Cybersecurity · Monday, 21 September 2026
One extortion gang broke into another gang's website and defaced it. It says it took the code, the logs and the keys.
ShinyHunters says it got full access to the site cl0p uses to publish stolen company files, after a year-long row over who found an Oracle flaw first. Reporters confirmed the defacement but not the rest.
100+
companies cl0p stole data from using the Oracle flaw
the estimate of a Google analyst, quoted by Reuters
600+
companies cl0p hit in 2023 through a flaw in MOVEit file-transfer software
records on tens of millions of people were taken then
~50
companies cl0p claimed data from last month alone
its list named Philips, Shell, Fiserv and GE
The lead story — what happened
-
The extortion group ShinyHunters broke into the website that the ransomware gang cl0p uses to publish files stolen from companies.
[2] -
It began on Friday night by uploading a small text file through a flaw in Grav CMS, the free website software the site runs on.
[2] -
Hours later the page had been replaced with a picture of the group's Pokemon logo and the line "rooting your systems since '19".
[2] -
ShinyHunters says it then took cl0p's source code, its system logs, and the private keys for the site's Tor web address.
[2] -
BleepingComputer confirmed the defacement and the uploaded file, but could not check the claims about the code, the logs or the keys.
[2] -
Asked what it would do with what it took, ShinyHunters answered: "Going to extort them."
[2] -
The two fell out over a break-in tool for Oracle's E-Business Suite, the software big firms run their accounts on.
[1] -
ShinyHunters told Reuters it found the Oracle flaw first and that cl0p stole it last year.
[1] -
cl0p then threatened to publish the names of several ShinyHunters members, and ShinyHunters threatened to publish how cl0p works inside.
[1] -
cl0p did not answer repeated messages from Reuters, and its site could not be reached on Sunday.
[1] -
Reuters said it could not establish whether ShinyHunters' account of the quarrel is true.
[1]
Who is involved
-
ShinyHunters
an extortion group that steals company data and demands payment for not releasing it; it broke into cl0p's site
-
cl0p
a Russian-speaking ransomware gang known for finding flaws in business software; its site was defaced
-
Grav CMS
the free website software cl0p's leak site runs on; ShinyHunters says a file-upload flaw in it was the way in
-
Oracle
one of the world's biggest makers of software for large companies; the flaw the two gangs fell out over was in its E-Business Suite
How it unfolded
-
2023 cl0p uses a flaw in MOVEit file software to take data from more than 600 companies
-
Last year ShinyHunters says cl0p stole its Oracle break-in tool
-
Last month cl0p claims files from nearly 50 companies, including Shell and GE
-
Fri night ShinyHunters uploads a taunting file to cl0p's site
-
Sat the site is defaced; ShinyHunters says it has full access to the server
-
Sun Reuters finds cl0p's site unreachable
Where this points
Watch whether the stolen company files held on cl0p's site are moved or published by whoever controls the address now, because that would show the claim about the Tor keys was real.
What is pushing on the whole day
The bar and the word are our reading of how hard each one is pushing today. The arrow is where it is heading. The evidence is in the stories below.
Jaguar Land Rover says 4,000 jobs will go and blames the attack that shut its factories in September 2025.
The US Treasury sanctioned BitBank, an Iranian exchange it says moved hundreds of millions of dollars to Iran's Revolutionary Guard.
South Korean police counted 336 billion won, about $246.57m, in stock-chatroom fraud cases in six months.
SolarWinds fixed a key that was built into every copy of its Access Rights Manager software.
Britain's air traffic service traced a six-hour outage that cancelled more than 2,000 flights to a software defect, not an attack.
The rest of the day
16 more stories on this beat.
Each with its own sources. None of these is a link to the story above.
-
02
Jaguar Land Rover to cut 4,000 jobs
The British carmaker Jaguar Land Rover shut its UK plants through September 2025 after an attack on its computers, stopping production of about 1,000 cars a day.
