:

SHINYHUNTERS HIJACKS CL0P RANSOMWARE GANG'S DARK WEB SITE

SECURITY DESK1 MIN READ
TUE, SEP 22, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

The ShinyHunters extortion group took control of the dark web leak site belonging to the prolific Cl0p ransomware gang over the weekend. The attackers set an eight-figure extortion demand pegged at 2.333% of Cl0p's estimated net worth.

ShinyHunters posted materials on Cl0p's compromised site announcing the hijacking and financial demand. The specific percentage calculation suggests the group has attempted to estimate Cl0p's total assets before setting the ransom figure. Cl0p has been one of the most active ransomware operations globally, responsible for high-profile breaches affecting major corporations and organizations. The gang typically exfiltrates data before encrypting systems, then uses dark web leak sites to pressure victims into paying ransoms. This incident represents a significant breach of the criminal operation itself. Hijacking a ransomware gang's leak site could expose internal communications, victim data, or operational details. The ShinyHunters group has previously targeted databases and stolen information, but extending operations to extort fellow cybercriminals marks an escalation in criminal-on-criminal attacks. The development underscores ongoing instability within dark web criminal ecosystems and competition between extortion groups.

■ SOURCES

Techmeme

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

The FBI's CJIS Security Policy v6.1 strengthens encryption requirements and vulnerability scanning mandates. Agencies must prepare for updated password, MFA, and identity verification standards ahead of compliance audits.

2H AGOSecurity Desk

New research reveals that digital watermarks intended to protect content ownership are being repurposed as surveillance mechanisms to track user behavior and identify individuals across platforms.

2H AGOIndustry Desk

Donating or recycling an old laptop is environmentally responsible, but failing to erase your data first can expose personal information to new owners or data recovery specialists.

5H AGOIndustry Desk

BigCommerce has alerted merchants to a data breach stemming from compromised Ribon app credentials. Attackers used the stolen access to inject malicious scripts into online stores.

6H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.