INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
ShinyHunters Exploits Oracle PeopleSoft Flaw to Deploy Web Shells
| 2026-09-28 13:55 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
On September 28, 2026, ShinyHunters bypassed web application firewall protections to exploit a critical PeopleSoft flaw (CVE-2026-35273) and deploy web shells. The APT Group behind the attacks is ShinyHunters, also tracked as UNC6240 by Google. Confirmed victims include over 100 Oracle PeopleSoft customers, including universities such as the University of Nottingham in the UK, insurance regulators group NAIC, and Nissan. The attack works by using a modified exploit to bypass WAF rules blocking the vulnerable Environment Management Hub (PSEMHUB) endpoint. As of now, ShinyHunters continues to deploy web shells on dozens of systems after successfully exploiting the vulnerability.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2025-61882, CVE-2026-35273 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
• Pre-compromise (ATT&CK mitigation for Botnet): This technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
wi•••••.network
fb•••••.gov
ap•••••.gov
ba1441••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
419c57••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
3ba215••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
2bee94••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
104.219.•••.•••
162.219.•••.•••
5.199.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHuntersScattered SpiderScattered Spider
UmbreonUmbreonNeo-reGeorgNeo-reGeorg
CVE-2025-61882CVE-2025-61882
CVE-2026-35273CVE-2026-35273
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
educationeducation
financefinance
transportationtransportation
Incident Timeline
August 2020
ShinyHunters reused the Umbreon artwork from their 2020 HackForums defacement on a leak site associated with Clop.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
Cybersecurity researcher
VXDB
told BleepingComputer the Umbreon artwork now displayed on Clop's leak site is the same as what was used in the
August 2020 defacement
of the HackForums website, which ShinyHunters also claimed at the time.
tactic
Defacement
Cybersecurity researcher
VXDB
told BleepingComputer the Umbreon artwork now displayed on Clop's leak site is the same as what was used in the
August 2020 defacement
of the HackForums website, which ShinyHunters also claimed at the time.
malware
Umbreon
Cybersecurity researcher
VXDB
told BleepingComputer the Umbreon artwork now displayed on Clop's leak site is the same as what was used in the
August 2020 defacement
of the HackForums website, which ShinyHunters also claimed at the time.
organisation
Cybersecurity
Cybersecurity researcher
VXDB
told BleepingComputer the Umbreon artwork now displayed on Clop's leak site is the same as what was used in the
August 2020 defacement
of the HackForums website, which ShinyHunters also claimed at the time.
organisation
VXDB
Cybersecurity researcher
VXDB
told BleepingComputer the Umbreon artwork now displayed on Clop's leak site is the same as what was used in the
August 2020 defacement
of the HackForums website, which ShinyHunters also claimed at the time.
organisation
HackForums
Cybersecurity researcher
VXDB
told BleepingComputer the Umbreon artwork now displayed on Clop's leak site is the same as what was used in the
August 2020 defacement
of the HackForums website, which ShinyHunters also claimed at the time.
2025/09/19
ShinyHunters allegedly used spear-phishing tactics to target individuals, including a threat actor from the Russian Federation identified as cl0p.
Click on any entity below to view its context and source!
organisation
EBS
They have now allegedly told BleepingComputer, “During the Oracle EBS campaign they ran and stole from me last year, someone from cl0p personally messaged me and said, and I quote (translated from Russian): I have more money than you and all of your people combined, I’ll kill you soon.”
"During the Oracle EBS campaign they ran and stole from me last year, someone from cl0p personally messaged me and said, and I quote (translated from Russian): I have more money than you and all of your people combined, I'll kill you soon," ShinyHunters told BleepingComputer.
target_region
Russian Federation
They have now allegedly told BleepingComputer, “During the Oracle EBS campaign they ran and stole from me last year, someone from cl0p personally messaged me and said, and I quote (translated from Russian): I have more money than you and all of your people combined, I’ll kill you soon.”
"During the Oracle EBS campaign they ran and stole from me last year, someone from cl0p personally messaged me and said, and I quote (translated from Russian): I have more money than you and all of your people combined, I'll kill you soon," ShinyHunters told BleepingComputer.
organisation
cl0p
They have now allegedly told BleepingComputer, “During the Oracle EBS campaign they ran and stole from me last year, someone from cl0p personally messaged me and said, and I quote (translated from Russian): I have more money than you and all of your people combined, I’ll kill you soon.”