[3] More than 5,000 other companies were caught by the shutdown, and the Bank of England said it helped slow national growth figures.[3] The carmaker has now said it will cut 4,000 jobs and blames the attack.[3] Britain's Cyber Monitoring Centre puts the cost at 1.9 billion pounds and calls it the most economically damaging cyberattack in British history.[3] United States412Europe369Ransomware attacks on manufacturers and distributors so far this year, counted by the security firm Black Kite. Why it matters — It is the clearest price tag yet on a single ransomware attack, and the people losing their jobs had nothing to do with the computers that were broken into.
-
03
SolarWinds fixes a key built into every copy
SolarWinds, whose software many large organisations use to manage their networks, has patched a flaw in Access Rights Manager, the product that controls who may open which files.
[4] The flaw, numbered CVE-2026-28326 and scored 8.8 out of 10, comes from a hard-coded static key: the same secret value shipped inside every copy of the software.[4] Anyone who learns it can run their own commands on the server without logging in at all.[4] It affects version 2026.2 and everything before it.[4] Why it matters — A secret that is identical in every copy stops being a secret the first time one person takes it apart, and every customer is then exposed at once.
-
04
A leaver's account was still open in May
CrowdSec, a French security company, says an attacker copied about 170 of its private code stores on 22 May using the account of an employee who had just left, because his access had never been switched off.
[5] His laptop had been infected in May's attack on TanStack, in which poisoned versions of popular free code packages stole passwords from developers' machines.[5] The code appeared on an online forum on 16 September, together with the email addresses of 83 CrowdSec users and details of 51 would-be investors.[5] CrowdSec made it public two days later.[5] Why it matters — Closing a departing colleague's accounts is dull administrative work, and four months passed here between the copying and anyone noticing.
-
05
Britain's flight chaos was a software fault
NATS, the company that runs Britain's air traffic control, says the failure that cancelled more than 2,000 flights earlier this month came from a software defect, not an attack.
[6] [7] Corrupted flight data was produced "in the space of a millisecond" after an aircraft asked for an identification code.[6] [7] Chief executive Martin Rolfe said the fault has been traced to a small section of code and a temporary fix is in place.[6] Transport minister Heidi Alexander called the disruption "completely unacceptable" and ordered a review by the Civil Aviation Authority.[6] Why it matters — Passengers stuck on airport floors are unlikely to be compensated, because the regulator has judged it extraordinary circumstances.
[7] -
06
South Koreans lost $250m in chat-room scams
South Korean police investigated 3,506 cases involving stock-tip chat rooms between January and June, covering 336 billion won, or about $246.57m.
[8] The number of cases rose only 4.1% on the same months last year, but the money involved was up 19.8%.[8] South Korea's main share index, the KOSPI, was the world's best performer in the first half of the year and then fell as much as 44% from its June peak.[8] Lawyers told Reuters the scammers switched from cryptocurrency and property schemes to share tips to match the rally.[8] Number of cases4.1%Money involved19.8%How much each figure rose against the same six months of last year, from South Korean police data. Why it matters — Inexperienced investors afraid of missing a rising market were the ones targeted, and the money lost grew faster than the number of victims.
-
07
US sanctions an Iranian crypto exchange
The US Treasury has sanctioned BitBank, a cryptocurrency exchange linked to the Iranian financier Babak Zanjani, saying it routed hundreds of millions of dollars to Iran's Revolutionary Guard.
[9] Treasury also named it as a route for money paid to Iran's newly created Hormuz Safe Marine Services Authority, and sanctioned Pishtaz Simorgh Electronic Trade Company, which wrote BitBank's software.[9] Zanjani was sentenced to death in Iran in 2016 for embezzlement; the sentence was commuted in 2024 and he reappeared the following year backing Iranian state projects.[9] Why it matters — Sanctions on an exchange are aimed at the plumbing rather than the people, and they only work while banks and exchanges elsewhere check who they are dealing with.
