ShinyHunters, one of the world’s most prominent cybercrime groups, says it has hijacked the dark-web infrastructure of rival hacking gang cl0p, exposing an unusually public feud between two major players in the cybercrime ecosystem.
The data-extortion group said Sunday that it breached cl0p’s dark-web site on Friday after finding a vulnerability in software used by the rival gang. ShinyHunters claimed the flaw gave it broad control over cl0p’s infrastructure.
“We basically own them now,” ShinyHunters told Reuters in an online chat.
Register for the next Tekedia Mini-MBA.
Register for Tekedia AI in Business Masterclass.
Join Tekedia Capital Syndicate and co-invest in great global startups.
Cl0p’s dark-web site was inaccessible when Reuters attempted to visit it on Sunday. A screenshot preserved by cybersecurity research platform eCrime.ch showed the site on Saturday displaying the message, “Domain Seized By ShinyHunters.”
Two cybersecurity experts told Reuters that the confrontation appeared to be genuine, although the details provided by ShinyHunters about the dispute could not immediately be independently verified.
“Street beefs on the dark web are a real thing,” said Brandon Parsons, a threat intelligence manager at Minnesota-based Ascent Solutions.
Joe Roosen, senior director of security research at SpyCloud, said he had rarely seen rival cybercrime groups confront each other so openly.
“This was a twist for sure,” he said. “It is rare I get to see these criminals fight each other.”
The reported breach is significant not because cybercriminals attacking one another is entirely unprecedented, but because both groups occupy an important position in the global ransomware and data-theft economy. Their dispute also illustrates how vulnerabilities in the infrastructure used by criminals can become weapons against the attackers themselves.
Feud Dates Back To Oracle Vulnerability
ShinyHunters said its conflict with cl0p dates to last year’s exploitation of a previously unknown vulnerability in Oracle’s E-Business Suite, enterprise software widely used by large organizations.
Such vulnerabilities, known as zero-days, are particularly valuable because defenders have had no prior opportunity to patch the underlying flaw. An attacker who discovers one can potentially gain access to systems before security teams know the vulnerability exists.
Cl0p, a Russian-speaking cybercrime group, exploited the Oracle vulnerability to steal data from more than 100 companies, according to a Google analyst cited by Reuters. ShinyHunters told Reuters that it had discovered the vulnerability first.
The disagreement subsequently escalated. According to ShinyHunters, cl0p threatened to expose the identities of several ShinyHunters members, while ShinyHunters threatened to reveal information about cl0p’s internal operations.
Reuters said it could not independently establish the accuracy of ShinyHunters’ account of the feud.
The episode nonetheless underscores an unusual feature of the cybercrime economy: the same weaknesses in software, infrastructure and operational security that criminals exploit against businesses can also expose the criminals themselves.
Cl0p has built a reputation for exploiting vulnerabilities in widely used enterprise software. In 2023, the group exploited a flaw in MOVEit file-transfer software, compromising data belonging to more than 600 organizations and affecting tens of millions of people.
More recently, cl0p claimed to have stolen data from dozens of companies, including Philips, Shell, Fiserv and GE.
ShinyHunters has also conducted large-scale data theft campaigns. The group attracted attention in April after claiming to have stolen millions of business records from video game developer Rockstar Games. In May, a hack targeting education technology platform Canvas caused widespread disruption across U.S. schools.
The group has also been intersecting with the AI sector. Anthropic said this month that it had detected hackers linked to ShinyHunters attempting to use its AI tools.
The alleged takeover of cl0p’s infrastructure adds another layer to that activity. If ShinyHunters’ claims are accurate, the incident demonstrates that cybercriminal organizations are not operating in isolation. They compete for vulnerabilities, stolen data, infrastructure, and access, creating a criminal marketplace in which one group’s security failure can become another group’s opportunity.
Thus, the episode offers businesses a reminder that cyber threats do not depend solely on sophisticated attacks against corporate networks. The infrastructure and software surrounding criminal campaigns are themselves vulnerable. The fact that rival groups can potentially compromise one another also shows how quickly control over stolen data and hacking infrastructure can change hands.