"During the Oracle EBS campaign they ran and stole from me last year, someone from cl0p personally messaged me and said, and I quote (translated from Russian): I have more money than you and all of your people combined, I'll kill you soon," ShinyHunters told BleepingComputer.
threat_actor
ShinyHunters
"During the Oracle EBS campaign they ran and stole from me last year, someone from cl0p personally messaged me and said, and I quote (translated from Russian): I have more money than you and all of your people combined, I'll kill you soon," ShinyHunters told BleepingComputer.
October 2025
Threat actors, identified as Clop, exploited multiple vulnerabilities in Oracle E-Business Suite servers to steal data from organizations in extortion campaigns.
Click on any entity below to view its context and source!
tactic
Extortion
In October 2025, Clop exploited multiple vulnerabilities in Oracle E-Business Suite servers, including a zero-day flaw tracked as
CVE-2025-61882
, to steal data from organizations in extortion campaigns.
vulnerability
CVE-2025-61882
In October 2025, Clop exploited multiple vulnerabilities in Oracle E-Business Suite servers, including a zero-day flaw tracked as
CVE-2025-61882
, to steal data from organizations in extortion campaigns.
December 2025
Threat actors known as ShinyHunters launched a spear-phishing campaign targeting Oracle PeopleSoft, which was exploited to carry out a ransomware attack and data breach against the University of Phoenix.
Click on any entity below to view its context and source!
tactic
Ransomware
These incidents include a ransomware attack and data breach against
the University of Phoenix
which affected nearly 3.5 million people in December 2025.
tactic
Data Breach
These incidents include a ransomware attack and data breach against
the University of Phoenix
which affected nearly 3.5 million people in December 2025.
organisation
the University of Phoenix
These incidents include a ransomware attack and data breach against
the University of Phoenix
which affected nearly 3.5 million people in December 2025.
general_metric
3.5 people
These incidents include a ransomware attack and data breach against
the University of Phoenix
which affected nearly 3.5 million people in December 2025.
May 2026
ShinyHunters published a statement claiming the attack on Oracle PeopleSoft was retaliation for an FBI report detailing their activities in May 2026.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
Retaliation over FBI report
ShinyHunters later published a lengthy statement on its data leak site claiming the attack was retaliation for an
FBI FLASH report detailing ShinyHunters
that was published in May 2026.
tactic
Data Leak
Retaliation over FBI report
ShinyHunters later published a lengthy statement on its data leak site claiming the attack was retaliation for an
FBI FLASH report detailing ShinyHunters
that was published in May 2026.
attribution
FBI
Retaliation over FBI report
ShinyHunters later published a lengthy statement on its data leak site claiming the attack was retaliation for an
FBI FLASH report detailing ShinyHunters
that was published in May 2026.
attribution
Retaliation
Retaliation over FBI report
ShinyHunters later published a lengthy statement on its data leak site claiming the attack was retaliation for an
FBI FLASH report detailing ShinyHunters
that was published in May 2026.
2026/09/14
ShinyHunters launched a spear-phishing campaign targeting Oracle PeopleSoft, potentially exposing victim organizations to additional risks due to their involvement with rival ransomware gang Clop.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
ShinyHunters apparently breached rival ransomware gang Clop last week, and the incident could pose additional risks to victim organizations caught in the middle.
tactic
Ransomware
ShinyHunters apparently breached rival ransomware gang Clop last week, and the incident could pose additional risks to victim organizations caught in the middle.
2026/09/15
ShinyHunters launched a spear-phishing campaign targeting Oracle PeopleSoft users.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
That dispute resurfaced last week when ShinyHunters breached and
defaced Clop's data leak site
, claiming it stole server data and the private keys for its Tor onion service.
tactic
Data Leak
That dispute resurfaced last week when ShinyHunters breached and
defaced Clop's data leak site
, claiming it stole server data and the private keys for its Tor onion service.
organisation
Tor
That dispute resurfaced last week when ShinyHunters breached and
defaced Clop's data leak site
, claiming it stole server data and the private keys for its Tor onion service.
