ShinyHunters Hijacks Cl0p Domain in Oracle Zero-Day Feud; 100+ Firms Impacted
ShinyHunters claims it seized cl0p's dark web infrastructure after a dispute over an Oracle E-Business Suite zero-day that hit more than 100 companies. Threat intelligence teams should view the public feud as a rare window into criminal infrastructure and possible leaked victim data. Monitoring for follow-on disclosures is the immediate priority.
Beat this week
Last 7 days · Threat Intelligence
Impact 6.4/10 (+0.1 vs prior). Counts are stories in our record, not a market forecast.
Open the change reportCoverage balance Negative coverage leads. Negative coverage exceeds positive coverage by 44 percentage points.
This story sits in Threat Intelligence — the counts compare this beat's last 7 days with the previous 7 in our verified record, not a market forecast.
Figures are computed live from our source-verified story record (as of ) The volume change compares this window with the prior 7 days in the same record. — see our methodology for how impact and sentiment are derived.
Cybersecurity briefing
Key takeaways
- ShinyHunters claims it seized cl0p's dark web infrastructure after a dispute over an Oracle E-Business Suite zero-day that hit more than 100 companies.
- Threat intelligence teams should view the public feud as a rare window into criminal infrastructure and possible leaked victim data.
- Monitoring for follow-on disclosures is the immediate priority.
- rappler.com
- bdnews24.com
- 933thedrive.com
- economictimes.indiatimes.com
In this briefing
Mentioned
Key Intelligence
Key Facts
- 1ShinyHunters claimed on Sunday, September 20, 2026 that it hijacked cl0p's dark web site on Friday, September 18, 2026.
- 2On Saturday, September 19, eCrime.ch preserved a screenshot showing cl0p's site displaying 'Domain Seized By ShinyHunters.'
- 3The conflict stems from an alleged theft of a zero-day exploit for Oracle's E-Business Suite; ShinyHunters says it discovered the flaw first.
- 4Cl0p used the EBS vulnerability to steal data from more than 100 companies, according to a Google analyst estimate.
- 5Cl0p did not respond to requests for comment, and Reuters found the dark web site unreachable on Sunday.
- 6Two independent researchers said the clash appears genuine, with SpyCloud's Joe Roosen calling open group-on-group attacks rare.
This was a twist for sure. It is rare I get to see these criminals fight each other.
Reacting to ShinyHunters' claimed hijack of cl0p's dark web site
Analysis
For security operations and threat intelligence teams, a public high-stakes conflict between two top cybercrime groups is more than dark web drama: it is a potential source of leaked internal tooling, victim lists, and operational details. The ShinyHunters-cl0p clash centers on an Oracle E-Business Suite zero-day, and the already compromised 100+ organizations could be re-exposed. Defenders should assume that any data held on cl0p's seized infrastructure is now in rival hands.
On September 20, 2026, ShinyHunters publicly claimed it hijacked the dark web site of rival cybercrime gang cl0p, pulling a long-simmering dispute into the open. The group told Reuters in an online chat that it breached cl0p's infrastructure on Friday, September 18, after discovering a vulnerability in cl0p's own software. By Saturday, September 19, a screenshot preserved by research platform eCrime.ch showed cl0p's dark web domain displaying 'Domain Seized By ShinyHunters.' When Reuters tried to visit the site on Sunday, September 20, it was unreachable, and cl0p did not respond to requests for comment.
The ShinyHunters-cl0p clash centers on an Oracle E-Business Suite zero-day, and the already compromised 100+ organizations could be re-exposed.
Two independent researchers told Reuters the clash appeared genuine. Brandon Parsons, a threat intelligence manager at Minnesota-based Ascent Solutions, called it 'street beefs on the dark web.' Joe Roosen, senior director of security research at Texas-based SpyCloud, said he had never seen one cybercrime group take on another so openly, describing the event as 'a twist for sure.' The fact that security professionals validated the claim matters, because dark web defacements and seizure messages can be staged or fabricated; here, observable infrastructure control and an archived screenshot gave the incident credibility.
