A public dispute between 2 major cybercrime groups has moved into the open after ShinyHunters claimed it had taken control of the dark web site operated by rival group cl0p.
ShinyHunters, known for large-scale data theft and digital extortion campaigns, said it breached cl0p’s site on Friday after finding a vulnerability in the group’s software. It claimed the flaw allowed it to gain broad control over cl0p’s infrastructure.
“We basically own them now,” ShinyHunters said in an online chat.
Cl0p did not respond to repeated requests for comment. Its dark web site was unreachable on Sunday. A screenshot preserved by a cybercrime research platform showed the site displaying, “Domain Seized By ShinyHunters” on Saturday.
2 cybersecurity experts said the confrontation appeared genuine.
“Street beefs on the dark web are a real thing,” said Brandon Parsons, a threat intelligence manager at a US security company.
Joe Roosen, senior director of security research at another US cybersecurity company, said he had not previously seen cybercriminal groups confront each other so openly. “This was a twist for sure,” he said. “It is rare I get to see these criminals fight each other.”
Dispute over Oracle exploit
ShinyHunters said its conflict with cl0p began over the alleged theft of a software exploit targeting a previously unknown vulnerability in Oracle’s E-Business Suite (EBS).
Such “zero days” are highly valuable to cybercriminals because security teams have had no time to patch the flaws before they are exploited.
Cl0p, a Russian-speaking cybercrime group, allegedly used the EBS vulnerability to steal data from more than 100 companies, based on an estimate from a Google analyst. ShinyHunters claimed it had discovered the vulnerability first.
According to ShinyHunters, cl0p later threatened to expose the identities of several members of its rival group. ShinyHunters responded by threatening to disclose details of cl0p’s internal operations.
The claims could not be independently verified.
Cl0p has previously exploited major enterprise software vulnerabilities. In 2023, it used a MOVEit flaw to steal data affecting tens of millions of people across more than 600 companies. Last month, it claimed data theft from nearly 50 companies, including Philips, Shell, Fiserv and GE.
ShinyHunters has also faced major allegations. In April, it claimed to have stolen millions of business records from Rockstar Games, maker of “Grand Theft Auto”. In May, a hack involving education platform Canvas caused widespread disruption across US schools.
Also read: Viksit Workforce for a Viksit Bharat
Do Follow: The Mainstream LinkedIn | The Mainstream Facebook | The Mainstream Youtube | The Mainstream Twitter
About us:
The Mainstream is a premier platform delivering the latest updates and informed perspectives across the technology business and cyber landscape. Built on research-driven, thought leadership and original intellectual property, The Mainstream also curates summits & conferences that convene decision makers to explore how technology reshapes industries and leadership. With a growing presence in India and globally across the Middle East, Africa, ASEAN, the USA, the UK and Australia, The Mainstream carries a vision to bring the latest happenings and insights to 8.2 billion people and to place technology at the centre of conversation for leaders navigating the future.


