### "Now They Are Essentially Ours" According to Reuters, the group ShinyHunters, known for large-scale corporate data theft and digital extortion, announced that on Friday, September 18, they discovered a vulnerability in the software used by Cl0p. Through it, the hackers allegedly managed to penetrate the systems of their competitors and gain significant control over their infrastructure. In a conversation with Reuters, representatives of ShinyHunters summarized the outcome succinctly: "Now we essentially own them." On Saturday, a message appeared on the dark web site of Cl0p stating "Domain Seized By ShinyHunters." A screenshot of the page was preserved by the research platform eCrime.ch. By Sunday, the Cl0p website was unavailable. Cl0p itself did not respond to journalists' inquiries. Therefore, Reuters emphasizes that it is currently impossible to independently verify all of ShinyHunters' claims regarding the extent of the access obtained. However, two cybersecurity experts who studied the situation informed the agency that the confrontation appears to be genuine. One of the experts noted that such an open attack by one major cybercriminal group on another is extremely rare. ### Quarreled Over Particularly Valuable "Weapons" Behind the dramatic seizure of the website lies a longer-standing conflict. According to ShinyHunters, it all began due to an unknown zero-day vulnerability in Oracle E-Business Suite — software used by large companies. ShinyHunters claims to have been the first to discover this vulnerability, but then the information about it fell into the hands of Cl0p. The latter exploited the vulnerability for a large-scale campaign to steal corporate data. According to Reuters, more than 100 companies were targeted by the attacks. The conflict gradually escalated into a real war. According to ShinyHunters, representatives of Cl0p threatened to reveal the identities of several members of the competing group. In response, ShinyHunters threatened to disclose internal information about Cl0p's activities. Reuters was unable to independently verify this version of the conflict's development. ### Who Are Cl0p Cl0p is considered one of the most active cybercriminal groups in recent years. It specializes in finding vulnerabilities in corporate software, mass data theft, and subsequent extortion of money from companies. The most well-known operation of Cl0p occurred in 2023 when the group exploited a vulnerability in the MOVEit file transfer system. As a result, data was stolen from more than 600 organizations, and the leak affected tens of millions of people. Activity continued in 2026 as well. Just last month, Cl0p claimed to have stolen significant volumes of information from nearly 50 companies, including Philips, Shell, Fiserv, and GE. ShinyHunters is also well-known among cybersecurity experts. The group specializes in stealing large amounts of data and subsequently blackmailing their owners. This year, it notably claimed to have stolen millions of records from video game developer Rockstar Games and was also linked to an attack on the educational platform Canvas, which caused serious disruptions in American educational institutions. ### War in the Darknet The open confrontation between two such large groups is an unusual situation even for the cybercriminal world. Typically, such structures try to avoid drawing attention to their own servers, participants, and internal organization. Now everything is the opposite: opponents not only attack each other but also publicly threaten to reveal the identities of participants and the structure of the competitor's criminal infrastructure. If ShinyHunters' claims are confirmed, the attack could be particularly painful for Cl0p: for a group that profits from hacking into others' systems, losing control over its own infrastructure is not only a technical problem but also a serious reputational blow.