ShinyHunters hackers claim to have hit data center provider used by Microsoft and Meta
Date:
Wed, 26 Aug 2026 17:10:00 +0000
Description:
The hackers are asking for $13 million from CyrusOne, and have given the company a four-day deadline to comply.
FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter ShinyHunters adds CyrusOne to its victim list, demanding $13m ransom Claimed theft includes 12.9 million Salesforce records, 600GB SharePoint data, PII, contracts, and facility diagrams Breach could enable physical intrusions and supplychain attacks; CyrusOne has not commented or paid The infamous ShinyHunters ransomware crew has added CyrusOne, a major US data center operator, to its list of victims, claiming to have stolen a treasure trove of highly sensitive data which, if proven true, could turn this into a bonafide catastrophe for the company and its customers.
Overall, ShinyHunters claims to have exfiltrated 12.9 million Salesforce records, more than 182,000 rows from the Salesforce Contacts object, more
than 600 GB of SharePoint data, more than 8,300 employee records containing personally identifiable information (PII), executed contracts, master service agreements, NDAs, and service agreements, data center floor plans, electrical diagrams, access-control records and badge audits, physical key inventories, security policies, critical Environment Reliability Management documentation, and various passwords and credential artifacts. No samples have been posted just yet, but researchers dont see it as suspicious, but rather as a pressure tactic. Latest Videos From TechRadar Watch full video here: What makes this attack different In exchange for deleting all of the stolen data,
ShinyHunters is demanding $13 million from CyrusOne which, at this time, is not commenting on the claims, and is seemingly not interested in
negotiations.
They are refusing to pay a $13 million demand. They have 24 hours left to engage with us. We hold 12.9 million Salesforce records, the attackers allegedly wrote. You may like Organized criminals are increasingly targeting data center cargo Hackers target data center equipment, including critical power devices Millions of stolen records allegedly dumped online by mystery "Hatman" hacker McDonalds, Vodafone and more see Microsoft Azure records stolen
Ransomware groups steal sensitive corporate data all the time, but this incident has the potential to be among the most devastating data breaches ever. Some of the secrets that were nabbed cannot simply be changed: data center floor plans, electrical diagrams, access-control records, badge
audits, physical key inventories, this kind of intelligence can be used for physical breaches.
If criminals know how keys are assigned, how the data center is organized, where surveillance cameras are located, and how guards operate, it makes it easier to physically break it. Are you a pro? Subscribe to our newsletter
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news
and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.
You cant patch a building, the researchers warned, noting that some of the things that can be changed, such as physical keys and access zones, still
take months and real money, they added, hinting at just how big the problem could be.
CyrusOne runs some 50 facilities all across the United States and serves hundreds of companies and corporations. Some of its clients include Fortune 1000 companies, as well as big tech names such as Microsoft , Meta, Verizon, AT&T, IBM, and CME Group.
Compounding the problem even further is the fact that ShinyHunters stole information about CyrusOnes customers, such as Meta, or Microsoft.
Information about the locations of certain customers, the services theyre paying for, the NDAs, service-level agreements, and contact information, can all be used for highly tailored, sophisticated phishing attacks that could turn this incident into an unprecedented third-party supply-chain attack.
What to read next 2.6 million DentaQuest accounts exposed by data breach ShinyHunters claim 234GB of data stolen NAIC confirms data breach with ShinyHunters claiming 3.1TB of data stolen in Oracle zero-day attack
Microsoft introduces security upgrades to tackle ShinyHunters
Contracts, MSAs, and NDAs identify the tenants as a customer list overlaid on a building map, with pricing and SLAs attached, the researchers added. No reaction To add insult to injury, ShinyHunters also seems to have stolen information about the companys power, cooling, and critical-environment reliability processes, which they could leverage to physically attack the servers, causing disruptions, outages, and possibly fires.
The group first added CyrusOne to their site on August 20 2026, although at that moment, the name of the victim was redacted, the researchers said. Instead, ShinyHunters posted a warning, saying Final warning - pay or leak. The company was given until August 24 to reach out which, it would seem, did not happen.
Three days later, on August 23, ShinyHunters publicly named CyrusOne as their victim, and stated that they demanded $13 million for the files. We are now well past the deadline, and nothings changed - the victim hasnt spoken out, and ShinyHunters did not leak the files.
Via Cybernews The best antivirus for all budgets Our top picks, based on real-world testing and comparisons
Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
======================================================================
Link to news story:
https://www.techradar.com/pro/security/shinyhunters-hackers-claim-to-have-hit- data-center-provider-used-by-microsoft-and-meta
--- Mystic BBS v1.12 A49 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)