ShinyHunters Extorts Cl0p, Victim Data at Risk
ShinyHunters set an eight-figure ransom demand against Cl0p and threatened to publish records identifying companies that paid the ransomware gang.

ShinyHunters sent Cl0p an eight-figure ransom demand over the weekend, claimed to hold payment records from the ransomware gang’s prior victims, and gave Cl0p 24 hours before escalating the terms further, according to The Record. Cl0p responded by Monday in an apparent attempt to establish contact, which is the first indication that the operational disruption is real.
This follows the group’s takeover of Cl0p’s dark web leak site, reported here on Saturday. The new development is what ShinyHunters now claims to hold and what they intend to do with it.
What is being threatened
The demand was framed as “2.333% of Cl0p’s purported net worth,” a construction that implies ShinyHunters believes Cl0p holds several hundred million dollars in assets. Within 24 hours, the terms expanded to include a public apology from Cl0p and a share of proceeds from the gang’s Oracle E-Business Suite campaign. Posted on the hijacked site: “Clock is ticking moron. Kindly excuse our unprofessionalism.”
The more consequential element is the data. ShinyHunters claims to possess records identifying which organizations paid Cl0p ransoms, the amounts paid, and associated Bitcoin addresses. The authenticity of those records has not been independently verified. Cl0p’s apparent decision to seek contact rather than go quiet suggests the threat landed.
What this means for past Cl0p victims
[Analysis] Any organization that paid Cl0p is now in a position where its ransom payment could become public, and could become the basis for a second extortion attempt from a different actor. If ShinyHunters publishes the records, those organizations face reputational exposure and, in regulated industries, questions about whether payments were disclosed appropriately and whether the payment amounts match what was reported internally.
The double-extortion model that Cl0p helped establish — pay the ransom or we publish your stolen data — is now being applied to Cl0p itself. Whether ShinyHunters follows through depends on whether Cl0p pays, whether there is a viable secondary market for leaked ransom-payment records, and how much the operational disruption has weakened Cl0p’s position. None of those factors are visible from the outside yet.
Why this started
ShinyHunters attributed the confrontation to two grievances, per The Record: Cl0p’s use of an Oracle vulnerability that ShinyHunters had publicly released, and threats made against a ShinyHunters member. The Oracle E-Business Suite campaign listed in the escalated demand aligns with Cl0p’s documented recent activity against Oracle-using enterprises. The technical specifics of the dispute between the two groups are unverified.
ShinyHunters specializes in social engineering and data extortion rather than ransomware deployment. That distinction matters here. The group’s 2026 activity follows a pattern of data theft followed by escalating payment demands, not operational disruption of a competitor for market reasons. This looks like an opportunistic leverage play, not a turf war.
The pattern
[Analysis] The cybercriminal economy is not a cooperative. Data stolen from one group’s operations, leverage applied sideways, ransom mechanics turned inward: this is what happens when the tools of extortion are portable and the data keeps existing long after the original incident. Organizations that paid Cl0p to make data disappear are now finding that the data — and the fact of payment — may have had a longer life than anyone in those negotiations anticipated.
Cl0p has made no public statement. The story is still developing. Prior Cl0p coverage: Ransomware Attacks on Manufacturers Up 40% in H1 2026. Topic: ransomware.
Found this useful? Share it.


