ShinyHunters Hijacked Dark Web Site of Cl0p

The cybercrime group gained control of the Cl0p site by exploiting a software vulnerability.

Updated on Sept. 21, 2026 in Cybersecurity

Isometric editorial illustration of interlocking geometric steel data-lattices and metallic conduits, representing compromised digital infrastructure.
The cybercrime group ShinyHunters seized control of rival gang Cl0p's dark web site after exploiting a software vulnerability in the group's infrastructure. AI Illustration. Upload story photo >

Live Poll

Do you trust that law enforcement can effectively stop large-scale cybercrime rings?

The cybercrime group ShinyHunters successfully hijacked the dark web site belonging to the rival hacking gang Cl0p. The takeover followed an alleged dispute over the theft of a software exploit.

Why it matters

The breach highlights the aggressive and volatile nature of cybercrime syndicates that frequently turn against one another over stolen tools and intellectual property. This move disrupts the infrastructure of a group historically known for massive data theft operations.

Cl0p has previously utilized significant vulnerabilities to breach security, including a MOVEit software bug that affected 600 companies and an Oracle E-Business Suite flaw impacting over 100 firms.

The players

ShinyHunters

This is a well-known cybercrime group that frequently targets organizations to exfiltrate and leak sensitive data.

Cl0p

Cl0p is an infamous cybercrime gang recognized for executing large-scale ransomware and data extortion attacks.

The details

ShinyHunters claimed to have discovered a vulnerability in Cl0p software, which they subsequently used to seize control of the group's dark web infrastructure. The site briefly displayed a message stating the domain had been seized before becoming entirely unreachable.

Timeline

  1. In 2023, Cl0p exploited a MOVEit software bug to target hundreds of companies.

  2. On September 18, 2026, ShinyHunters reportedly broke into the Cl0p dark web site.

  3. On September 19, 2026, the site displayed a seizure message.

  4. On September 20, 2026, the Cl0p dark web site became unreachable.

The Tech Race

This incident follows the pattern of large-scale infrastructure exploitation established by the 2023 MOVEit software vulnerability exploitation. It represents a significant paradigm shift where high-profile cyber-extortionists are now being successfully targeted by their own peers.

For security professionals and IT administrators, this event underscores the persistent threat of software vulnerabilities being exploited in the wild. While the hijacking is a criminal-on-criminal action, it serves as a reminder to prioritize the patching of enterprise software.

The takeaway

The event serves as a stark reminder that even cybercriminal syndicates are vulnerable to the same exploitation tactics they use against others. Vigilance in maintaining secure, updated software remains the primary defense for all organizations.

Further reading

Learn more about the latest developments in Cybersecurity.

Live Poll

Do you trust that law enforcement can effectively stop large-scale cybercrime rings?

ShinyHunters Hijacked Dark Web Site of Cl0p