Two of the crews that have done the most damage to healthcare providers are fighting each other in public, and the fallout is landing on the same dark web channels hospitals watch for breach notices.
ShinyHunters defaced the long-running leak site Cl0p uses to name victims, replacing it over the weekend with a banner claiming the domain had been seized. The intruders posted an eight-figure demand they described as 2.333% of Cl0p’s net worth, said the figure would rise every 24 hours, and later added a public apology to their terms. By Monday Cl0p had answered with a message asking ShinyHunters to come online.
The fight traces to a flaw in Oracle’s E-Business Suite. ShinyHunters published a working proof-of-concept on Telegram, then watched Cl0p run its own campaign on the same vulnerability. Patches became urgent enough that Oracle and the FBI issued warnings, joined by cyber agencies in Britain and Singapore. The stakes for hospitals are direct: enterprise resource planning platforms such as E-Business Suite sit behind finance and supply-chain operations, and the extortion attempt includes a threat to publish records showing which victims paid Cl0p, how much they paid and which Bitcoin addresses were used.
Both groups carry deep healthcare rosters. Cl0p has listed Philips, Starkey and Mindray; ShinyHunters has hit McKesson, Baxter, Medtronic and NovoCure, and stole records tied to roughly 4 million people in an April strike on the world’s largest medical device maker.