Flash Report: ShinyHunters Attacks Cl0p Ransomware Leak Site
by ZeroFox Intelligence
Key Findings
- On September 18, 2026, ransomware and digital extortion (R&DE) collective ShinyHunters gained unauthorized access to the dark web leak site belonging to fellow R&DE threat collective Cl0p.
- ShinyHunters claims to have stolen significant amounts of data from Cl0p, including the group’s source code—likely meaning the source code for Cl0p’s ransomware-as-a-service (RaaS) software and tools. There is a roughly even chance that ShinyHunters gained access to the IP addresses of individuals connected to Cl0p.
- Unless Cl0p comes to a rapid agreement for ShinyHunters to release the stolen data—and assuming ShinyHunters will actually return data and source code—ZeroFox assesses that Cl0p is unlikely to have the capability to conduct successful R&DE operations, causing a tangible, if temporary, degradation of the threat actor group’s ability to impact organizations.
- Additionally, ZeroFox assesses that rivalries and attacks between R&DE collectives will very likely lead to greater fragmentation across the threat landscape. Such fragmentation will almost certainly see new threat actors and splinter groups, creating a more crowded R&DE ecosystem and almost certainly leading to an increase in incidents.
Details
On September 18, 2026, R&DE collective ShinyHunters gained unauthorized access to the dark web leak site belonging to fellow R&DE threat collective Cl0p. The attack began when ShinyHunters exploited what the group claims was an unauthenticated file upload vulnerability on Cl0p’s site; ShinyHunters allegedly exploited the vulnerability to upload a small text file that contained a note warning Cl0p not to threaten the group.1
Several hours later, ShinyHunters reportedly told a journalist that it had defaced Cl0p’s leak site.2 The defaced leak site now includes a link to ShinyHunters’ own dark web leak site, as well as a message taunting Cl0p.
ShinyHunters claims to have stolen significant amounts of data from Cl0p, including its source code3—likely meaning the source code for Cl0p’s RaaS software and tools.
- It is also likely that ShinyHunters obtained system activity indicators and authentication logs.
- There is a roughly even chance that ShinyHunters gained access to the IP addresses of individuals connected to Cl0p.
On September 22, 2026, ShinyHunters added Cl0p as a victim on its dark web leak site. In the post, the collective threatened to destroy Cl0p’s brand unless an eight-figure ransom is paid, with the amount increasing every 24 hours that Cl0p fails to respond or negotiate.4
ZeroFox assesses that this incident will likely have a significant impact on Cl0p’s R&DE activity over the next six months. ShinyHunters exploiting Cl0p’s leak site, stealing data, and very likely gaining access to Cl0p’s source code will likely have more consequences than just reputational damage. Unless Cl0p comes to a rapid agreement for ShinyHunters to release the stolen data—and assuming ShinyHunters will actually return data and source code—ZeroFox assesses that Cl0p is unlikely to have the capability to conduct successful R&DE operations, causing a tangible, if temporary, degradation of the threat actor group’s ability to impact organizations.
Additionally, ZeroFox assesses that rivalries and attacks between R&DE collectives will very likely lead to greater fragmentation across the threat landscape. Such fragmentation will almost certainly see new threat actors and splinter groups, creating a more crowded R&DE ecosystem and almost certainly leading to an increase in incidents.
Scope Note
ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 10:00 AM (EDT) on September 22, 2026; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
ZeroFox Intelligence Probability Scale
All ZeroFox intelligence products leverage probabilistic assessment language in analytic judgments. Qualitative statements used in these judgments refer to associated probability ranges, which state the likelihood of occurrence of an event or development. Ranges are used to avoid a false impression of accuracy. This scale is a standard that aligns with how readers should interpret such terms.
- hXXps://www.bleepingcomputer[.]com/news/security/shinyhunters-hacks-clop-leak-site-threatens-to-extort-ransomware-gang/
- Ibid.
- Ibid.
- Ibid.