-
08
A Hong Kong crypto exchange is closing
CoinEx, a cryptocurrency exchange based in Hong Kong and launched in 2017, says it will shut down.
[10] Founder Haipo Yang said weak markets, thinner trading and rising rules in major countries had "exceeded reasonable boundaries", and that the security and compliance risks of running an exchange had become hard to contain.[10] He said the exchange had millions of users but gave no figure.[10] A June report by the US research firm TRM Labs named CoinEx as the largest single trading partner of Nobitex, an Iranian exchange put under US sanctions that month.[10] Why it matters — Customers of an exchange that closes have to move their money out on the operator's timetable, and CoinEx did not answer questions about the Iranian link.
-
09
A home camera opened without a password
Researchers at the security firm OPSWAT found two flaws in TP-Link's Tapo C200, a cheap indoor camera sold for watching homes and pets.
[11] One lets somebody already on the same wifi network replay a value from the camera's own security check and get administrator access without knowing the password.[11] The second crashes the camera's secure connection by sending oversized wifi details while it is being set up.[11] TP-Link fixed both, numbered CVE-2026-15315 and CVE-2026-15316, in firmware released in August.[11] Why it matters — A camera that can be opened by anyone on the home network turns a device bought for reassurance into a window into the room.
-
10
Two US agencies publish cloud sign-in advice
NIST, the US standards body, and CISA, the US cyber-defence agency, have published a joint report telling government departments and cloud providers how to protect sign-in tokens.
[11] A token is the pass a system hands you once you have logged in, and it keeps working afterwards without asking for a password again, which is why stealing one is now a common way in.[11] The report covers checking tokens, storing secrets and spotting misuse at scale, and it takes in comments on an earlier draft.[11] Why it matters — Guidance is not a fix, but it sets what a government department can be held to when its cloud accounts are opened with a stolen pass.
-
11
Eleven flaw numbers at once in school software
The Hacker News's weekly list of fixes worth applying urgently includes eleven separate flaw numbers for Chamilo, a free platform that schools and universities use to run online courses.
[12] They were published together by researchers at the security firm Quarkslab.[12] The same list carries urgent fixes for Microsoft Windows, SAP, GitLab, Citrix, Ivanti, Fortinet, FreeIPA and the UEFI Shell, which is part of the startup software in most computers.[12] Why it matters — A platform holding a school's coursework and pupil accounts rarely has anybody whose job is watching for flaw announcements.
-
12
$667,000 goes back from Jersey
Jersey's Attorney General has returned $667,000, about 495,000 pounds, to the US Department of Justice from a bank on the island.
[13] The money had been deposited there by Gustavo Geraldes, who ran a medical fraud in the United States during the pandemic: telemedicine providers authorised genetic tests nobody needed, at laboratories he part-owned, and he paid them for it.[13] He was convicted in April 2022 and ordered to hand over $2.64m traceable to the scheme; the Jersey money counts towards that total.[13] Why it matters — Money can be followed across borders and clawed back, which is not true of the medical records and personal details taken in most of the other stories here.
-
13
A friend's name on fifteen fake companies
Neil Moore, 58, of Newcastle, has been given a one-year sentence suspended for 18 months at Newcastle Crown Court after admitting transferring criminal property.
[14] He made more than 37,000 pounds by letting his name be used on fictitious companies set up by Timothy Paul Nellis, who claimed 722,000 pounds in pandemic loans meant to keep businesses alive.[14] Nellis set up 15 fake companies between April and November 2020 and was jailed for almost 18 years in December; a third man, Sundeep Chahal, is still on the run.[14] Why it matters — A loan scheme designed to pay out in days had almost no checks at the front, so the checking happened years later in a courtroom.
-
14
35 more victims of a fake footballer
The FBI says it has found 35 more people who lost money to Daejon Love, 35, who prosecutors say spent four years on dating apps pretending to be a wide receiver for the San Francisco 49ers, an American football team.
