A feud between two major cybercrime groups has spilled into the open after ShinyHunters claimed it had breached the dark web infrastructure of rival gang cl0p and taken control of its website.
ShinyHunters, a prolific digital extortion group known for large-scale data theft, said it exploited a vulnerability in cl0p’s software on Friday to gain extensive access to the group’s infrastructure.
“We basically own them now,” ShinyHunters told Reuters in an online chat.
The claim could not immediately be independently verified. Cl0p did not respond to repeated requests for comment, while its dark web site was inaccessible when Reuters attempted to visit it on Sunday.
On Saturday, however, the site displayed a message saying, “Domain Seized By ShinyHunters”, according to a screenshot preserved by cybercrime research platform eCrime.ch.
Two cybersecurity researchers said the confrontation appeared to be genuine, highlighting the unusual nature of one cybercrime operation directly targeting another.
“Street beefs on the dark web are a real thing,” said Brandon Parsons, a threat intelligence manager at Minnesota-based Ascent Solutions.
Joe Roosen, senior director of security research at SpyCloud, said he had rarely seen rival cybercriminal groups engage each other so openly.
The dispute reportedly centres on a zero-day vulnerability in Oracle’s E-Business Suite software. Such vulnerabilities are particularly valuable to cybercriminals because they are previously unknown flaws that can provide access to vulnerable systems before security teams have had an opportunity to develop and deploy a fix.
According to ShinyHunters, cl0p used the Oracle vulnerability to steal data from more than 100 companies, but the group claimed it had discovered the flaw before its rival.
The disagreement subsequently escalated, with ShinyHunters alleging that cl0p threatened to expose the identities of members of its organisation. ShinyHunters responded by threatening to disclose details of cl0p’s internal operations.
Reuters could not independently establish the accuracy of the competing claims.
Cl0p has built a reputation as one of the most active cybercrime groups targeting enterprise software. In 2023, the group exploited a vulnerability in MOVEit file-transfer software, leading to data breaches affecting more than 600 organisations and tens of millions of people.
The group has also claimed responsibility for more recent data theft campaigns involving major companies across different sectors.
ShinyHunters has likewise been linked to a series of high-profile breaches. In April, the group claimed to have stolen millions of business records from Rockstar Games, the developer of Grand Theft Auto. In May, a separate attack involving education technology company Canvas caused disruption across U.S. schools.
The latest confrontation illustrates another risk within the cybercrime ecosystem: criminal groups that normally compete for victims and stolen data can also become targets of one another.
For security researchers, the incident could provide an unusual glimpse into the internal conflicts, vulnerabilities and relationships that exist within the wider cybercrime underground.














