Security1 publisher2 min readPublished
Clop asks ShinyHunters to come online from the leak site ShinyHunters defaced
For two days ShinyHunters published eight-figure demands on Clop's onion address and served Salesforce data through it. On September 21 a short message attributed to Clop appeared there instead, asking for contact.
The Watch · Security desk

What happened
- Hackread.com reported on September 19 that Clop's dark web leak site had been replaced with ShinyHunters material, after directly observing the takeover of the onion address.
- ShinyHunters used the seized page to demand an eight-figure payment from Clop, with an email contact instruction, a deadline and a threat if the gang refused to engage.
- Later on September 21 the ShinyHunters content was gone and a short message attributed to Clop stood on the address, saying ShinyHunters' email did not work.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure If ShinyHunters really holds Clop's payment records, every company that quietly paid is exposed by a party it never negotiated with, and the amount and the wallet go out with the name.
- constraint Clop's own message says its email channel is dead, so a victim trying to verify a listing or open talks has no reliable line to the group holding its files.
- contradiction Hackread.com can confirm what the page displays but not who runs the server, so the reappearance of a Clop message is not proof that Clop got its infrastructure back.
- precedent One crew serving another crew's stolen data from a branded onion address means leak-site content now evidences who controls the host, not who did the intrusion.
A leak site is the part of an extortion operation that victims actually touch. It is where a company checks whether it is listed, pulls a sample to confirm the files are real, and reads the instructions for opening negotiation. Between September 19 and September 21, two days, Clop's onion address carried ShinyHunters' material instead [1][17]. Visitors to it could download the Salesforce-related data ShinyHunters had also published on its own leak site [2].
The ransom note on that page was addressed to Clop itself. On September 19 ShinyHunters demanded an eight-figure payment, told Clop to make contact by email, and attached a deadline and a threat [3]. A day later the message named two individuals, "Likhogray & Tarasov", and told them to get their boss, "j0nny", to respond [4]. ShinyHunters said it wanted the money Clop allegedly made from its Oracle E-Business Suite campaign, plus a further amount and interest [5]. By September 21 it had added a clock: demands rise for every 24 hours Clop stays quiet, and it wants a public apology [8].
ShinyHunters also threatened to publish what it says it holds on companies that paid Clop, including the amounts and the Bitcoin addresses used for the payments [6]. Hackread.com said it has not independently verified that ShinyHunters has those records [7].
Later on September 21 the ShinyHunters material was gone from the onion address and a short message directed at the group sat in its place [9]. "Shiny Hunters we trying to reach you Your email does not work. Come online old platform no email," the message read [10]. It does not identify the platform [12]. Hackread.com said the message alone does not establish whether Clop has fully regained control of the underlying infrastructure or whether ShinyHunters retains access [11].
ShinyHunters' own onion site was unreachable for several hours during the dispute. Asked whether that was connected to the Clop attack, the group told Hackread.com: "There was a few hour downtime due to network issues that are not related to the Clop incident." [13] It did not answer the other questions put to it, about how far its access into Clop's infrastructure went, whether it took data from Clop, or whether it controlled additional systems [14].
Reuters reported on September 21 that ShinyHunters traces the fight to an Oracle E-Business Suite zero-day it says it found first and Clop then used in attacks, an account Reuters said it could not independently establish [15]. Clop has operated since at least 2019 [16], seven years before the messages Hackread.com observed this month [18].
What to watch
- Whether ShinyHunters publishes the claimed records of Clop payers, with amounts and Bitcoin addresses.
- Whether Clop resumes victim listings on the same onion address or stands up a new one.
- Whether anyone corroborates ShinyHunters' claim that it found the Oracle E-Business Suite zero-day before Clop used it.