ShinyHunters: 8 Things We Know About the Group That Hacked Clop

ShinyHunters defaced the Clop ransomware gang’s dark web leak site on 18 September 2026, replacing it with a Pokémon and a message reading “THIS SITE HAS BEEN PWN3D BY SHINYHUNTERS”. By the weekend the banner said “DOMAIN SEIZED BY SHINYHUNTERS”. The group told Reuters it now had wide-ranging control of Clop’s infrastructure, summing it up as owning them outright.

It was a strange week in an extraordinary year.

ShinyHunters spent 2026 breaching Salesforce customers, breaking into Oracle PeopleSoft with a zero-day, and extracting a ransom payment from the company behind Canvas, the learning platform used by thousands of schools. Then it turned on a rival gang.

Here are 8 things we know about the group, what is still unproven, and what it means for your organization.

1. They got into Clop through an off-the-shelf CMS

Clop was running its leak site on Grav, a flat-file content management system. ShinyHunters found an unauthenticated file upload flaw in it.

That’s it. No zero-day, no advanced tradecraft. One of the most prolific ransomware operations of the past seven years was taken down by a web app bug.

ShinyHunters told BleepingComputer, which broke the story, that the attack started on the Friday night.

The sequence is worth noting. First a single text file appeared on the site, proving write access. Hours later the whole site was replaced. That two-stage pattern is the classic shape of an upload bug being escalated to full control.

2. Most of what they claim can’t be verified

This is the part to be careful about.

Confirmed: the defacement itself, which BleepingComputer verified on Clop’s own infrastructure, and a file uploaded by the attackers. Hackread noted that a visible defacement proves the attacker could change content, and nothing more.

Claimed, by ShinyHunters alone: source code, Grav plugins, system and authentication logs, Tor onion private keys, and files revealing the IP addresses of Clop members.

Two researchers told Reuters the feud looks genuine. That is not the same as confirming the stolen data. Clop has said nothing.

3. The feud started over Oracle E-Business Suite

In October 2025, Clop ran a mass extortion campaign against Oracle E-Business Suite customers using a zero-day, CVE-2025-61882.

Around the same time, actors under the Scattered Lapsus$ Hunters banner, ShinyHunters included, published a working exploit for that flaw along with partial Oracle source code.

Handing out a rival’s exclusive capability is a hostile act in this world. The defacement message included the line “maybe don’t try to threaten us next time”, which suggests things escalated from there.

4. They breach platforms, not companies

This is the pattern that matters most.

ShinyHunters doesn’t attack organizations one at a time. It finds a weakness in a platform that thousands of companies use, automates exploitation across all of them, and extorts the results.

Here are 6 insights into how that plays out.

  1. Snowflake, 2024: credential stuffing against Snowflake-connected environments led to confirmed breaches at Ticketmaster, Santander and dozens more.
  2. Drift and Salesloft, August 2025: stolen OAuth tokens were reportedly used to reach roughly 760 downstream Salesforce customer organizations.
  3. Salesforce Experience Cloud, March 2026: misconfigured guest user profiles exposed through the Aura API endpoint, affecting an estimated 300 to 400 organizations.
  4. Canvas, April and May 2026: around 3.5 TB taken from Instructure, with the group claiming data on 275 million people across nearly 9,000 schools.
  5. Oracle PeopleSoft, June 2026: a zero-day used against roughly 300 instances at more than 100 organizations.
  6. Florida DMV, September 2026: the group claims over 200,000 records from the state’s Driver and Vehicle Information Database. Claimed, not confirmed.

One detail from the Salesforce campaign should worry anyone who publishes security tooling. ShinyHunters weaponised a modified version of Mandiant’s own AuraInspector utility, released in January 2026 to help admins find exactly the misconfigurations the group was hunting.

5. The PeopleSoft campaign was a step up

For most of its history the group relied on vishing, stolen tokens and weak access controls. Not software exploitation.

June 2026 changed that. Google’s Mandiant attributes the campaign to a cluster it tracks as UNC6240 and dates it between 27 May and 9 June. Oracle’s advisory landed on 10 June, so this was a zero-day the whole time.

CVE-2026-35273 is a remote code execution bug in the Environment Management component of PeopleSoft Enterprise PeopleTools. It scores 9.8. No login, no user interaction, just network access over HTTP.

Mandiant notified more than 100 organizations. Most were in the US, and more than two thirds were colleges and universities. The University of Nottingham confirmed a breach.

For anyone hunting retrospectively: Google saw the cluster deploy a customised MeshCentral build disguised as Microsoft Azure services, with five sequential IPs in the 142.11.200.186 to 190 range as the main indicators.

6. The extortion runs like a business

Ransom emails arrive with itemised lists of what was taken, Bitcoin payment instructions, 72-hour deadlines and proof samples hosted on public file-sharing sites.

