ShinyHunters hijacked the dark web site of cybercrime gang Cl0p, set an eight-figure extortion demand, describing the amount as “2.333%” of Cl0p's net worth
The ShinyHunters extortion group hijacked the dark web leak site of the prolific Cl0p ransomware gang, according to material posted on the site over the weekend.
Context & Ripple Effects
ShinyHunters had already built a profile in 2020 by offering purportedly stolen records from multiple companies, while Cl0p's leak site functions as a public pressure point in its extortion operation. The takeover turns that infrastructure against its operator rather than a corporate victim.
The incident follows the 2025 defacement of LockBit affiliate panels and exposure of panel data, showing that criminal groups' own web infrastructure can become an operational target. Coverage across several security and general-interest outlets underscores the unusual visibility of this intra-criminal confrontation.
First-order effects
- Cl0p loses control of a key leak-site channel while ShinyHunters uses the takeover to press its confirmed eight-figure payment demand.
- ShinyHunters gains a public platform for the demand, increasing pressure on Cl0p by making the dispute visible to the gang's affiliates and victims.
Second-order effects
- Cl0p affiliates and extortion victims must treat the compromised site as an unreliable source of claims or instructions until control is restored.
- Other ransomware and data-extortion groups face a clearer incentive to harden or compartmentalize leak portals and affiliate panels, following the earlier LockBit panel compromise.
Third-order effects
- If attacks on criminal infrastructure recur, leak sites and affiliate portals become liabilities as well as coercion tools, weakening the operational separation ransomware groups seek between operators, affiliates, and victims.
- The episode points to a cybercrime market in which rival groups compete not only for stolen data and payments but also by disrupting the trust and infrastructure that make extortion campaigns work.
The trend: Cybercrime groups are increasingly exposed to the same infrastructure compromise and public-pressure tactics they use against targets.