Skip to content

Security1 publisher2 min readPublished

ShinyHunters threatens to name companies that paid Clop after defacing its leak site

ShinyHunters defaced Clop's leak site, demanded an eight-figure sum and threatened to name firms that allegedly paid Clop in the Oracle EBS campaign. Only ShinyHunters vouches for its theft claims. The firms it would name are victims whose payments were meant to stay private.

The Watch · Security desk

Photograph accompanying ShinyHunters threatens to name companies that paid Clop after defacing its leak site
Photo: hackread.com

What happened

  • ShinyHunters defaced the Tor data leak site run by the Cl0p ransomware gang, SecurityWeek reported.
  • It threatened to expose companies that allegedly paid Clop during Clop's Oracle E-Business Suite campaign.
  • ShinyHunters calls the attack payback for threats it says a Clop representative made in a feud dating to that campaign.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Oracle E-Business Suite victims that paid Clop face public disclosure of the payment itself, the fact a quiet settlement was bought to keep out of view.
  • constraint A ransom paid to Clop bound only Clop, so the silence it bought does not hold once a rival claims Clop's logs and keys.
  • capability If the onion-service keys are genuine, their holder can publish at Clop's own address, so a naming post there cannot be trusted as Clop's.

Only one part of this is on the record as done. SecurityWeek reports the defacement of Clop's Tor leak site as fact [1]. Everything else comes from ShinyHunters itself. That covers the server logs, the source code and the onion-service private keys it says it took [2], and the grudge it gives as its reason [5].

The threat to name payers is the part that reaches past the two gangs. ShinyHunters says it will expose companies that allegedly paid Clop during the Oracle E-Business Suite campaign [4]. Those companies were breached once already. What they paid Clop put no obligation on a rival that now says it holds Clop's files [2].

The account does not say ShinyHunters has published any names yet, or that the logs it claims to hold include payment records. The phrase in SecurityWeek's report is companies that "allegedly paid" [4]. A list built on guesses would still land on real organizations. One pulled from Clop's own server logs would also be hard for a named company to dispute.

Test the onion keys first. If they are genuine, whoever holds them can run a site at Clop's own address [2]. A post there naming payers would sit at the address Clop used, with Clop no longer in control of it, until Clop moves to a new address or shows it still holds the key.

On the record, this is a feud between two extortion groups. ShinyHunters wants an eight-figure payment and a public apology [3]. Its leverage is the threat to name the companies that paid [4]. It traces the dispute to threats it says a Clop representative made during the Oracle campaign [5].

Scope is narrow. Organizations that were not Clop victims in the Oracle E-Business Suite campaign have nothing new to act on here. For victims that paid, the risk is that an incident they settled gets disclosed a second time, and this time the disclosure includes the payment [4].

What to watch

  • Whether ShinyHunters publishes any company names, and whether they match known victims of the Oracle E-Business Suite campaign.
  • Whether Clop moves its leak site to a new onion address, which would support the claim that its private keys were taken.
  • Any response from Clop to the eight-figure demand or the call for a public apology.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories