Clop gets a taste of its own medicine after ShinyHunters hijack leak site
Summary
The ShinyHunters threat actor group has reportedly hijacked the leak site used by the Clop ransomware gang. ShinyHunters is now demanding an eight-figure ransom and threatening to expose companies that previously paid Clop to keep their stolen data private.
IFF Assessment
FOE
This indicates a shift in threat actor dynamics and potentially new extortion tactics, which is bad news for defenders.
Defender Context
This incident highlights the dynamic and often opportunistic nature of threat actor ecosystems. Defenders should be aware that data previously exfiltrated by one group might be re-leveraged or exposed by another, increasing the risk of secondary breaches and reputational damage for victim organizations.