On 19 September, the extortion group ShinyHunters broke into the dark web leak site run by Cl0p, one of the most prolific ransomware operations of the past two years, and defaced it. Three days later Cl0p was still trying to regain control, and every company that quietly paid Cl0p to make a breach disappear had a new, uncomfortable question to answer.
What ShinyHunters Actually Took
ShinyHunters exploited an unauthenticated file upload flaw in Grav CMS, the content management software Cl0p used to run its own site, and used the access to claim Cl0p’s source code, its CMS plugins, its system logs, and the private cryptographic keys protecting Cl0p’s Tor hidden service address. The keys matter more than the defacement. As ShinyHunters put it, having Cl0p’s onion keys means it can run the same dark web address from its own infrastructure even if Cl0p regains its server, so if Cl0p kicks the group out, ShinyHunters claims, it would not matter at all.
The Demand Escalates by the Day
The initial demand, made on 19 September, was an eight-figure sum, which ShinyHunters described as 2.333% of its own claimed net worth. By 21 September the group had raised the price to everything Cl0p made from its 2025 Oracle E-Business Suite data theft campaign, plus more, and with interest, adding a demand for a public apology and a clause that the total rises every 24 hours Cl0p stays silent. Cl0p’s own response, once it regained partial control of the site, was to remove the defacement and claim ShinyHunters’ contact email did not work, an avoidance move rather than a denial.
Why This Should Worry Organisations That Paid Cl0p, Not Just Cl0p
ShinyHunters has also threatened to publish the identities of every company that paid Cl0p a ransom, the amounts involved and the Bitcoin addresses used to pay it, tied directly to Cl0p’s Oracle EBS campaign. That threat has nothing to do with any organisation’s own security posture today. It depends entirely on whether a rival criminal group decides to make good on an extortion demand against a competitor, a decision an affected company has no way to influence and no visibility into. Any organisation that treated a Cl0p ransom payment as a closed incident, in exchange for a deletion promise from a criminal group, is discovering that a criminal’s word was never the same thing as a resolved risk.
The Real Governance Lesson Here
None of this is confirmed by Cl0p or by a neutral party. Every figure above comes from ShinyHunters’ own claims, corroborated across multiple independent outlets but not yet verified by Cl0p or a third party. That uncertainty is itself worth carrying into the next risk review. An incident an organisation paid to make disappear can resurface years later, at a time and in a form it does not control, because the decision to disclose sat with a criminal the whole time, not with the organisation that paid. The practical question for this quarter is not whether an organisation is a past Cl0p victim. It is whether legal and the incident response lead have already agreed what happens the day a rival gang publishes that answer for them.