< Back to situations

Monitor this situation.

[SITUATION] · [ACTIVE] · [TECHNOLOGY]

2 clusters · 137 sources · 3 days · First seen · Last updated

ShinyHunters and Clop cybercrime conflict

Overview

A public confrontation has emerged between cybercrime syndicates ShinyHunters and Clop. In late September 2026, ShinyHunters reportedly hijacked Clop’s dark web leak site by exploiting an unauthenticated file upload vulnerability in Grav CMS. The takeover included defacing Clop’s Tor site with the message “Domain Seized By ShinyHunters” and allegedly stealing sensitive data, such as source code, system logs, and private cryptographic keys.

The dispute is reportedly driven by a disagreement over a zero-day exploit used in campaigns targeting Oracle E-Business Suite. ShinyHunters claims they discovered the vulnerability first and is attempting to extort Clop for an eight-figure payment and a public apology. The groups have engaged in mutual threats, with ShinyHunters vowing to leak Clop’s files and identify companies that previously paid ransoms to the gang.

On September 22, 2026, ShinyHunters expanded its activities by claiming to have breached FBI systems, allegedly stealing between 2TB and 3TB of sensitive data. The group asserts the breach includes information on current and former FBI agents, employees, and job applicants, such as names, home addresses, and phone numbers. ShinyHunters claims they exploited a zero-day vulnerability in Oracle PeopleSoft to access recruitment infrastructure and move into government cloud environments like AWS GovCloud. The group described the attack as retaliation for a May 2026 FBI announcement regarding their methods, demanding the bureau retract its statements. While some portions of a data sample have been partially verified by media outlets, the FBI has not officially confirmed the breach.

Entities

Oracle · FBI · Huntress · Grav CMS · Brett Leatherman

Claims

What the coverage asserts, and how many sources carry each claim.

Timeline

  1. 2 days ago

    [TECHNOLOGY] 128 sources
    FBI systems allegedly breached by ShinyHunters hacking group

    The hacking group ShinyHunters claims to have stolen up to 3TB of sensitive data from the FBI, including personal information of agents and applicants, in retaliation for a previous FBI warning.

  2. 4 days ago

    [TECHNOLOGY] 13 sources
    ShinyHunters hijacks Clop ransomware gang's dark web leak site

    The ShinyHunters cybercrime group has hijacked the Clop ransomware gang's dark web leak site, claiming to have stolen private keys and source code following a dispute over an Oracle software exploit.

Sources

20minutos.com.mx · actualidad.rt.com · aksam.com.tr · albiladpress.com · americanindependent.com · americanwirenews.com · anlatilaninotesi.com.tr · arstechnica.com · asaaseradio.com · balleralert.com · bangordailynews.com · baocalitoday.com · baogialai.com.vn · bgvoice.com · blocktempo.com · blogspan.net · boldmedya.com · bright.nl · cafef.vn · cbsnews.com · chimicamo.org · clubic.com · cnbce.com · cnet.com · complex.com · correiodamanha.pt · CT24.cz · cyberdefence24.pl · cyberinsider.com · cybernoz.com · cybersecurity360.it · cyprus-mail.com · dagens.com · dagens.de · dagensps.se · deultimominuto.net · dev.to · developpez.net · diariolibre.com · dimokratia.gr · donanimgunlugu.com · ehandel.se · epochtimes.com · federalsoup.com · finance.technews.tw · fjala.al · fortunegreece.com · freerepublic.com

This summary has been updated 1 time: see revision history