ZeroFox Intelligence Flash Report - ShinyHunters Attacks Cl0p Ransomware Leak Site
|by Alpha Team

ZeroFox Intelligence Flash Report - ShinyHunters Attacks Cl0p Ransomware Leak Site
Product Serial: F-2026-09-22a
TLP:CLEAR
In this Flash Report, ZeroFox researchers report on the recent ShinyHunters attack on the Cl0p ransomware leak site, in a case of threat actor versus threat actor activity.
For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- On September 18, 2026, ransomware and digital extortion (R&DE) collective ShinyHunters gained unauthorized access to the dark web leak site belonging to fellow R&DE threat collective Cl0p.
- ShinyHunters claims to have stolen significant amounts of data from Cl0p, including the group’s source code—likely meaning the source code for Cl0p’s ransomware-as-a-service (RaaS) software and tools. There is a roughly even chance that ShinyHunters gained access to the IP addresses of individuals connected to Cl0p.
- Unless Cl0p comes to a rapid agreement for ShinyHunters to release the stolen data—and assuming ShinyHunters will actually return data and source code—ZeroFox assesses that Cl0p is unlikely to have the capability to conduct successful R&DE operations, causing a tangible, if temporary, degradation of the threat actor group’s ability to impact organizations.
- Additionally, ZeroFox assesses that rivalries and attacks between R&DE collectives will very likely lead to greater fragmentation across the threat landscape. Such fragmentation will almost certainly see new threat actors and splinter groups, creating a more crowded R&DE ecosystem and almost certainly leading to an increase in incidents.
Tags: tlp:clear, dark web, threat actor