ShinyHunters Breaches Clop's Leak Site, Threatens Extortion
The ShinyHunters extortion group has turned the tables on Clop by hacking and defacing the ransomware gang's own data leak site.
ShinyHunters, a well-known extortion gang, has breached the data leak site operated by the Clop ransomware group. The attackers defaced the Tor site and claim to have accessed server data as well as the private keys for its onion service, according to BleepingComputer.
By seizing those credentials, ShinyHunters could potentially disrupt Clop's ability to operate its leak site or impersonate the gang's infrastructure. The move is notable because it shows criminal groups increasingly targeting each other's operations, not just conventional victims.
BleepingComputer reports that ShinyHunters is now threatening to extort the ransomware gang. The full extent of the stolen data and Clop's response remain unclear, but the breach highlights how fragile even ransomware operations' own security can be.
Sources · 4
More in Security & Privacy
WordPress Click2Shell CSRF Flaw Could Let Attackers Run PHP Code
A newly disclosed cross-site request forgery vulnerability in WordPress Core, with a public proof-of-concept, can let attackers execute PHP on the server.
Film Torrents Carry New Malware, Victims Found in Kenya and Uganda
Cybercriminals are using popular movie torrents to distribute fresh malware, with confirmed infections in East Africa.
CrowdSec Breach: TanStack npm Attack Exposed 170 Private Repos
CrowdSec says an attacker used a former employee's still-active GitHub access to copy 170 private repositories, tracing the intrusion to the TanStack npm attack.
CISA Adds Three Exploited Linux Kernel Flaws to KEV Catalog
The agency's move signals active attacks and pressures federal agencies to patch quickly.