Tendvane

← All articles

SecuritySeptember 21, 2026

One extortion gang just robbed another, and the receipts are the ransom

Visitors to Clop's dark web leak site this weekend found a banner reading "DOMAIN SEIZED BY SHINYHUNTERS". Not by a police force. By a rival.

ShinyHunters broke in on Friday through an unauthenticated file upload flaw in Grav, the content management system Clop was running its site on, and says it walked away with the private keys as well. "We basically own them now," the group told reporters. A ransom demand went up on 19 September asking for an eight-figure sum plus a public apology, and by Sunday it was being raised every 24 hours. The grudge, as ShinyHunters tells it, is that they found the Oracle E-Business Suite zero-day first and Clop took the exploit and ran a mass extortion campaign with it.

Here is the part that matters beyond the gossip. ShinyHunters is threatening to publish the list of companies that paid Clop to keep their breaches quiet, including the sums and the Bitcoin addresses. Those payments were made on the understanding that nobody would ever know. Every organisation on that list is about to learn what security people have said for years: paying a criminal buys a promise from a criminal, and the promise is worth nothing the moment somebody else gets hold of the paperwork. Meanwhile the stolen data from Clop's victims, Shell and Philips and Fiserv among them, sits in an archive now controlled by a different gang with different motives.

None of this is something you can act on directly, and that is rather the point. The details you hand to a company become their problem to guard and then somebody else's asset. What you still control is whether one leaked password opens more than one door, so use a different one everywhere and turn on two-step sign-in wherever it is offered. Tendvane's privacy and accounts check is a quick way to see how the accounts and sign-in settings on your own PC are set up.

Sources

Download Tendvane