CyrusOne, LLC. in the US reported a ransomware extortion claim by shinyhunters, stating they refused a $13 million demand and faced a 24-hour deadline. The attackers alleged theft of 12.9 million Salesforce records plus substantial SharePoint files and sensitive business, employee, and security documentation, warning of data leakage if demands were not met. #UnitedStates
Incident Details
- Victim: CyrusOne, LLC.
- Sector: Technology
- Country: US
- Actor: shinyhunters
- Source:
- Discovered: 2026-08-23T20:27:42.698495+00:00
- Published: 2026-08-23T11:10:00+00:00
Information
- We are removing the clients name off this post. They are refusing to pay a $13 million demand.
- They have 24 hours left to engage with us.
- We hold 12.9 million Salesforce records along with SharePoint data: 369.6 GB compressed / 645 GB uncompressed, 288,729 files, and 60,513 folders.
- More than 182,000 rows of customer data were extracted from the Contacts Salesforce object.
- Over 8,300 rows of employee PII were obtained, including full names, emails, job titles, and phone numbers.
- Thousands of executed contracts, MSAs, NDAs, amendments, leases, and SOWs are included.
- The data also contains extensive physical key inventory logs, verification photos, and contractor Green Badge audits.
- A large collection of data center drawings, floor plans, electrical one-line diagrams, security system drawings, and site schematics was taken.
- The full CERM (Critical Environment Reliability Management) process library is included.
- The archive contains physical and information security policy suites plus governance materials.
- Regional security scorecards, KPI workbooks, GAM sheets, and signed performance packages are included.
- Credential and access-control artifacts were also obtained, including PasswordList.xlsx, Okta SSC access lists, active badge reports, and multiple Data Center Access Control forms.
- This is a final warning to make contact by end of day 24 Aug 2026 before the leak and additional digital disruptions.
- Warning: final warning, pay or leak.
Disclaimer: This post is based on public claims made by the ransomware group "shinyhunters". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.