Cybercrime War: ShinyHunters Claims Hijack of Rival Gang cl0p
ShinyHunters, a notorious digital extortion group, claimed to have hijacked the dark web infrastructure of its rival cybercrime group cl0p. The rare turf war exposes escalating friction within the underground hacking economy, carrying severe implications for enterprise risk management and supply chain security as threat actors turn their sophisticated tooling against one another.
The Anatomy of an Underground Turf War
The digital extortion landscape shifted dramatically on Friday when ShinyHunters exploited a software vulnerability within cl0p’s systems to seize sweeping operational control. According to an online chat with Reuters, a ShinyHunters representative asserted complete dominance over the rival infrastructure, stating, “We basically own them now.”
Evidence of the breach quickly surfaced across the dark web. The primary dark web portal utilized by cl0p was knocked offline by Sunday. Prior to its complete blackout, visitors were greeted with a blunt defacement message reading, “Domain Seized By ShinyHunters,” a detail verified through screenshots preserved by the cybercrime research platform eCrime.ch.
Cybersecurity validation for the clash came swiftly from institutional threat intelligence experts. Brandon Parsons, a threat intelligence manager at Ascent Solutions, noted that street-level friction in the criminal underground is a genuine operational reality. Meanwhile, Joe Roosen, senior director of security research at SpyCloud, highlighted the unprecedented nature of the direct confrontation. “This was a twist for sure,” Roosen told Reuters. “It is rare I get to see these criminals fight each other.”
Oracle Software Exploits and Retaliation Triggers
The friction between the two syndicates stems from a prolonged dispute over high-value software exploits. ShinyHunters disclosed that the conflict originated from a battle over the theft of a zero-day vulnerability targeting Oracle’s E-Business Suite (EBS). Zero-days are prized assets in cybercrime circles because developers have had zero days to deploy defensive patches, granting unauthorized intruders sweeping network access.
Historical operational tracking demonstrates the scale at which both syndicates operate. Cl0p previously leveraged an enterprise file-management bug in MOVEit to compromise data across more than 600 companies affecting tens of millions of individuals. Just last month, cl0p claimed responsibility for extracting large data volumes from nearly 50 multinational entities, including Philips, Shell, Fiserv, and GE. Furthermore, a Google analyst estimated that cl0p’s use of the Oracle EBS vulnerability compromised over 100 corporate networks.

ShinyHunters matches this aggressive footprint. The group made global headlines in April by claiming the theft of millions of records from Rockstar Games, the developer behind “Grand Theft Auto.” Additional disruption followed in May when a targeted campaign against education software provider Canvas impacted schools across the United States. Escalating their profile further, AI developer Anthropic reported catching ShinyHunters-linked actors attempting to abuse its intelligence systems.
As the Oracle dispute intensified, cl0p allegedly threatened to expose the identities of several ShinyHunters members. In a retaliatory posture, ShinyHunters threatened to expose the internal operational mechanics of cl0p, culminating in the weekend’s infrastructure takeover. While Reuters could not independently verify every internal claim made by the syndicates, the physical disruption of cl0p’s digital assets remains a matter of public record.