Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-22 · updated: 2026-09-22 · tags: [incident, global, ransomware] · confidence: medium · severity: high · affected_sectors: [global] · au_impact: true

The ShinyHunters extortion group took over the dark-web leak site of the Cl0p ransomware gang over the weekend and is running Cl0p's own pressure tactics against it. The defaced page carries an extortion demand described as "2.333%" of Cl0p's net worth — an unspecified eight-figure sum — and states that the figure will rise every 24 hours that Cl0p fails to respond; by Monday the terms had expanded to require a public apology. A message posted on Sunday named three people identified as Cl0p operators, all previously named in public reporting, and demanded the proceeds of Cl0p's recent Oracle E-Business Suite campaign "plus more". The demand that matters most to defenders is the threat to publish records showing which companies paid Cl0p, how much they paid and which Bitcoin addresses were used: any organisation that settled with Cl0p during the E-Business Suite campaign would be exposed to a second extortion attempt armed with proof of the first. ShinyHunters says the feud began with Cl0p's unauthorised use of a vulnerability ShinyHunters had published proof-of-concept code for, and with threats against one of its members. Cl0p replied on Monday asking ShinyHunters to make contact.

Attribute Detail
Sector Global (Macro)
Date 2026-09-22
Source The Record
Reliability Tier 2