← Back to Feed
ShinyHunters Hacked Clop. Now What About Clop's Victims?
September 21, 2026 · Dark Reading · Severity: MEDIUM
ShinyHunters defaced Clop's Dark Web site and claims to have stolen victim data, potentially exposing organizations that paid ransoms to renewed extortion attempts.
Key Takeaways
- ShinyHunters hacked the Clop ransomware leak site, raising questions about the fate of Clop's victims' data now that a rival criminal group controls the extortion infrastructure.
- The takeover of Clop's leak site by ShinyHunters creates uncertainty for organizations previously targeted by Clop, as their stolen data may now be in the hands of a different threat actor.
- This incident demonstrates the volatile nature of ransomware group infrastructure and the importance of assuming leaked data is permanently exposed regardless of which group controls the leak site.