The root of the feud is an alleged theft of a zero-day exploit targeting Oracle's E-Business Suite. ShinyHunters says it discovered the flaw first, but cl0p, a Russian-speaking cybercrime gang, allegedly stole the exploit last year and used it to compromise data from more than 100 companies, according to an estimate attributed to a Google analyst. Zero-day exploits are among the most prized tools in cybercrime because they target vulnerabilities that defenders have had no time to patch, allowing broad and stealthy access to networks. Ownership disputes over exploit code are not new, but they rarely escalate into domain seizure and public claims of total infrastructure control.
Cl0p is a prolific extortion group known for mass exploitation campaigns, and its apparent failure to secure its own dark web infrastructure is a significant operational security failure. For ShinyHunters, saying it now owns cl0p's infrastructure is both retaliation and a demonstration of technical capability to other criminals and potential buyers of stolen data. The move also raises the immediate risk of an escalation spiral: both sides have reportedly threatened to expose each other's members and internal workings, and cl0p may now attempt countermeasures against ShinyHunters.
What to Watch
For corporate defenders and threat intelligence teams, the Oracle EBS angle has direct relevance. The zero-day was used to steal data from more than 100 companies, and those organizations may now face renewed exposure if data or access details change hands. Security teams should treat any stolen data or infrastructure associated with cl0p as potentially in ShinyHunters' control and review Oracle E-Business Suite patch levels and unusual activity. The incident also signals that even mature cybercrime groups can be penetrated by the same exploit techniques they wield, a reminder that no actor is invulnerable.
Looking ahead, the conflict may produce an unusual flow of actionable intelligence. When criminal groups fight each other, they sometimes leak internal chat logs, source code, victim lists, and payment infrastructure details. Defenders and law enforcement will likely monitor for such disclosures. At minimum, the feud demonstrates how fragile dark web monopolies are. While cl0p will probably rebuild its infrastructure quickly, the more lasting consequence may be increased mistrust and volatility between major cybercrime actors, leading to more internecine attacks and additional information leaks. Organizations in the Oracle EBS ecosystem and previous cl0p victims should remain on high alert, because data compromised in the original campaign could resurface in this new phase.
Timeline
Timeline
Alleged theft of Oracle EBS zero-day
ShinyHunters claims it discovered a zero-day flaw in Oracle E-Business Suite, but cl0p allegedly stole the exploit and later used it to steal data from more than 100 companies.
ShinyHunters breaches cl0p infrastructure
ShinyHunters says it found a vulnerability in cl0p's software and used it to establish wide-ranging control over the group's dark web infrastructure.
Seizure message appears on cl0p site
Screenshot preserved by eCrime.ch shows cl0p's dark web site displaying 'Domain Seized By ShinyHunters.'
ShinyHunters publicizes the hijack
ShinyHunters tells Reuters 'We basically own them now'; Reuters finds cl0p's site unreachable and receives no comment from cl0p.
Source cluster
Primary reporting
- economictimes.indiatimes.comShinyHunters cybercrime : Cybercrime feud erupts on dark web as notorious group claims hijack of rival website
Cite This Page
"ShinyHunters Hijacks Cl0p Domain in Oracle Zero-Day Feud; 100+ Firms Impacted." Cyber Intelligence Brief, September 21, 2026. https://getcyberbrief.com/story/shinyhunters-hijacks-cl0p-oracle-zero-day-feud
How we covered this story
Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.
Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.
Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.
See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.
| Signal on this page | What it tells you |
|---|---|
| Verified by N sources | Independent corroboration count. N≥2 is our confidence floor; N=1 is marked explicitly. |
| Impact score (1-10) | Regulatory + financial + operational weight. 8+ signals an experienced-operator action item. |
| Sentiment | Five-tier classification trained on labeled cybersecurity-specific corpora. |
| Timeline | Where applicable, the related-events sequence that contextualizes today's development. |