Ransomware gangs are turning on one another in a strange kind of justice playing out on the dark web right now, and it’s worth paying attention to — not because it’s entertaining (though it is), but because of what it reveals about the ransomware economy.

The Breach

Late last week, the extortion group ShinyHunters broke into the data leak site run by Clop (also written Cl0p), one of the most prolific ransomware operations of the past few years. ShinyHunters exploited what they say is an unauthenticated file-upload flaw in Grav CMS to first plant a taunting message on Clop’s site, then fully defaced it with imagery tied to their own brand.

According to BleepingComputer, which corresponded directly with the threat actors, ShinyHunters claims to have pulled source code, Grav CMS plugins, system logs, and — notably — the private cryptographic keys behind Clop’s Tor onion service. If that last claim holds up, it means ShinyHunters could theoretically stand up a mirror site at Clop’s own dark-web address, using infrastructure Clop no longer controls. BleepingComputer has confirmed the defacement itself but has not independently verified every claim ShinyHunters has made about what was stolen.

And in what might be the most on-brand line of the whole saga, when asked what they intend to do with the data, ShinyHunters simply said they plan to extort Clop — giving the gang 72 hours to respond before going public.

Why Two Ransomware Gangs Are Feuding

This isn’t a random turf war. ShinyHunters says the conflict traces back to Clop’s 2025 campaign against Oracle E-Business Suite servers, where Clop exploited a zero-day vulnerability to steal data from victim organizations. ShinyHunters claims the exploit used in that campaign actually originated with them, and that Clop obtained and used it without permission.

From there, according to ShinyHunters, things got personal — they allege a Clop representative sent direct threats against members of their group during the fallout from the Oracle campaign. Whether or not every detail checks out, the pattern is consistent with what security researchers have been tracking for a while: today’s ransomware and extortion ecosystem isn’t one unified underworld. It’s a loose, often hostile collection of crews who compete for victims, poach each other’s tools, and occasionally turn on one another when the money or the ego is on the line. In short, ransomware gangs behave less like a cartel and more like rival startups fighting over market share.

Why This Matters for Businesses — Not Just Security Nerds

It’s tempting to watch this as pure spectacle: criminals hacking criminals. But there are real implications here for any organization thinking about ransomware risk.

Extortion groups are unpredictable by nature, and now doubly so. An operation that’s internally stable is at least somewhat predictable — negotiators know roughly how these groups behave. A group that’s mid-feud, scrambling to control its own leaked data, or trying to rebuild infrastructure after a defacement is a wildcard. That instability can spill over into how (and whether) they honor “deals” with victims who’ve already paid. When ransomware gangs are distracted by internal conflict, the usual rules of engagement can shift without warning.

Leaked victim data doesn’t stay contained. If ShinyHunters really does hold Clop’s stolen files and onion keys, any data Clop was sitting on from its own victims — including companies that may have already paid a ransom to keep it private — is now potentially exposed to a second threat actor. Paying a ransomware gang was never a guarantee of privacy, and stories like this are a stark reminder why.

The barrier to entry keeps getting exploited on both sides. The initial compromise here reportedly came down to an unpatched CMS vulnerability — the same category of “boring” flaw that takes down legitimate businesses every day. Criminal infrastructure gets breached through the same kinds of gaps we tell our own clients to close: unpatched software, weak upload controls, and exposed admin functionality. Even ransomware gangs are not immune to the basic security failures they profit from exploiting in others.

The Takeaway

Ransomware gangs are businesses — messy, criminal, sometimes petty businesses — and like any business under stress, infighting creates chaos that ripples outward. For organizations, the lesson isn’t “relax, the bad guys are busy fighting each other.” It’s the opposite: an unstable threat landscape is a harder one to predict, negotiate with, or trust. The only reliable defense is not needing to find out how any of these groups behave — by keeping them out in the first place.

Ready to reduce your risk from ransomware gangs and other evolving threats? Schedule a free cybersecurity assessment with our team today and get a clear view of your current defenses.