The ShinyHunters extortion group took control of the dark web leak site belonging to the prolific Cl0p ransomware gang over the weekend. The attackers set an eight-figure extortion demand pegged at 2.333% of Cl0p's estimated net worth.
ShinyHunters posted materials on Cl0p's compromised site announcing the hijacking and financial demand. The specific percentage calculation suggests the group has attempted to estimate Cl0p's total assets before setting the ransom figure.
Cl0p has been one of the most active ransomware operations globally, responsible for high-profile breaches affecting major corporations and organizations. The gang typically exfiltrates data before encrypting systems, then uses dark web leak sites to pressure victims into paying ransoms.
This incident represents a significant breach of the criminal operation itself. Hijacking a ransomware gang's leak site could expose internal communications, victim data, or operational details. The ShinyHunters group has previously targeted databases and stolen information, but extending operations to extort fellow cybercriminals marks an escalation in criminal-on-criminal attacks.
The development underscores ongoing instability within dark web criminal ecosystems and competition between extortion groups.
Obscura has launched a VPN service architected to make user activity logging technically impossible. The service uses a no-log-by-design approach rather than relying on policy promises alone.
Hackers claim to have compromised the Federal Bureau of Investigation and obtained personal data on all FBI employees. The breach's scope and authenticity have not yet been independently verified.
Researchers at Cisco Talos developed a new framework to detect malware and hacking tools powered by AI chatbots. The discovery revealed an unusual threat: autonomous malware operating without human handlers.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an emergency directive ordering federal agencies to patch a high-severity vulnerability in Zyxel GS1900 series switches. Attackers are actively exploiting the flaw to steal data.