18 September
ShinyHunters defaced Clop's dark web data leak site with a message claiming they had taken control of the site.
Click on any entity below to view its context and source!
tactic
Data Leak
The incident, which came to light on the evening of 18 September, saw Clop’s dark web data leak site defaced with a message which said “THIS SITE HAS BEEN PWN3D BY SHINYHUNTERS”.
Sept. 19
Threat actors known as ShinyHunters sent a spear-phishing message to Clop on September 19, demanding an eight-figure payment in Bitcoin and providing contact information via Onionmail.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
On Sept. 19, a message attributed to ShinyHunters demanded an unspecified eight-figure payment in Bitcoin and directed Clop to contact an Onionmail address.
organisation
Onionmail
On Sept. 19, a message attributed to ShinyHunters demanded an unspecified eight-figure payment in Bitcoin and directed Clop to contact an Onionmail address.
Sept. 20
Threat actors, identified as ShinyHunters, used spear-phishing tactics to target Oracle PeopleSoft on September 20.
Click on any entity below to view its context and source!
organisation
EBS
On Sept. 20, the attackers wrote on Clop's page, "I want all the money you made off the EBS campaign plus more AND WITH INTEREST, before I start releasing information regarding the companies that paid you, how much, and to what Bitcoin address.
2026/09/21
ShinyHunters' spear-phishing campaign against Oracle PeopleSoft did not result in a ransom payment as of the date mentioned on their defacement message.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
We found another one yesterday and immediately exploited it on the FBI," ShinyHunters told BleepingComputer.
What About the Ransomware Victims?
ShinyHunters' effort does not appear to have yet resulted in a payment, as the defacement message included a note dated today.
attribution
FBI
We found another one yesterday and immediately exploited it on the FBI," ShinyHunters told BleepingComputer.
tactic
Defacement
What About the Ransomware Victims?
ShinyHunters' effort does not appear to have yet resulted in a payment, as the defacement message included a note dated today.
organisation
Ransomware
What About the Ransomware Victims?
ShinyHunters' effort does not appear to have yet resulted in a payment, as the defacement message included a note dated today.
2026/09/28
ShinyHunters exploited a zero-day vulnerability in Oracle PeopleSoft to gain remote code execution without authentication, targeting over 100 customers.
Click on any entity below to view its context and source!
organisation
CVE-2026-35273
The activity targets CVE-2026-35273, a critical PeopleSoft flaw previously used as a zero-day against universities.
organisation
PeopleSoft
The activity targets CVE-2026-35273, a critical PeopleSoft flaw previously used as a zero-day against universities.
Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign.
"The Oracle product we exploited the 0day in is PeopleSoft.
organisation
Oracle
PeopleSoft customers are advised to apply Oracle’s patches for CVE-2026-35273, to harden their environments, hunt for potential indicators of compromise (IoCs) and data theft, and prepare for extortion in the event of compromise.
During Clop's 2025 Oracle E-Business Suite data theft campaign, ShinyHunters was part of a group calling itself "Scattered Lapsus$ Hunters" that
leaked a proof-of-concept exploit
later confirmed by Oracle to match one used in the attacks.
organisation
Google
Google’s warning comes four months after the hacking group was seen exploiting a zero-day vulnerability in PeopleSoft, tracked as
CVE-2026-35273
, to gain remote code execution without authentication.
threat_actor
ShinyHunters
Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign.
ShinyHunters Bypasses WAF Protections to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells.
ShinyHunters has renewed attacks against Oracle PeopleSoft systems by slipping past web application firewall protections and planting web shells.
The […] The post ShinyHunters Bypasses WAF Protections to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells appeared first on Cyber Security News .
While ShinyHunters’ initial PeopleSoft campaign focused on the education sector, the new wave of attacks has expanded to agriculture, government, healthcare, IT services, technology, and transportation organizations, Google says.
Mandiant and Google Threat Intelligence Group (GTIG) over the weekend warned that the notorious extortion group ShinyHunters has launched a fresh mass-exploitation campaign targeting Oracle PeopleSoft customers.
“UNC6240 has a well-established pattern of data theft extortion, that is, stealing data and threatening to release it on a data leak site unless the victim pays a ransom.
