Overview
- ShinyHunters told reporters it broke into cl0p's dark‑web leak site on Friday and gained broad control, and a preserved screenshot from eCrime.ch showed the site briefly reading “Domain Seized By ShinyHunters.”
- The dispute centers on an Oracle E‑Business Suite zero‑day that cl0p used in a campaign against more than 100 companies according to a Google analyst while ShinyHunters says it discovered the flaw first.
- Security firms quoted in reporting said the public clash appears genuine, but Reuters and others said they could not independently verify the full extent of ShinyHunters’ control and cl0p has not responded.
- Technical accounts from investigators say ShinyHunters exploited a flaw in cl0p’s site software to upload a file and claimed it holds the onion private keys for the address, a step that would let it host the same dark‑web URL.
- Researchers warn the feud raises two risks: it could trigger leaks of exploit code or victim data that compound harm to companies and it could complicate efforts by security teams and law enforcement to trace and stop the attackers.