ShinyHunters defaced Cl0p's dark web site over the weekend, threatening to publish records of companies that paid ransoms to Cl0p, including how much was paid.
What happened
ShinyHunters hijacked the dark web leak site Cl0p has used for years to name victims and pressure them into paying, then used it against Cl0p itself, The Record reported on September 21, 2026. The site was defaced with a banner stating the domain had been seized. Messages posted there set an unspecified eight-figure demand, which the author described as 2.333% of ShinyHunters' own net worth. The group said its demands would rise every 24 hours that Cl0p failed to respond, and by Monday had added a requirement that Cl0p apologize publicly. A message posted Sunday named three people identified as Cl0p operators, all previously named in public reporting.
Going deeper
The dispute traces to Oracle's E-Business Suite, a widely used business software platform. ShinyHunters published a working demonstration of an exploit for a vulnerability in it on Telegram, and Cl0p then ran a campaign against the platform using that vulnerability, attacks that prompted warnings from Oracle, the FBI, and cybersecurity agencies in two other countries. ShinyHunters says the feud stems from unauthorized use and from threats made against one of its members. Its demands include the proceeds of the Oracle campaign. By Monday, the defaced site had been replaced with a message apparently from Cl0p reading: "Shiny Hunters, we're trying to reach you. Your email does not work. Come online old platform no email."
What was said
"I hope you can pay that much because that is the demand, negotiable. Get your bosses in front of the white board in the war room. The clock is ticking, moron. Kindly excuse our unprofessionalism," the notice on the seized site read, according to The Record. A later message added, "Be sure to bring an English interlocutor so you can comprehend my literacy in acquiring your bank account." Alongside the demand, ShinyHunters threatened to release records showing which companies paid Cl0p, how much they paid, and which Bitcoin addresses were used.
In the know
Cl0p built its earnings on vulnerabilities in file transfer software, the products organizations use to move large files between systems and partners. It is believed to have made hundreds of millions of dollars exploiting previously unknown flaws in products from Cleo, MOVEit, GoAnywhere, and Accellion, The Record has documented across those campaigns. Healthcare organizations featured heavily among the victims, since file transfer tools carry claims files, enrolment data, and records moving between providers, payers, and vendors. ShinyHunters has its own healthcare record, having taken information belonging to more than four million people in an April attack on a medical device manufacturer.
The big picture
Payment records becoming public is the part healthcare compliance teams should think through. An organization that paid Cl0p during one of those campaigns and settled the matter privately has no control over a disclosure made by a third party years later. Treasury's Office of Foreign Assets Control advises that companies facilitating ransomware payments may risk violating sanctions regulations, and that reporting the incident to and cooperating with US government agencies at the time counts as a mitigating factor in any enforcement action. The advisory reaches beyond victims to financial institutions, cyber insurance firms, and incident response companies involved in the payment. Organizations with a payment in their history should establish now what was documented, whether law enforcement was notified, and who holds the record, rather than assembling that answer after a leak site publishes it.
FAQs
Does paying a ransom have to be disclosed?
No general federal requirement exists, though publicly traded companies assess materiality for securities disclosure, and a ransomware incident involving protected health information triggers HIPAA breach notification regardless of whether payment occurred. The payment itself is usually not part of that notice.
What sanctions risk attaches to a ransom payment?
Payments to individuals, groups, or jurisdictions on Treasury's sanctions lists can violate US sanctions law even where the payer does not know the recipient's identity. Organizations generally route these decisions through counsel and report to law enforcement partly to establish the mitigating factors the advisory describes.
Why would one criminal group extort another?
Criminal operations hold funds, infrastructure, and records that have value, and they cannot report a theft to the police. Disputes over shared exploits, affiliate payments, and territory have produced public conflicts before, though a full leak site takeover is unusual.
Should an organization treat claims on a leak site as reliable?
No. Material posted by criminal groups is unverified and frequently exaggerated, including claims about who paid and how much. Organizations named in such a release should confirm against their own records before responding publicly.
What is a file transfer product and why do attackers target them?
Software used to move large or sensitive files between organizations, often holding data in transit from many clients at once. A single flaw can therefore expose records belonging to hundreds of organizations, which is what made these campaigns so widely damaging.
