Ransomware crews have spent years pressuring victims to pay up. Now they are doing it to each other. Earlier this month, extortion group ShinyHunters took over the dark web site of the Cl0p ransomware gang and held Cl0p's own data for an eight-figure ransom. The ShinyHunters Cl0p ransomware takeover is a strange story on its surface, but it carries a practical lesson for anyone whose data sits on someone else's systems.
What ShinyHunters Did to Cl0p's Leak Site
According to the reporting, ShinyHunters gained control of the dark web site that Cl0p uses to operate its extortion business. It then posted a notice demanding an eight-figure payment in return for Cl0p's own data. "I hope you can pay that much because that is the demand, negotiable," ShinyHunters said in the notice, which was also reported by The Record.
The tone is worth noting. The message mimics the language ransomware groups routinely aim at their victims: a large demand, a hint of flexibility, and a clear attempt to apply pressure. In effect, one extortion crew ran its own playbook against another.
The source article, a Mastercard overview of how ransomware is evolving, mentions the incident as an example of the shifting tactics and business models in this criminal ecosystem. The details available to us are limited to that notice and the demand itself, so it is best to avoid guessing about what data was taken or how access was gained.
Why Ransomware Gangs Are Turning on Each Other
The episode fits a broader theme: ransomware is not a single, tidy industry. It is a loose economy of groups with overlapping tools, targets and reputations. Those groups compete for victims, attention and payouts, and there is no honor among them.
A few reasons rivalry like this can emerge:
- Data is currency. Stolen files are the product. A group that holds a rival's data, or its infrastructure, holds leverage.
- Reputation matters. Leak sites are a public stage. Taking one over is a way to embarrass a competitor and signal strength.
- Operations depend on infrastructure. Extortion groups rely on servers, sites and communication channels. Like any organization, they can be breached.
None of this makes either group less dangerous. A feud between criminals is not a safety net for their victims. If anything, it shows how unpredictable the market is. For a view of which groups are currently most active, see our Q2 2026 ransomware roundup, which covers how the field has reshuffled its cast of characters.
What This Means For You
The core lesson is simple: once your data sits on someone else's infrastructure, you no longer fully control what happens to it. That is true for a company's customer records, and it is true for the personal files you store with online services. Even the criminals holding stolen data cannot guarantee its safety, as this incident shows.
For organizations that have already been hit, this raises an uncomfortable point. Paying a ransom or negotiating with an extortion group does not guarantee that stolen data stays contained. It can end up in the hands of other parties, and the group holding it can itself be compromised. We cannot say from the source whether any specific victim data was exposed in this case, but the principle holds.
For individuals, it is a reminder that you rarely get to choose how well a company protects what it holds about you. What you can control is how much sensitive information you hand over, how it is protected, and how quickly you can recover if something goes wrong.
How to Prepare: Backups, Encryption and Access Hygiene
You cannot stop rival gangs from fighting, but you can reduce how much damage any of them can do to you. Focus on the basics, and do them well.
Backups
- Keep at least one backup offline or otherwise isolated from your main network, so ransomware cannot reach it.
- Test restores regularly. A backup you have never restored is a hope, not a plan.
- Encrypt sensitive files before they are stored or shared. Data that is encrypted with keys you control is far less useful to anyone who steals it.
- Use full-disk encryption on laptops and phones.
Access hygiene
- Turn on multi-factor authentication for email, cloud storage and remote-access tools.
- Use unique, strong passwords with a password manager.
- Review who has remote access to your systems and remove accounts that are no longer needed.
- Keep software patched, since attackers commonly exploit known weaknesses.
A VPN can help protect your traffic on untrusted networks and is one useful layer for remote access, but it is not a defense against ransomware on its own. Treat it as one part of a broader set of habits.
Takeaways
The ShinyHunters Cl0p ransomware takeover is a vivid sign that the ransomware economy is volatile and that stolen data rarely stays under anyone's control. Do not count on criminal infighting to protect you.
- Assume data held by third parties can be exposed, and share only what is necessary.
- Maintain isolated, tested backups.
- Encrypt sensitive data and lock down accounts with multi-factor authentication.
- Audit your remote-access practices on a regular schedule.
To see which groups are currently the most active, read our Q2 2026 ransomware roundup, then take an hour this week to review your own backup, encryption and remote-access setup.




