ShinyHunters has reportedly hacked the cybercriminal group Cl0p, defaced its website and threatened to publish stolen files. TechRadar reports that the attackers gave Cl0p 72 hours to pay an undisclosed ransom or face a leak.
According to Cybernews and BleepingComputer, the allegedly stolen data includes source code, Grav CMS plugins, system logs and information from the server’s /var/log directory. ShinyHunters also claimed to have obtained authentication logs, IP addresses and the private keys for Cl0p’s Tor onion service. The claims have not been independently verified in the source material.
Cybernews confirmed that Cl0p’s website had been defaced with an ASCII image associated with ShinyHunters and a link to the group’s Tor site. The attackers allegedly exploited an unauthenticated file-upload flaw in the Grav CMS installation.
ShinyHunters said the attack followed an alleged threat made by a Cl0p member during the group’s 2025 Oracle E-Business Suite attacks. The broader dispute reflects how cooperation between cybercriminal groups can break down. A previous major example came in 2022, when Conti’s public support for Russia was followed by leaks of more than 60,000 messages. Conti later collapsed, while alleged members moved into groups including Black Basta, Royal and Quantum.
Comments
0No comments yet. Be the first to comment.