SEPTEMBER 23, 2026
On the night of 19 September 2026, anyone visiting Clop’s data leak site found a message that was not written by Clop. ShinyHunters had broken into the server and replaced the page, first with a text file mocking the group and then with its own ASCII art logo. A ransomware leak site is where an extortion group names the organisations that did not pay and publishes their data. When that site is itself compromised, the question for every company listed on it changes. It is no longer only what Clop will do next. It is who else now holds the data, and who can speak in Clop’s name.
| 72 hrs The deadline ShinyHunters said it would give Clop to make contact before extorting it (Source: ShinyHunters statement, September 2026) | 4,442 Victim negotiation messages exposed when another ransomware panel was breached (Source: leaked LockBit panel database, May 2025) | 59,975 Bitcoin addresses in that same leaked ransomware database (Source: leaked LockBit panel database, May 2025) | Aug 9 Earliest confirmed exploitation in the 2025 Oracle EBS campaign at the root of this feud (Source: Google Threat Intelligence Group, October 2025) |
According to ShinyHunters, the way in was an unauthenticated file upload flaw in the content management system that ran the site. The first visible change was a text file reading “THIS SITE HAS BEEN PWN3D BY SHINYHUNTERES #Skids10p – Maybe don’t try to threaten us next time.” Hours later the entire page was replaced with the group’s logo and the line “rooting your systems since ’19 ;)”.
The defacement itself was confirmed independently while it was live. The rest are claims. ShinyHunters says it took the site’s source code and plugins, system logs from the server, and the private keys for Clop’s Tor onion service. “We have their onion keys,” the group said. “So if they kick us out it wouldn’t matter at all because we control the private keys.” None of those claims had been independently verified at the time of writing, and Clop had not responded. ShinyHunters said it would post a message giving Clop 72 hours to make contact.
The dispute goes back to the Oracle E-Business Suite campaign of 2025. Google Threat Intelligence Group tracked extortion emails sent to executives at numerous organisations from 29 September 2025, tied to exploitation of CVE-2025-61882 that it confirmed as early as 9 August 2025. ShinyHunters, then operating as part of Scattered Lapsus$ Hunters, leaked a matching proof of concept in October 2025 and has since claimed that Clop stole its exploit. The ransomware leak site takeover is the latest move in that argument, and victims are standing in the middle of it.
On 7 May 2025 LockBit’s dark web panels were defaced with the message “Don’t do crime CRIME IS BAD xoxo from Prague”, and a database dump from the operation’s panel was published alongside it. The contents were not about LockBit alone. The dump held 59,975 unique bitcoin addresses, 4,442 negotiation messages exchanged with victims between 19 December and 29 April, and 75 administrator and affiliate accounts, some with passwords stored in plain text. LockBit’s operator confirmed the breach and insisted that no private keys were leaked and no data was lost.
For the organisations in those chats, the practical result was that a negotiation they had assumed was private became readable by anyone who downloaded the file: what was asked, what was offered and, in some cases, what was paid. The lesson carries directly to Clop. A criminal operation’s infrastructure has no incident response team, no disclosure obligations and no reason to protect the people whose data it holds.

If the claims about server access are accurate, anything hosted on or reachable from that server should be assumed to be in more than one set of hands. Deletion promises, never worth much, are now worth nothing, because the party making them no longer controls every copy.
A Tor onion address is tied to its private key. Whoever holds the key can publish at that address. If ShinyHunters does hold Clop’s keys, a listing, a deadline or a sample file posted under Clop’s banner no longer proves that Clop posted it. Security teams, journalists and regulators who read leak sites as a record of fact will need to treat each new post as a claim until its origin is established.
The LockBit dump showed that operator logs and chat records survive on these servers. If Clop’s logs were taken, the record of who negotiated, when and on what terms may appear in front of insurers, regulators, litigants or the press, long after the incident was considered closed.
A group holding a victim list, contact details and proof files can approach those victims directly, either impersonating the original operator or offering to “handle” the data for a fee. The organisation receiving that message has no reliable way to tell which group it is talking to.
An ecosystem that was already fragmented now has two groups competing to use one brand. Any report that counts listings on Clop’s site over the coming weeks will have to account for the possibility that some of them were not placed there by Clop.
The value of watching a ransomware leak site used to be simple: it told you what the group had published. After a takeover, the work shifts to following where the data goes next and who is claiming it.
| Capability | How It Addresses a Compromised Leak Site |
| Leak site and mirror monitoring | Watches Clop’s leak site, its mirrors and any new address that begins publishing Clop listings, so a relisting under a different banner is caught the day it appears. |
| Ransomware group feud tracking | Follows the Clop and ShinyHunters dispute across forums and Telegram, including claims about stolen keys, logs and victim data, with the source of each claim attached. |
| Dataset repost surveillance | Detects files from a listing when they are reposted, split or sold in Telegram channels and forums after the original site changes hands. |
| Credential exposure from stolen files | Surfaces employee and service credentials contained in leaked datasets so they can be rotated before a second holder uses them. |
| Supplier listing alerts | Alerts when a supplier or partner appears on the site, since your data may sit inside their stolen files rather than your own. |
RELATED READING
146 Active Groups and Counting: Why Ransomware Fragmentation Makes Attribution Harder Than Ever: https://brandefense.io/blog/ransomware-fragmentation-attribution-146-groups-2026/ : the wider fragmentation that a contested brand like Clop now adds to.
Top 5 Ransomware Groups in Q2 2026: Who They Are, How They Operate, and What They Target: https://brandefense.io/blog/top-5-ransomware-groups-q2-2026/ : where Clop and its peers stood before this feud broke into the open.
What Is Triple Extortion? The Anatomy of the Encryption + Leakage + DDoS Trio: https://brandefense.io/blog/what-is-triple-extortion/ : the extortion model that makes the leak site the centre of the pressure campaign.
Leaked Credentials from Ransomware Groups: Case Insights: https://brandefense.io/blog/leaked-credentials-from-ransomware-groups/ : what credentials inside ransomware leaks are used for once they spread.
Criminal infrastructure fails the way any other infrastructure does, with one difference: when it fails, the people who pay are the ones it was built to pressure. For organisations listed on a ransomware leak site, the useful assumption from this week on is that the listing is no longer the end of the story, and possibly no longer written by the group whose name is on it.

Take control of your digital security with an exclusive demo of our powerful threat management platform.