Jakarta, ThedailyID — Cybercrime group ShinyHunters claims it hacked the dark web site of rival group Cl0p, exposing a long-running dispute between the two groups.
ShinyHunters is known for large-scale data theft and digital extortion. The group said it breached Cl0p’s dark web infrastructure on Friday, September 18.
ShinyHunters said it found a weakness in Cl0p’s software. The group then used the vulnerability to gain control of its rival’s infrastructure.
“Basically, we have it now,” ShinyHunters said, according to Reuters on Thursday, September 24.
Cl0p’s dark web site became inaccessible on Sunday. A day earlier, the site reportedly displayed a message stating, “Domain Seized By ShinyHunters.”
The incident highlights an unusual conflict between cybercrime groups. Brandon Parsons, a threat intelligence manager at Ascent Solutions, said rivalries within the dark web community do exist.
Joe Roosen, senior director of security research at SpyCloud, said he had rarely seen cybercriminal groups confront each other so openly.
“This is really a surprise. I rarely see these criminals fighting each other,” Roosen said.
The dispute reportedly began over an alleged software exploit from last year. The issue involved a vulnerability in Oracle’s E-Business Suite, or EBS.
Hackers used the zero-day vulnerability to gain broad access to vulnerable networks. Google analysts estimated that Cl0p used the vulnerability to steal data from more than 100 companies.
However, ShinyHunters claimed it discovered the zero-day vulnerability first. The disagreement between the groups then escalated.
According to the report, Cl0p threatened to expose the identities of some ShinyHunters members. ShinyHunters responded by threatening to reveal details about Cl0p’s internal operations.
Cl0p is considered one of the most active cybercrime groups. It has gained attention for finding and exploiting vulnerabilities in enterprise software.
In 2023, Cl0p exploited a vulnerability in MOVEit file-transfer software. The campaign affected more than 600 companies and exposed data belonging to tens of millions of people.
Last month, Cl0p also claimed to have stolen large amounts of data from nearly 50 companies worldwide. The reported victims included Philips, Shell, Fiserv, and GE Aerospace.
ShinyHunters has also claimed several major attacks. In April, the group claimed to have stolen millions of business records from Rockstar Games, the developer of Grand Theft Auto.
In May, the group targeted the Canvas education platform. The incident caused disruptions across schools in the United States.
Anthropic also disclosed this month that hackers linked to ShinyHunters had attempted to misuse its Claude AI system to assist cyberattacks.
The alleged attack on Cl0p now adds another layer to the rivalry between major cybercrime groups. It also offers a rare public glimpse into conflicts that typically remain hidden within the dark web.





