Hackers hacked the hackers: ShinyHunters takes over Russian gang cl0p's dark web site

One of the world's most notorious cybercriminal groups, ShinyHunters, claimed on Sunday that it had taken control over the dark web site of its main rival, the Russian-speaking gang cl0p. The move brought a long-simmering feud between the two gangs into public view, Reuters reported.

ShinyHunters, known for its aggressive data theft campaigns and specializing in digital extortion, said it broke into cl0p's site on Friday after finding a flaw in the rival group's software and using it to gain extensive control over its infrastructure.

"We basically own them now"

the group told Reuters in an online conversation. cl0p did not respond to repeated inquiries from the news agency. The site was inaccessible on Sunday, and on Saturday it displayed the message "Domain seized by ShinyHunters," according to a screenshot captured by the cybercrime research platform eCrime.ch. Reuters could not independently verify ShinyHunters' account. Two cybersecurity experts said the clash appeared to be genuine. "Turf wars are part of the reality on the dark web," said Brandon Parsons, head of threat intelligence at Ascent Solutions in Minnesota. Joe Roosen, director of security research at SpyCloud in Texas, said he had never seen two cybercriminal groups turn on each other so openly before. "It really was an unexpected turn. I rarely see these criminals fighting each other."

According to ShinyHunters, the feud began last year when cl0p allegedly stole an attack tool from it that exploited a previously unknown flaw in the Oracle E-Business Suite enterprise resource planning software. Such flaws, known as zero-day vulnerabilities—named because defenders have "zero days" to fix them—are especially prized by hackers because they can grant nearly unrestricted access to vulnerable networks. According to cybersecurity analysts at Google, starting in late September 2025 attackers tried to extort victims through a mass email campaign launched from hundreds of compromised third-party accounts. A Google analyst estimated that cl0p stole data from more than a hundred companies by exploiting the flaw; ShinyHunters claims it discovered the vulnerability first. The dispute escalated to the point where, according to ShinyHunters, cl0p threatened to expose the identities of several of its members, while ShinyHunters intended to leak details of cl0p's internal operations.

cl0p is considered one of the world's most prolific and inventive cybercriminal groups, largely because of its skill at identifying and exploiting flaws in corporate software. In 2023, it exploited a vulnerability in the file-transfer software MOVEit to steal data belonging to tens of millions of people from more than six hundred companies. Last month, it claimed to have obtained large volumes of data from nearly fifty companies worldwide, including Philips, Shell, Fiserv and GE. ShinyHunters is similarly active. In April, it made headlines after claiming to have stolen millions of business records from Rockstar Games, the developer of the Grand Theft Auto series, and in May it launched an attack on Instructure, the company that runs the Canvas education platform, causing widespread disruption in American schools. The group has also been linked to an attack on RingCentral and the recent cyberattack on Manchester Airports Group.

In a report published on September 10, artificial intelligence developer Anthropic said it had identified and shut down several financially motivated cybercriminal groups it suspects are affiliated with ShinyHunters. According to the report, these groups used the Claude models to speed up target reconnaissance, exploit vulnerabilities and take over systems. One member, using the French-language alias "frkoo," built an automated system across ten cloud servers that downloaded, decompiled and scanned 1.8 million Android applications in search of embedded passwords and access keys. The data obtained this way was later used in confirmed breaches, including one in which the hackers gained access to the data of about two hundred customers of a software service provider by breaching it. Anthropic said it had disabled the accounts and strengthened its defense mechanisms.

Ugar

Did you like this article?

Support our work with a small donation

Secure payment via Stripe • Min. 2 EUR

Gesta recommendations:

Three-year extension of sanctions, but Fridman and Usmanov removed from the list with Hungary's support

Three-year extension of sanctions, but Fridman and Usmanov removed from the list with Hungary's support

The member states of the European Union on Tuesday extended for three years the individual sanctions affecting nearly three thousand Russian citizens and entities, though two billionaires considered close to Moscow — Uzbek-Russian businessman Alisher Usmanov and Russian oligarch Mikhail Fridman — were removed from the list. The agreement was reached only at the last moment, after Latvia vetoed…

ugar
Zero risk, over a hundred countries: this is how Revolut would build the global bank

Zero risk, over a hundred countries: this is how Revolut would build the global bank

Nik Storonsky, founder and CEO of Revolut,in a Monday interview with the Financial Times outlined the kind of global bank he wants to build. The essence of the model is that the company would only lend out a fraction of its deposits, meaning that, in Storonsky's words, it takes on "essentially zero risk." The plan was unveiled at a time when the London-based fintech is steadily obtaining banking…

ugar
Moldovan man behind Paris coffin graffiti arrested

Moldovan man behind Paris coffin graffiti arrested

Romanian authorities last week detained Moldovan citizen Iurie Manic at the Moldova–Romania border. He is accused by French prosecutors of being one of the leaders of a series of vandalism actions in Paris directed by Russia. The case was first reported by Ziarul de Iaşi.

ugar
The art of "adormire": the system caught Georgescu again, then let him go

The art of "adormire": the system caught Georgescu again, then let him go

An average Romanian citizen accused of swindling a businessman out of 1.1 million euros, whose case is being handled by DIICOT, the anti-organized-crime prosecutor's office, would likely spend the standard thirty days of pretrial detention in a Bucharest holding cell before he could even calculate how many tenths of a percent are left on his Swiss bank account. Călin Georgescu is not an average…

ugar
32 percent: the bill presented to Trump at the gas pump

32 percent: the bill presented to Trump at the gas pump

Democracy has its own peculiar form of justice: slow, clumsy, sometimes maddeningly delayed, but it arrives in the end - and now Donald Trump's Middle East war has brought the bill. According to a four-day Reuters/Ipsos poll that closed on Sunday, the president's approval rating has fallen to 32 percent, the lowest of his entire political career. Esteemed American public opinion has come to this…

ugar