Clop gets a taste of its own medicine after ShinyHunters hijack leak site

Summary

The ShinyHunters threat actor group has reportedly hijacked the leak site used by the Clop ransomware gang. ShinyHunters is now demanding an eight-figure ransom and threatening to expose companies that previously paid Clop to keep their stolen data private.

IFF Assessment

FOE

This indicates a shift in threat actor dynamics and potentially new extortion tactics, which is bad news for defenders.

Defender Context

This incident highlights the dynamic and often opportunistic nature of threat actor ecosystems. Defenders should be aware that data previously exfiltrated by one group might be re-leveraged or exposed by another, increasing the risk of secondary breaches and reputational damage for victim organizations.

Read Full Story →