zerofox logo
Advisories

ZeroFox Intelligence Flash Report - ShinyHunters Attacks Cl0p Ransomware Leak Site

|by Alpha Team

banner image

ZeroFox Intelligence Flash Report - ShinyHunters Attacks Cl0p Ransomware Leak Site

Product Serial: F-2026-09-22a

TLP:CLEAR

In this Flash Report, ZeroFox researchers report on the recent ShinyHunters attack on the Cl0p ransomware leak site, in a case of threat actor versus threat actor activity.

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:

https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report here

Key Findings

  • On September 18, 2026, ransomware and digital extortion (R&DE) collective ShinyHunters gained unauthorized access to the dark web leak site belonging to fellow R&DE threat collective Cl0p.
  • ShinyHunters claims to have stolen significant amounts of data from Cl0p, including the group’s source code—likely meaning the source code for Cl0p’s ransomware-as-a-service (RaaS) software and tools. There is a roughly even chance that ShinyHunters gained access to the IP addresses of individuals connected to Cl0p.
  • Unless Cl0p comes to a rapid agreement for ShinyHunters to release the stolen data—and assuming ShinyHunters will actually return data and source code—ZeroFox assesses that Cl0p is unlikely to have the capability to conduct successful R&DE operations, causing a tangible, if temporary, degradation of the threat actor group’s ability to impact organizations.
  • Additionally, ZeroFox assesses that rivalries and attacks between R&DE collectives will very likely lead to greater fragmentation across the threat landscape. Such fragmentation will almost certainly see new threat actors and splinter groups, creating a more crowded R&DE ecosystem and almost certainly leading to an increase in incidents.

Tags: tlp:clear,  dark web,  threat actor