[15] Prosecutors say he persuaded dozens of women to invest with him and spent the money on himself, keeping up the story with a spread of social media accounts.[15] An alleged accomplice, Taylor Chan, 18, is accused of posing as Love's financial adviser and making fake bank documents.[15] Both face wire fraud charges.[15] Why it matters — The cover story was detailed enough to survive the checks a cautious person actually makes, including a search engine and an AI assistant.
[15] -
15
Fifteen charged over US aid money
US federal prosecutors charged three people over $12m taken from Southern California homelessness programmes, a week after charging twelve others over more than $10m in childcare aid.
[16] [17] The three worked for or ran non-profit groups holding public contracts to house and support homeless people.[16] Prosecutors say they paid personal bills from those contracts, took bribes and billed for work never done.[16] In the childcare case, the head of the US tax authority's criminal division said the money went on luxury homes, transfers abroad and large cash withdrawals.[17] Why it matters — Programmes built to pay out quickly to people in need are the ones with the fewest checks between the application and the money.
-
16
Dell patches its server management tool
A flaw numbered CVE-2026-81480 has been published for Dell OpenManage Server Administrator, the software companies use to watch and control Dell servers from a distance.
[18] It is a stack-based buffer overflow, a fault where a program is handed more data than it set aside room for and starts overwriting whatever sat next to it.[18] Dell says an attacker who already holds high-level access and can reach the machine over the network could use it to run their own code.[18] Versions before 11.1.0.3 are affected.[18] Why it matters — It needs an attacker to be inside already, which is precisely the position everything else in this briefing is about reaching.
-
17
A security expert argues surveillance has gone far enough
Bruce Schneier, a long-standing writer on computer security, has published an essay with the lawyer Cindy Cohn arguing that the mass surveillance built after the attacks of 11 September 2001 should be wound back.
[19] They describe a shift from targeted wiretaps to bulk collection of internet and phone records, and say it is now used routinely for immigration enforcement and against protesters rather than for terrorism.[19] They also trace how data gathered by companies for advertising ends up available to police and immigration agencies.[19] Why it matters — It puts a name on the quiet part of every breach story here: the material stolen from companies exists because it was collected in the first place.
The break-in ends in a day. The paying takes years.
Jaguar Land Rover's factories were attacked a year ago, and this month the carmaker said 4,000 jobs will go.
The twist
An attack is over in hours. Four thousand Jaguar Land Rover jobs are going a year after its factories were switched back on.
The picture
How it works
- Attackers get in and take what they came for
- The company shuts systems down to stop it spreading
- Production, payments and paperwork stop with them
- Customers, suppliers and staff wait while it all restarts
- The bill lands months or years afterwards
The same force, elsewhere today
Where this chain is also running, in today's other stories.
-
Jaguar Land Rover cutting 4,000 jobs
the attack shut the factories in September 2025 and the job cuts were announced a year later
-
CrowdSec's copied code
the repositories were copied on 22 May and the company found out on 16 September, when the files turned up on a forum
-
The $667,000 returned from Jersey
Gustavo Geraldes was convicted in April 2022 and this slice of the money he hid has only now reached the US government
-
The fake American football player
the scam ran for four years and the FBI is still adding people to the list of those who lost money
Where you've seen this
A house fire
the fire is out in an hour and the insurance claim and the rebuild take a year
A car crash
the crash lasts two seconds and the court case runs for years
A flood
the water drains in days and families are out of their homes for months
The catch
Some of the cost never appears anywhere. Nobody counts the customers who quietly went elsewhere, or the small supplier that ran out of orders and closed.
And the whole of it
The 4,000 people losing their jobs at Jaguar Land Rover never chose the software, and the 5,000 other firms caught in the shutdown were never attacked. Each one only ever sees the part of the cost that lands on them.
What is really going on
ShinyHunters says it broke into cl0p's website because cl0p stole its Oracle break-in tool last year, so this is two gangs fighting over who owns a way into other people's computers. The files sitting on that website were taken from more than a hundred companies, and none of them were asked about any of this.