ShinyHunters
, tracked by Google as UNC6240, targeted
more than 100 PeopleSoft customers
in June.
“This new wave of activity stems from UNC6240 modifying its exploit to bypass web application firewall (WAF) rules blocking the vulnerable Environment Management Hub (PSEMHUB) endpoint,” Mandiant and GTIG
warn
now.
In the recent
attack aimed at the FBI
, ShinyHunters claimed to have leveraged a PeopleSoft zero-day.
When BleepingComputer asked the main representative of the ShinyHunters extortion gang whether they were concerned this would lead to increased pressure from the US government to apprehend them, they responded, "I don't care.
Allegedly defaced FBI Jobs website
Source: ShinyHunters
The message further claimed that sensitive personally identifiable and health-related information belonging to FBI employees and applicants had been stolen.
ShinyHunters also told BleepingComputer that it is now using the same alleged PeopleSoft vulnerability to target corporations and the Fortune 500 after
targeting the education sector
.
The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants.
In the statement, ShinyHunters gave the FBI one week to correct or remove the FLASH report, while claiming the demand was not financially motivated and was not extortion.
ShinyHunters later told BleepingComputer that the exploit originally belonged to them and that the Clop ransomware gang obtained it without authorization.
However, ShinyHunters shared a screenshot with BleepingComputer showing the FBI Jobs website at apply.fbijobs.gov defaced with the group's Umbreon Pokémon logo and a message claiming that FBI employee and applicant information had been compromised.
ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach.
ShinyHunters claims it stole between 2TB and 3TB of data from the agency, including information on current and former FBI employees, job applicants, and other internal records.
ShinyHunters further claims it is now exploiting the same alleged zero-day against other organizations, including Fortune 500 companies.
"
ShinyHunters told BleepingComputer that the FBI quickly became aware of the intrusion, immediately took affected systems offline, and that the FBI Jobs site now displays a maintenance message.
"They literally pulled the plug on everything," ShinyHunters said.
Alleged PeopleSoft zero-day
ShinyHunters claims they gained initial access through a new zero-day vulnerability in Oracle PeopleSoft that remains unpatched.
ShinyHunters claims the stolen FBI data came from systems accessed following the initial PeopleSoft compromise.
ShinyHunters statement about FBI attack
Source: BleepingComputer
The group disputes claims that ShinyHunters actors may exaggerate access to sensitive information, harass victims and their relatives, conduct swatting attacks, and falsely claim to possess compromising material.
When asked whether the group would release the allegedly stolen FBI data if the agency did not make changes to the report, ShinyHunters declined to say.
"
The alleged PeopleSoft zero-day would not be the first time ShinyHunters has been linked to exploitation of a previously unknown Oracle vulnerability.
During Clop's 2025 Oracle E-Business Suite data theft campaign, ShinyHunters was part of a group calling itself "Scattered Lapsus$ Hunters" that
leaked a proof-of-concept exploit
later confirmed by Oracle to match one used in the attacks.
ShinyHunters also recently
claimed an attack on American healthcare giant McKesson
, which wholesale medical supplies and pharmaceutical distribution to over 40,000 corporate and institutional customers.
ShinyHunters Claim Hack of Rival Ransomware Gang Clop.
The
ShinyHunters
hacking and extortion gang has claimed a cyber-attack against a fellow cybercriminal outfit, the Clop ransomware group.
ShinyHunters claimed to have stolen private keys and server data used to run Clop’s ransomware operations.
The message left behind on the Clop website also contained a link to ShinyHunters’ own data leak site.
When questioned by Bleeping Computer about what they planned to do with the access they had to Clop, the attacker reportedly replied, “going to extort them.”
Feud Between Hacking Gangs
The ShinyHunters attack against Clop appears to be the latest stage in a feud between the two criminal extortion groups which began in 2025.
ShinyHunters is one of the most prolific cyber extortion groups of 2026, with significant campaigns against users of commonly deployed software-as-a-service providers including
Salesforce Experience Cloud
and
Canvas Learning Management System.
ShinyHunters told the publication they had stolen files which could reveal activity, authentication logs and even the IP addresses of Clop members who connected to the service.
Despite Clop being another criminal hacking gang, ShinyHunters are treating them like any other victim and have issued a ransom note telling Clop to contact them.
Jon Baker, vice president of threat-informed defense at AttackIQ, tells Dark Reading that there's no proof yet that ShinyHunters actually obtained Clop's victim files, but a larger point is that "stolen information doesn't retire.
ShinyHunters is a financially motivated cybercrime group known primarily for data theft and extortion attacks.
Over the weekend, ShinyHunters defaced Clop's Dark Web data leak site with a message: "DOMAIN SEIZED BY SHINYHUNTERS."
However, Dark Reading confirmed that, as of this writing, Clop's leak site removed the defacement message and now displays a plain text note, possibly from Clop itself, claiming ShinyHunters' email address does not work.
If ShinyHunters obtained additional information tied to Clop's victims, those organizations could potentially face further exposure or even renewed extortion attempts.
ShinyHunters Hacked Clop.
As first reported by
BleepingComputer
, ShinyHunters claimed the attack began on Friday night when it exploited an unauthenticated file upload vulnerability in the Grav CMS used by Clop's leak site.
Cybercriminals Are Hiding New Malware in Torrents for Popular Films
ShinyHunters vs. Clop: Cybercrime Feud
ShinyHunters claimed it obtained full access to Clop's leak site server and stole source code, Grav CMS plug-ins, system logs, private keys for its Onion service, and other data.
"
On the other hand, it's unknown whether ShinyHunters obtained any information about Clop's victims.
At this time, ShinyHunters has not provided proof that it has this data in its possession.
That said, ShinyHunters has already threatened to publish information about companies that allegedly paid Clop, including payment amounts and Bitcoin addresses.
"
It remains to be seen whether ShinyHunters actually obtained Clop victim information or not.
ShinyHunters hacks Clop leak site, threatens to extort ransomware gang (1).
Lawrence Abrams reports:
The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation’s data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service.
The attack began Friday night when ShinyHunters exploited what they claim is an unauthenticated file upload vulnerability in Grav CMS, which they used to upload a small text file to Clop’s site.
At the time, ShinyHunters told BleepingComputer and DataBreaches that the zero-day was theirs and Clop had used it without their permission.
ShinyHunters hacks Clop leak site, threatens to extort ransomware gang.
The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation's data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service.
File uploaded to Clop's data leak site
Source: BleepingComputer
The file also contained a link to the ShinyHunters data leak site.
Clop's data leak site defaced by ShinyHunters
Source: BleepingComputer
At the time of this writing, the defaced page is still being served from Clop's infrastructure, according to ShinyHunters.
BleepingComputer has independently confirmed the defacement and earlier uploaded file but has not independently verified ShinyHunters' claims that it stole server logs, source code, or Clop's onion private keys.
The attack began Friday night when ShinyHunters exploited what they claim is an unauthenticated file upload vulnerability in Grav CMS, which they used to upload a small text file to Clop's site.
Several hours later, ShinyHunters told BleepingComputer that they had "completely defaced" the Clop site.
Visiting the site confirmed it had been replaced with a page displaying ASCII art of Umbreon, the Pokémon used as ShinyHunters' logo.
ShinyHunters claims data theft
ShinyHunters told BleepingComputer it gained "full access" to the server and stole source code, Grav CMS plugins, system logs, and other data.
We are still downloading and reviewing them," ShinyHunters told BleepingComputer.
ShinyHunters also claims to have obtained the private keys used by Clop's Tor onion service.
ShinyHunters says it is now reviewing the allegedly stolen data.
Feud between cybercrime groups
ShinyHunters says the attack is retaliation for threats allegedly made by a Clop representative during an ongoing feud between the cybercrime groups.
According to ShinyHunters, a Clop representative threatened to identify group members and made violent threats after ShinyHunters disrupted a Clop data theft campaign.
ShinyHunters says the dispute dates back to
Clop's 2025 Oracle E-Business Suite data theft campaign
.
Around the same time, threat actors calling themselves "Scattered Lapsus$ Hunters," including ShinyHunters,
leaked a proof-of-concept exploit
that Oracle later confirmed matched an exploit used in the Clop attacks.
At the time, ShinyHunters told BleepingComputer the exploit had originally belonged to them and that Clop obtained it without authorization.
ShinyHunters claims that tensions escalated after the Oracle campaign, with a Clop representative allegedly threatening members of the group.
BleepingComputer has not independently verified these allegations and has contacted Clop about the breach and the allegations made by ShinyHunters and will update the story if we receive a response.
organisation
Oracle PeopleSoft
ShinyHunters has renewed attacks against Oracle PeopleSoft systems by slipping past web application firewall protections and planting web shells.
Mandiant and Google Threat Intelligence Group (GTIG) over the weekend warned that the notorious extortion group ShinyHunters has launched a fresh mass-exploitation campaign targeting Oracle PeopleSoft customers.
Alleged PeopleSoft zero-day
ShinyHunters claims they gained initial access through a new zero-day vulnerability in Oracle PeopleSoft that remains unpatched.
organisation
Cyber Security News
The […] The post ShinyHunters Bypasses WAF Protections to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells appeared first on Cyber Security News .
victims
100 PeopleSoft customers
ShinyHunters
, tracked by Google as UNC6240, targeted
more than 100 PeopleSoft customers
in June.
data_breach
2 TB
ShinyHunters claims it stole between 2TB and 3TB of data from the agency, including information on current and former FBI employees, job applicants, and other internal records.
data_breach
3 TB
ShinyHunters claims it stole between 2TB and 3TB of data from the agency, including information on current and former FBI employees, job applicants, and other internal records.
organisation
Oracle E-Business Suite
During Clop's 2025 Oracle E-Business Suite data theft campaign, ShinyHunters was part of a group calling itself "Scattered Lapsus$ Hunters" that
leaked a proof-of-concept exploit
later confirmed by Oracle to match one used in the attacks.
ShinyHunters says the dispute dates back to
Clop's 2025 Oracle E-Business Suite data theft campaign
.
The reference to "EBS" likely references
Clop's extortion campaign
targeting customers affected by the critical Oracle E-Business Suite (EBS) zero-day vulnerability CVE-2025-61882 last fall.
The origins of the row centered around competing claims over ownership of vulnerabilities in Oracle E-Business Suite servers.
The dispute appears to be a continuation of a fight that began when Clopexploited a zero-day vulnerability tracked as CVE-2025-61882 that enabled it to attack Oracle E-Business Suite servers.
victims
40,000 corporate customers
ShinyHunters also recently
claimed an attack on American healthcare giant McKesson
, which wholesale medical supplies and pharmaceutical distribution to over 40,000 corporate and institutional customers.
organisation
Feud Between Hacking Gangs
When questioned by Bleeping Computer about what they planned to do with the access they had to Clop, the attacker reportedly replied, “going to extort them.”
Feud Between Hacking Gangs
The ShinyHunters attack against Clop appears to be the latest stage in a feud between the two criminal extortion groups which began in 2025.
organisation
Canvas Learning Management System
ShinyHunters is one of the most prolific cyber extortion groups of 2026, with significant campaigns against users of commonly deployed software-as-a-service providers including
Salesforce Experience Cloud
and
Canvas Learning Management System.
organisation
IP
ShinyHunters told the publication they had stolen files which could reveal activity, authentication logs and even the IP addresses of Clop members who connected to the service.
The threat actors also claim to have stolen all files stored under
/var/log
, which could contain system activity, authentication logs, and potentially, the IP addresses of those who connected to it.
organisation
AttackIQ
Jon Baker, vice president of threat-informed defense at AttackIQ, tells Dark Reading that there's no proof yet that ShinyHunters actually obtained Clop's victim files, but a larger point is that "stolen information doesn't retire.
organisation
Tor
Lawrence Abrams reports:
The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation’s data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service.
The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation's data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service.
organisation
Grav CMS
The attack began Friday night when ShinyHunters exploited what they claim is an unauthenticated file upload vulnerability in Grav CMS, which they used to upload a small text file to Clop’s site.
The attack began Friday night when ShinyHunters exploited what they claim is an unauthenticated file upload vulnerability in Grav CMS, which they used to upload a small text file to Clop's site.
organisation
BleepingComputer
At the time, ShinyHunters told BleepingComputer and DataBreaches that the zero-day was theirs and Clop had used it without their permission.
BleepingComputer has not independently verified the alleged zero-day, lateral movement, or amount of stolen data.
BleepingComputer confirmed that the file had been uploaded to Clop's server and could be downloaded directly from the ransomware gang's Tor site.
organisation
DataBreaches
At the time, ShinyHunters told BleepingComputer and DataBreaches that the zero-day was theirs and Clop had used it without their permission.
organisation
the
University of Nottingham
Confirmed victims include the
University of Nottingham
in the UK, insurance regulators group
NAIC
, and
Nissan
.
organisation
Nissan
Confirmed victims include the
University of Nottingham
in the UK, insurance regulators group
NAIC
, and
Nissan
.
infrastructure
Windows
Related:
Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability
Related:
China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks
Related:
New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining
Related:
Mandiant and GTIG observed the hacking group establishing persistence through two complementary, single-line JSP web shells, and deploying the SideEye backdoor on Windows servers to steal credentials from browsers and applications, manage files and processes, and gain reverse shell and reverse proxy capabilities.
organisation
JSP
Mandiant and GTIG observed the hacking group establishing persistence through two complementary, single-line JSP web shells, and deploying the SideEye backdoor on Windows servers to steal credentials from browsers and applications, manage files and processes, and gain reverse shell and reverse proxy capabilities.
organisation
SideEye
Mandiant and GTIG observed the hacking group establishing persistence through two complementary, single-line JSP web shells, and deploying the SideEye backdoor on Windows servers to steal credentials from browsers and applications, manage files and processes, and gain reverse shell and reverse proxy capabilities.
organisation
ERP
An integrated enterprise resource planning (ERP) software suite, PeopleSoft is used across numerous large enterprises for the management of core business functions, including finance, HR, payroll, and supply chain.
organisation
CVE-2025-61882
The reference to "EBS" likely references
Clop's extortion campaign
targeting customers affected by the critical Oracle E-Business Suite (EBS) zero-day vulnerability CVE-2025-61882 last fall.
The dispute appears to be a continuation of a fight that began when Clopexploited a zero-day vulnerability tracked as CVE-2025-61882 that enabled it to attack Oracle E-Business Suite servers.
organisation
MeshCentral
Additionally, the attackers deployed the open source Neo-reGeorg tunneling toolkit for internal discovery and lateral movement, and the open source remote management platform MeshCentral.
organisation
ShinyHunter
The small text file contained a message from the threat actors to the Clop ransomware gang, warning not to threaten them and including a link to ShinyHunter’s own data leak site.
File downloaded from Clop's data leak site
Source: BleepingComputer
The small text file contained a message from the threat actors to the Clop ransomware gang, warning not to threaten them and including a link to ShinyHunter's own data leak site.
data_breach
5,000 purported FBI employee records
404 Media
first reported
the alleged breach after receiving a sample containing approximately 5,000 purported FBI employee records.
organisation
POST
The attackers either sent multiple POST requests to access web shells behind some load-balanced environments, likely to ensure that a copy of the web shell is deployed on every WebLogic node, or sent POST requests that returned command output directly in the HTTP response to spawn the shell processes.
organisation
WebLogic
The attackers either sent multiple POST requests to access web shells behind some load-balanced environments, likely to ensure that a copy of the web shell is deployed on every WebLogic node, or sent POST requests that returned command output directly in the HTTP response to spawn the shell processes.
organisation
US Department of Justice
The publication said it verified that some information in the sample was accurate, including phone numbers corresponding to people with the same names and numbers associated with US Department of Justice personnel.
organisation
0APT
Public feuds and attacks between cybercriminal groups aren't uncommon; earlier this year, two emerging ransomware groups,
0APT and KryBit
, hacked one another and leaked internal data.
organisation
KryBit
Public feuds and attacks between cybercriminal groups aren't uncommon; earlier this year, two emerging ransomware groups,
0APT and KryBit
, hacked one another and leaked internal data.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
ASCII
The background of the site was also changed to ASCII artwork of a
Pokémon.
organisation
KnowBe4
"This is a useful reminder that cybercriminal groups are not a single, coordinated ecosystem; they are competitive businesses driven by trust, reputation and money,” said Javvad Malik, lead CISO advisor at KnowBe4.
threat_actor
Scattered Spider
The group's identity has become increasingly fluid, with researchers observing ties to and collaboration with cybercriminals associated with the
Scattered Spider
and Lapsus$ collectives.