The same 72-hour structure showed up in the Clop defacement. Same playbook, whether the target is a university or a rival gang.

It gets uglier than that. Allison Nixon of Unit 221B, who tracks the group closely, describes pressure tactics during negotiations that include DDoS attacks, spam campaigns and direct threats against executives and their families. Her summary is that this resembles a violent mafia more than skilled hacking.

7. Arrests haven’t slowed them down

On 25 June 2025, French authorities arrested four people across multiple regions, targeting the aliases “ShinyHunters”, “Hollow”, “Noct” and “Depressed”.

Operations continued without interruption. Researchers and the group itself indicated those arrested were affiliates rather than core leadership.

Law enforcement action against this group has been going on for years. Sébastien Raoult was arrested in Morocco in 2022, extradited, and sentenced to three years in 2024. Matthew Lane was sentenced in November 2025 to four years for the PowerSchool breach.

The group kept working through all of it.

8. “ShinyHunters” isn’t really one group

Google Threat Intelligence tracks the activity across at least three linked clusters: UNC6240, UNC6661 and UNC6671. Other vendors use Bling Libra and UNC6040.

Membership overlaps heavily with Scattered Spider and Lapsus$, in a loose arrangement branded Scattered Lapsus$ Hunters since August 2025.

That makes attribution hard. A claim made under the ShinyHunters name might come from the original operators, from collaborators, or from someone borrowing a brand that carries weight.

One thing does act like a signature. The Umbreon artwork in the Clop defacement was matched by the researcher VXDB to a HackForums defacement from August 2020, also attributed to ShinyHunters.

Case studies: ShinyHunters in action

Let’s look at what this looks like for the organizations on the receiving end.

When Canvas went down during finals week…

Instructure detected unauthorized activity in Canvas on 29 April 2026. ShinyHunters claimed responsibility on 3 May and set a deadline of 7 May.

Instructure tried to patch rather than negotiate. So on 7 May the group broke in again, defaced around 330 school login portals, and displayed a ransom note to every user. Canvas went offline during end-of-year exams at many institutions.

The deadline moved to 12 May. On 11 May, Instructure reached an agreement.

When a vendor paid up…

Instructure has never used the word ransom. CEO Steve Daly said the company reached an agreement with the unauthorized actor, that the data was returned, that it received digital confirmation of destruction in the form of shred logs, and that no customer would be separately extorted.

The Register, Help Net Security and Inside Higher Ed all characterised it as a ransom payment. The terms were not disclosed.

It is a rare decision. Coveware found that just 19% of non-encryption extortion victims paid in 2025.

There is also a precedent that should give anyone pause. PowerSchool, another education software vendor, paid after a 2024 breach. Its customers were extorted again afterwards, with data that was supposedly destroyed.

When the extortionists got extorted…

Which brings us back to Clop.

If ShinyHunters did take victim data from Clop’s servers, then every organization that quietly paid Clop now has its data sitting with a second criminal group that agreed to nothing. Dark Reading raised exactly this.

Paying buys a promise from criminals that their copy of your data is gone. That promise is only as good as their own security, which here turned out to be a CMS with an unauthenticated upload flaw.

Defending against ShinyHunters

The tactics are consistent, so the defences are too. Here are some things we recommend.

Auditing your SaaS configuration

Check Salesforce Experience Cloud guest user profiles for API access and review your organization-wide defaults. Disable anything not explicitly needed.

A setting that seems harmless in one tenant becomes a mass-exploitation opportunity when thousands of companies share the same default.

Getting ERP off the public internet

If your PeopleSoft Environment Management Hub is reachable from outside, that is your exposure. The same applies to any enterprise application that was never designed to face the internet but ended up there.

Training the service desk

Vishing is still the group’s primary access route. The zero-day exploitation is new. The phone calls are not, and they keep working.

Rotating tokens after any vendor incident

The Drift and Salesloft campaign reached hundreds of organizations through OAuth tokens, not through their own networks. When a SaaS vendor discloses a breach, rotate API keys, OAuth tokens and SSO credentials rather than waiting to be told you were affected.

Finding your exposure first

Snowflake, Salesforce, Canvas and PeopleSoft have one thing in common. In each case the exposed component was reachable from the internet, and in a lot of victims, not fully accounted for.

Gestión de la Superficie de Ataque maps that estate from the outside, which is where ShinyHunters scans from. Inteligencia de Credenciales covers the identity side of the same problem.

A su disposición

Two criminal groups attacking each other makes for a good story. It is also the least useful thing about this one.

What matters is that ShinyHunters spent 2026 proving the same point over and over. The fastest route into hundreds of organizations at once is a shared platform with an internet-facing component that nobody has fully inventoried.

So the question is the same as always. What of yours is reachable from the internet right now, and do you know about all of it?

Sobre el autor