Security/ shinyhunters · data-breach · cyrusone · ransomware

Hackers Claim They Breached a Data Center Microsoft and Meta Use

ShinyHunters says it stole 12.9 million Salesforce records and facility blueprints from CyrusOne, and wants $13 million to not leak them.

A ransomware crew says it broke into CyrusOne, one of the largest data center operators in the US, and is threatening to leak the loot unless it gets paid $13 million.

ShinyHunters claims to have exfiltrated 12.9 million Salesforce records, more than 600GB of SharePoint files, and over 8,300 employee records containing personal information. The group also says it grabbed contracts, NDAs, and service agreements, plus facility floor plans, electrical diagrams, badge-access logs, physical key inventories, and environmental reliability documentation. CyrusOne has not confirmed the breach or commented publicly, and researchers say the company appears unwilling to negotiate. The attackers first listed CyrusOne anonymously on August 20, 2026, named the company on August 23, and set a ransom deadline that has now passed without a leak or a payment.

CyrusOne hosts infrastructure for Microsoft, Meta, Verizon, AT&T, IBM, and CME Group across roughly 50 US facilities, so the real exposure extends well past CyrusOne itself. Contracts and floor plans that pair a customer list with building layouts and security details give attackers a blueprint for both targeted phishing and, researchers warn, physical break-ins that can't simply be patched. Tenant data combined with building security details is what separates this from a routine ransomware smash-and-grab.

Unlike a stolen password, a badge-access map and a key inventory take months and real money to replace, which is exactly the kind of leverage that makes staying silent look like the more expensive option.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →