Two of the most notorious names in data extortion are now fighting each other rather than their victims. According to a report by Golem, the ShinyHunters crew claims to have broken into infrastructure belonging to Clop — the ransomware group also tracked as Cl0p — and the two operations are trading accusations in darknet forums.

Both have spent years building names that make the spat worth watching. Clop industrialised "hit-and-run" mass extortion: rather than encrypting one company at a time, it exploited a single widely used file-transfer product — Accellion, GoAnywhere, MOVEit and later Cleo — to steal data from hundreds of organisations at once and demand payment under threat of publication. ShinyHunters built its reputation on high-volume theft and leak-site sales, and has been linked to some of the largest cloud-data extortion campaigns of recent years.

That pattern is what makes a feud between them notable. The modern extortion economy is less a hierarchy than a crowded market of affiliates, access brokers, negotiators and leak sites, all competing for the same victims and the same attention. When two big crews collide, the fallout does not stay inside their own channels: stolen chats, tooling and affiliate lists tend to spill into public view, and rival groups may try to poach each other's members.

For defenders, the episode is a reminder of two things. First, cybercrime groups are not a monolith — they compete, betray and sometimes destroy each other, and accidental leaks from those fights occasionally hand investigators real intelligence. Second, none of this reduces the threat: the same crews remain active against ordinary organisations, and their disputes are, at most, a distraction from the underlying economics of extortion, which still pays.

Golem's report relays claims and counter-claims from both sides; as with any darknet dispute, the accounts are self-serving and hard to verify independently.