Breaking
Machine Learning

Ransomware Group Hijacks Rival Leak Site Demands Millions

By Blake Weston 2 min read
Ransomware Group Hijacks Rival Leak Site Demands Millions - ransomware group
ShinyHunters replaced the rival’s leak portal with ASCII art of Pokémon Umbreon and a takeover declaration by September 20.

A ransomware group known as ShinyHunters seized control of a rival’s Tor-based leak portal, repurposing it for their own extortion campaign. This confirmed the breach originated from the rival group’s systems, demonstrating even cyber-extortionists can become targets.

The defaced website displayed ASCII art of the Pokémon Umbreon alongside a declaration that the domain had been taken over. All original leak listings were erased, leaving no legitimate content. By September 20, the site no longer showed the usual data dumps. Instead, a header announced the domain seizure, and security researchers confirmed the change was genuine.

The attackers followed up with an eight-figure ransom demand tied to 2.333% of the victim’s presumed net worth, complete with a deadline that would increase the amount by a fixed percentage for each day the payment was delayed. They also insisted on a public apology and interest on profits allegedly earned from a previous campaign against Oracle E-Business Suite. The threats included publishing a list of companies that had paid ransoms, along with settlement figures and Bitcoin addresses.

The feud between the two groups began in 2025, when the victim exploited a vulnerability in Oracle E-Business Suite affecting over 100 organizations. The rival group claims it discovered the same flaw first and that the victim used its proof-of-concept code. Security researchers noted that the rival released a proof-of-concept exploit around the same time, which Oracle later confirmed matched the method used in the victim’s attacks. The rival also alleges that a representative from the victim threatened to expose its members, though this claim lacks independent verification.

Both sides rely on the same dark-web infrastructure typically used to host stolen data. The rival’s public seizure of the leak portal replicates the victim’s own extortion model: capturing a site, threatening data release, setting a deadline, and demanding a precise payout. The demand for 2.333% of the victim’s net worth carries symbolic weight alongside its financial implications. While no independent analysis confirms the victim’s net worth, an eight-figure sum suggests an assumed valuation in the hundreds of millions. The demand structure, fixed percentage, escalating penalties, and threats of public exposure, mirrors conventional corporate extortion tactics, though applied within a criminal ecosystem.

Blake Weston

Leave a Reply

Your email address will not be published. Required fields are marked *