Why it works on us — A fight between two criminal gangs is easy to read as a spectator sport, because both sides are the villain and neither is asking anyone for sympathy.
Who gains
-
ShinyHunters
— It says it holds cl0p's source code, its logs and the keys to its web address, which is leverage in a quarrel cl0p escalated by threatening to name its members.
[1] [2] -
The newer ransomware groups
— Half of this year's attacks on manufacturers were run by groups that did not exist two years ago, and one of them claimed 12% of the year's total on its own.
[3] -
Scam operators in South Korea
— Police counted 336 billion won, about $246.57m, in stock-chatroom cases over six months, with the money involved up 19.8% on last year.
[8] -
Whoever copied CrowdSec's code
— One infected laptop in May gave them a departing employee's still-open account, and 170 private code stores went out through it.
[5] -
The US Treasury's Iran sanctions programme
— Naming BitBank and the firm that wrote its software closes a route Treasury says carried hundreds of millions of dollars to Iran's Revolutionary Guard.
[9]
Who pays
-
The companies whose stolen files sit on cl0p's website
— cl0p took data from more than 100 firms through the Oracle flaw, and a rival group now says it has full access to the server holding it.
[1] [2] -
4,000 Jaguar Land Rover workers
— The carmaker says the jobs will go and blames the attack that shut its plants in September 2025.
[3] -
Small investors in South Korea
— Police investigated 3,506 stock-chatroom cases in six months, and lawyers told Reuters the targets were inexperienced investors chasing a rising market.
[8] -
Passengers on more than 2,000 cancelled British flights
— The outage came from a software defect rather than an attack, and the regulator has judged it extraordinary circumstances, so most of them get no compensation.
[6] [7] -
CoinEx's users
— The Hong Kong exchange says it will close, telling millions of account holders that the security and compliance costs of running it had passed what it could contain.
[10]
What nobody knows yet
Open questions from across today’s stories — ours included.
-
01
Whether ShinyHunters really holds the private keys to cl0p's web address.
BleepingComputer confirmed the defacement and the uploaded file, and says it could not check the claims about the keys, the source code or the logs.
[2] -
02
Who actually found the flaw in Oracle's E-Business Suite first.
ShinyHunters told Reuters it did and that cl0p took it, and Reuters said it could not establish whether that account of the quarrel is true.
[1] -
03
What now happens to the stolen company files held on cl0p's site.
Neither group has said, and cl0p did not answer repeated messages from Reuters.
[1] -
04
How many of Jaguar Land Rover's 4,000 job cuts are down to the attack.
The carmaker blames the attack and no breakdown has been published.
[3] -
05
How the 1.9 billion pound figure for that attack was worked out.
It is an estimate by Britain's Cyber Monitoring Centre, and the method behind it is not given.
[3] -
06
What was in the 170 private code stores copied from CrowdSec.
The company has named the user emails and investor details that appeared with the code, but not what the code itself contained.
[5] -
07
Whether anyone used the SolarWinds key before the fix came out.
The advisory describes the flaw and the hard-coded key, and does not say whether it was ever attacked.
[4] -
08
How much of the $246.57m lost by South Korean investors will come back.
The police figures count cases and the money involved, not the money recovered.
[8] -
09
Why the fault in Britain's air traffic software was not found before 2,000 flights were cancelled.
The transport minister asked exactly that, and the Civil Aviation Authority's separate review has not reported.
[6]
A bank in Jersey has sent $667,000 back to the US Department of Justice. The money was hidden there by Gustavo Geraldes, who was convicted in April 2022 of paying telemedicine providers to order genetic tests nobody needed.
Also true today
- TP-Link has fixed two flaws in its Tapo C200 home camera. One of them let anybody already on the same wifi get administrator access without knowing the password.
- SolarWinds has published a fix for Access Rights Manager, removing a secret key that was the same in every copy of the software.
More from Cybersecurity
Across the beats