01Summary
Starting on 18 September 2026, ShinyHunters defaced Cl0p's Tor leak site with its Umbreon logo and the message "rooting your systems since '19 ;)". It claimed to have taken source code, server logs and the private keys for Cl0p's onion address. It demanded an eight-figure sum that would rise every 24 hours, and threatened to publish details of companies that had paid Cl0p, including payment amounts. On 21 September Cl0p posted: "Shiny Hunters we trying to reach you. Your email does not work." ShinyHunters rejected the approach.
02Victims and impact
Countries affected
- Global
03Data exposed
Data types
- Ransomware gang source code (claimed)
- Server logs (claimed)
- Onion service keys (claimed)
- Victim payment records (threatened)
04Timeline
- 2026-09-18ShinyHunters defaces Cl0p's leak site.
- 2026-09-21Cl0p publicly tries to contact ShinyHunters.
05On the record
Shiny Hunters we trying to reach you. Your email does not work. Come online old platform no email
06Significance and legacy
Significance
A rare public war between two of the biggest extortion crews. It could expose Cl0p's infrastructure and paying victims.
07Disclosure and media
Publishing organisations
- BleepingComputer
- SOCRadar
09Field notes
- 01The defacement replaced Cl0p's leak site with ASCII art of the Pokémon Umbreon.
10Sources
References
- [1]BleepingComputer: https://www.bleepingcomputer.com/news/security/shinyhunters-hacks-clop-leak-site-threatens-to-extort-ransomware-gang/
- [2]SOCRadar: https://socradar.io/blog/clop-hack-shinyhunters-hijacks-data-leak-site/









