# ShinyHunters and Clop cybercrime conflict

> Live situation record from CLSTR: https://clstr.news/situations/shinyhunters-and-clop-cybercrime-conflict
> Updated: 2026-09-22T08:30:07.000Z. Sources: 137. Developments: 2.

A public confrontation has emerged between cybercrime syndicates ShinyHunters and Clop. In late September 2026, ShinyHunters reportedly hijacked Clop’s dark web leak site by exploiting an unauthenticated file upload vulnerability in Grav CMS. The takeover included defacing Clop’s Tor site with the message “Domain Seized By ShinyHunters” and allegedly stealing sensitive data, such as source code, system logs, and private cryptographic keys.

The dispute is reportedly driven by a disagreement over a zero-day exploit used in campaigns targeting Oracle E-Business Suite. ShinyHunters claims they discovered the vulnerability first and is attempting to extort Clop for an eight-figure payment and a public apology. The groups have engaged in mutual threats, with ShinyHunters vowing to leak Clop’s files and identify companies that previously paid ransoms to the gang.

On September 22, 2026, ShinyHunters expanded its activities by claiming to have breached FBI systems, allegedly stealing between 2TB and 3TB of sensitive data. The group asserts the breach includes information on current and former FBI agents, employees, and job applicants, such as names, home addresses, and phone numbers. ShinyHunters claims they exploited a zero-day vulnerability in Oracle PeopleSoft to access recruitment infrastructure and move into government cloud environments like AWS GovCloud. The group described the attack as retaliation for a May 2026 FBI announcement regarding their methods, demanding the bureau retract its statements. While some portions of a data sample have been partially verified by media outlets, the FBI has not officially confirmed the breach.

## Claims

- The hacking group ShinyHunters claims to have breached FBI systems and stolen personal data of thousands of employees. (corroborated by 42 sources)
- The group claims to have defaced the FBI jobs website. (corroborated by 30 sources)
- The attack is a retaliation for an FBI announcement in May 2026 regarding the group's methods. (corroborated by 30 sources)
- The FBI has not confirmed the breach. (corroborated by 27 sources)
- The stolen data includes names, home addresses, phone numbers, and information about employees' spouses. (corroborated by 25 sources)
- A sample of approximately 5,000 files was provided to 404 Media as evidence of the breach. (corroborated by 24 sources)
- The FBI's job application site and Special Agent Applicant Portal were reported as temporarily unavailable on Tuesday. (corroborated by 18 sources)
- Reuters verified at least nine instances of matching names and addresses from the leaked sample against credit bureau records and District 4 Labs data. (corroborated by 12 sources)
- The group claims to have stolen between 2TB and 3TB of data. (corroborated by 11 sources)

## Timeline

### 2026-09-22: FBI systems allegedly breached by ShinyHunters hacking group

The hacking group ShinyHunters claims to have stolen up to 3TB of sensitive data from the FBI, including personal information of agents and applicants, in retaliation for a previous FBI warning.

128 sources. https://clstr.news/cluster/shinyhunters-claims-to-hijack-rival-clop-ransomware-infrastructure

### 2026-09-20: ShinyHunters hijacks Clop ransomware gang's dark web leak site

The ShinyHunters cybercrime group has hijacked the Clop ransomware gang's dark web leak site, claiming to have stolen private keys and source code following a dispute over an Oracle software exploit.

13 sources. https://clstr.news/cluster/shinyhunters-hacks-clop-ransomware-leak-site

---
Cite as: ShinyHunters and Clop cybercrime conflict. CLSTR, https://clstr.news/situations/shinyhunters-and-clop-cybercrime-conflict