organisation
Lapsus$
The group's identity has become increasingly fluid, with researchers observing ties to and collaboration with cybercriminals associated with the
Scattered Spider
and Lapsus$ collectives.
organisation
Fortra GoAnywwhere
Clop actors were behind the massive 2023 campaign that exploited a zero-day in Progress Software's
MOVEit file transfer software
, as well as a similar campaign that targeted a
Fortra GoAnywwhere flaw
that same year.
organisation
Vectra AI Launches Ascent
Related:
Vectra AI Launches Ascent to Help Address New Era of AI-Driven Attacks
organisation
Help Address New Era
Related:
Vectra AI Launches Ascent to Help Address New Era of AI-Driven Attacks
organisation
Keeper Security
Similarly, Darren Guccione, CEO and cofounder at Keeper Security, said the fundamental problem behind this is that "you can't rely on criminals to honor agreements" even if you paid a ransom.
organisation
Guccione
"Paying for deletion assumes the criminal will destroy the data, but you're negotiating with someone whose business model is deception and theft," Guccione says.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
Related:
Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability
Related:
China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks
Related:
New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining
Related:
Mandiant and GTIG observed the hacking group establishing persistence through two complementary, single-line JSP web shells, and deploying the SideEye backdoor on Windows servers to steal credentials from browsers and applications, manage files and processes, and gain reverse shell and reverse proxy capabilities.
Metrics
victims
100
Peoplesoft Customers
ShinyHunters
, tracked by Google as UNC6240, targeted
more than 100 PeopleSoft customers
in June.
Metrics
data_breach
5,000
Purported Fbi Employee Records
404 Media
first reported
the alleged breach after receiving a sample containing approximately 5,000 purported FBI employee records.
Metrics
data_breach
2
Tb
ShinyHunters claims it stole between 2TB and 3TB of data from the agency, including information on current and former FBI employees, job applicants, and other internal records.
Metrics
data_breach
3
Tb
ShinyHunters claims it stole between 2TB and 3TB of data from the agency, including information on current and former FBI employees, job applicants, and other internal records.
Metrics
victims
40,000
Corporate Customers
ShinyHunters also recently
claimed an attack on American healthcare giant McKesson
, which wholesale medical supplies and pharmaceutical distribution to over 40,000 corporate and institutional customers.
Intelligence Sources
Data Breaches
2026-09-19
BleepingComputer
2026-09-19
BleepingComputer
2026-09-22
SecurityWeek
2026-09-28
Dark Reading
2026-09-21
Infosecurity-Magazine
2026-09-21
ShinyHunters Claim Hack of Rival Ransomware Gang Clop
Infosecurity-Magazine
AlienVault OTX
2026-09-28
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Reset / Delete
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-06T10:43
Comprehensive Tactical Telemetry
Highly Correlated Entities
46x
organisation
Identified Entity
CVE-2026-35273
entity
16x
timeline
Temporal Reference
May 2026
date
10x
industry
Targeted Sector
Finance
sector
9x
attribution
Attributing Entity
Google Threat Intelligence Group
authority
8x
tactic
Cyber Operation Type
Botnet
tactic
4x
target region
Target Country
United Kingdom
country
4x
tactic
MITRE ATT&CK Technique
T1584.004 - Server
technique
2x
vulnerability
Exploited CVE
CVE-2026-35273
cve
2x
threat actor
APT Group
ShinyHunters
actor
2x
malware
Malware Payload
Neo-reGeorg
tool
2x
data breach
Tb
2
tb
2x
general metric
Hours
24
hours
Contextual Telemetry
Context Block
12 METRICS
general metric
Cve-2026
35,273
cve-2026
infrastructure
Affected Product
Windows
software
victims
Peoplesoft Customers
100
peoplesoft customers
general metric
%
50
%
source region
Origin Country
United States
country
general metric
Media
404
media
data breach
Purported Fbi Employee Records
5,000
purported fbi employee records
general metric
Fortune
500
fortune
general metric
Suite Theft Campaign
2,025
suite theft campaign
victims
Corporate Customers
40,000
corporate customers
general metric
People
3,500,000
people
general metric
Gang
1
gang
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.