```html ```
top of page

ShinyHunters Seized Cl0p's Leak Site and Is Extorting the Extortionist for 2.333% of Its Net Worth. The Interesting Part Is Who Now Holds the Victim Data.

Writer: Patrick Duggan
Patrick Duggan
1 hour ago
6 min read

Over the weekend somebody repainted the sign on Cl0p's storefront. According to material posted on the site itself and reported Monday by Alexander Martin at Recorded Future News, the ShinyHunters extortion crew has seized the dark-web leak site of the Cl0p ransomware operation, named three of its operators, and demanded an eight-figure payment described as 2.333 percent of Cl0p's net worth. The demand is not only money. ShinyHunters wants a public apology, the proceeds from Cl0p's recent Oracle E-Business Suite campaign, and it has threatened to publish Cl0p's payment records, the amounts, and the Bitcoin addresses used. The demand rises every twenty-four hours without a reply. By Monday Cl0p had posted a response of its own, which reads less like a ransomware syndicate and more like a man locked out of his email: "Shiny Hunters we trying to reach you Your email does not work."


It is funny. It is also a market signal, and the funny part is the least useful thing about it.



What we hold on both crews, and why that matters here


Before writing a word of analysis we checked what we actually have, because the alternative is recycling someone else's narrative. Our blog index returns 145 posts matching ShinyHunters and 12 matching Cl0p on an exact-phrase query, and the indicator index carries 57 attributed ShinyHunters records and 123 attributed Cl0p records. That is eleven months of first-party coverage on both sides of this fight, which is the only reason we can say anything about it that is not a summary of Monday's news.




Laid out side by side, the two lanes do not look like the same business at all.


Cl0p's lane is a vulnerability calendar. In January we covered its wave through Hilton, law firms and healthcare. In June we wrote that it was mass-exploiting Oracle E-Business Suite and went hunting the exposed surface ourselves. In July it was PTC Windchill and the product designs inside it, which we flagged as a medical-device problem as much as a manufacturing one. In August we published a post noting that the exact hunt pattern we had put out on June 26 had since produced 43 listed Windchill victims, and we ingested that campaign's indicators under a dated source on August 21. Cl0p finds a file-transfer or ERP product with a critical bug, exploits it at scale, and lists whoever falls out.


ShinyHunters' lane is a trust calendar. Our earliest post in this window is the September 2025 piece on OAuth's blind spot in the Salesloft Drift compromise. In April it claimed Vercel, and the more established ShinyHunters identity publicly disowned the claim, which we checked and wrote up rather than repeating. Five days later it claimed ADT for ten million records. Two days after that we documented six companies in seven days and published ten Salesforce-plus-Okta targets that fit the same pattern. By June we were ingesting its PeopleSoft indicators, and in July we wrote that it had been inside PeopleSoft since the spring. ShinyHunters does not need a zero-day. It needs a token, a vendor relationship, or a help desk.


One crew farms software. The other farms relationships. This week the relationship crew came for the software crew's storefront, and it did not need a vulnerability to do it.



The credibility note we are obliged to repeat


In April we published a post titled around the fact that ShinyHunters claimed Vercel and the real ShinyHunters said it was not them, and we checked. That post exists because attribution in this space is a marketing channel. Names get borrowed. A claim on a leak site is a press release from a party with every incentive to inflate. We were careful then and we are being careful now: everything above about the seizure comes from material posted on the site and from Recorded Future News's reporting of it. We have not visited the infrastructure, we are not confirming the operator names posted there, and we are not treating the "2.333 percent" figure as a verified statement about anyone's holdings. It is a number an extortionist typed.


Which brings us to the part nobody has a plan for.



Who inherits the victim data


A ransomware leak site is not just a billboard. It is a data custodian. Every victim Cl0p listed and every victim who negotiated, paid, or stalled has material sitting on that infrastructure, or referenced by it, or indexed against a countdown clock. When the site changes hands, the custody of that material changes hands with it, and the new custodian has announced publicly that it intends to publish payment records, amounts and wallet addresses.


Read that as a victim and the implications get sharp fast. If your organization appeared on Cl0p's site in the last year, a second group now has whatever was staged there. If your organization paid Cl0p, the record of that payment is now an asset held by a party that has said out loud it will publish such records. Every assumption baked into the decision to pay — that the counterparty controls the data, that deletion means deletion, that discretion is part of what was purchased — was an assumption about a single counterparty who is no longer in sole possession.


This is the shared-responsibility seam again, in the least expected place. The control worked exactly as designed on both sides: Cl0p ran its extortion business, victims made their calls under the information they had, incident response plans covered notification, forensics, regulators and negotiation. The half nobody assigned is what happens when the extortionist is itself compromised and the data changes owner without any of the original parties being party to it. We have never read an incident response plan with a clause for that. We have never written one either.


There is a second-order effect for the crews themselves, which is why this is a market signal rather than gossip. The entire ransomware affiliate economy runs on a trust assumption: that the operator holds the infrastructure, takes a cut, and does not become a liability to its own affiliates. A leak site seized by a rival, with payment records threatened as leverage, is an operator failing at the one job an affiliate is paying for. If Cl0p's payment ledger becomes public, every affiliate in that ecosystem learns what their operator actually earned and what victims actually paid, and every future negotiation starts from different arithmetic.



Indicators: none published, and we are not inventing any


The reporting carries no technical indicators. No new leak-site domain, no wallet address, no contact handle, no email. We checked our own corpus for anything that would let us enrich the event and found nothing new to add, so there is nothing to ingest and no batch was created. Our existing holdings on both actors — 57 ShinyHunters records and 123 Cl0p records, including the Windchill campaign batch dated August 21 — remain as they were.


We are saying this plainly because the alternative is the thing we complain about in other people's write-ups: a post about a campaign with no indicators in the feed, where the prose names things that a defender cannot pull and block. When there is nothing to feed, the honest move is to say so rather than dress up the corpus we already had as new work.



What a defender should actually take from this


If you were on Cl0p's victim list at any point, treat the data as having changed custody and re-run whatever notification analysis you did the first time, because the set of parties holding your material has changed and that is usually a material fact. If you paid, assume the payment record is now held by a party that has threatened to publish payment records. If you are writing or reviewing an incident response plan this quarter, add the clause: what do we do when the party holding our data is itself breached, seized or succeeded by another. It sounds absurd until the week it happens, and this is the week.


And if you run threat intelligence, notice which lane did this. It was not the crew with the better exploits. It was the crew that has spent a year getting into things through trust relationships rather than software flaws, and it applied exactly that method to a peer. The technique did not change. Only the victim did.


Was this useful? Rate this post. The widget is at the bottom of the page, and we read every response.




Every indicator in this post is in the feed. Free.

1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.



Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=shinyhunters-seized-cl0p-s-leak-site-and-is-extorting-the-extortionist-for-2-333-of-its-net-worth



Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page