
  4. R. Ghimire, "Grav-ity of the situation: Unauthenticated Access to RCE in Grav CMS," TantoSec, 09-Oct-2024. [Online]. Available: https://tantosec.com/blog/grav/ [Accessed 22 Sep. 2026].
  5. WIRED, "Hackers Detail How They Allegedly Breached Ticketmaster via Snowflake Contractor EPAM Systems," WIRED, 2024-06-17. [Online]. Available: https://www.wired.com/story/epam-snowflake-ticketmaster-breach-shinyhunters/ [Accessed 22 Sep. 2026].
  6. Picus Security, "The ShinyHunters Domino Effect: One Breach, Hundreds of Victims," 2026-06-24. [Online]. Available: https://www.picussecurity.com/resource/blog/the-shinyhunters-domino-effect-one-breach-hundreds-of-victims [Accessed 22 Sep. 2026].
  7. J. Fokker and J. Tologonov, "Gang Wars: Breaking Trust Among Cyber Criminals," Trellix, 2025. [Online]. Available: https://www.trellix.com/blogs/research/gang-wars-breaking-trust-among-cyber-criminals/ [Accessed 22 Sep. 2026].
  8. T. Seals, "Ransomware Underground Economy: Trust Hierarchy and Criminal Marketplace Dynamics," Threatpost, May 26, 2021. [Online]. Available: https://threatpost.com/inside-ransomware-economy/166471/ [Accessed 22 Sep. 2026].
  9. J. MacColl, "Ransomware Economics and Criminal Monetization of Personal Data [Web page]," Royal United Services Institute (RUSI), 2024. [Online]. Available: https://rusi.org [Accessed 22 Sep. 2026].
  10. Halcyon, "Ransomware Affiliate Defection Data Leak Internal Betrayal Underground," Halcyon, UNKNOWN. [Online]. Available: https://www.halcyon.ai/blog/ransomware-tmz-more-than-a-year-of-leaks-lies-and-betrayals [Accessed 22 Sep. 2026].

How Anomali Can Help

The ShinyHunters breach of Clop exposes dark web actor intelligence gaps that ThreatStream Feeds and Anomali Vulnerability and Exploit Intelligence are built to close.

  • Anomali's vulnerability prioritisation intelligence maps CVEs like those described above to known exploitation activity, helping teams prioritise the patches that matter most before adversaries exploit them.
  • Anomali's dark web and advanced threat intelligence provides coverage that commodity feeds do not reach, nation-state actor attribution including Iranian-nexus groups, pre-ransomware initial access broker detection with a 24–72 hour warning window, outside-in compromised host visibility, and dark web credential monitoring, all surfaced inside ThreatStream as enriched, actionable intelligence.
  • Anomali Vulnerability & Exploit Intelligence provides sensor-derived exploit hashes and file indicators tied to CVEs, enabling teams to detect active exploitation of the vulnerabilities described above and prioritise patching based on real-world attack activity.

Does your current stack surface dark web actor conflicts like the ShinyHunters breach of Clop before they affect you?

Talk to Anomali.

FEATURED RESOURCES

September 23, 2026
No items found.

When Criminals Hack Criminals: ShinyHunters' Breach of Clop and What It Reveals About the Ransomware Underground

Read More
September 22, 2026
Anomali Cyber Watch

NightEagle GhostContainer Backdoor, SparroWocky Against Government, RatHat Malware Uses AI to Target Banking, Jade Sleet Targets Indian IT, BragJack Hijacks AI Agents, OpenAI Identity Design Flaw, and more

NightEagle APT Expands from Asia to Russia Using GhostContainer Backdoor and Tunneling Tools. FamousSparrow Deploys SparroWocky Backdoor Against Latin American Government Agencies. RatHat Android Malware Uses AI Automation to Target Banking Credentials. Jade Sleet Targets Indian IT Provider With FLATROOF and ROOFDECK Backdoors. BragJack Proof-of-Concept Hijacks AI Browser Agents via Malicious Extensions. Researchers Chain libheif Over-Read and OpenAI Identity Design Flaw to Reach Internal Code Repository.
Read More
September 16, 2026
No items found.

Ransomware's New Hire: Why Criminal Groups Are Recruiting Your Employees Instead of Hacking Them

Read More
Explore All