Verizon, CyrusOne, AT&T and CME Group: ShinyHunters hackers claim to have hit data center provider used by Microsoft and Meta

Verizon, CyrusOne, AT&T and CME Group: ShinyHunters hackers claim to have hit data center provider used by Microsoft and Meta

ShinyHunters Targets CyrusOne in $13M Ransomware Attack, Stealing Highly Sensitive Data

The notorious ransomware group ShinyHunters has added CyrusOne, a major U.S. data center operator, to its list of victims, claiming to have exfiltrated a massive trove of sensitive corporate and operational data. The breach, if verified, could pose severe risks to both CyrusOne and its high-profile clients, including Fortune 1000 companies, Microsoft, Meta, Verizon, AT&T, IBM, and CME Group.

Stolen Data Includes Critical Infrastructure Details

ShinyHunters alleges the theft of:

  • 12.9 million Salesforce records and 182,000+ contact entries
  • 600GB of SharePoint data
  • 8,300+ employee records containing PII (personally identifiable information)
  • Executed contracts, NDAs, and master service agreements
  • Data center floor plans, electrical diagrams, and access-control records
  • Physical key inventories, badge audits, and security policies
  • Environmental reliability documentation (power, cooling, and critical infrastructure processes)
  • Passwords and credential artifacts

The attackers are demanding $13 million in exchange for deleting the data, threatening to leak it if CyrusOne does not comply. As of now, the company has not responded publicly or engaged in negotiations, despite the group’s 24-hour ultimatum issued on August 24, 2026.

Potential for Physical and Supply-Chain Attacks

Unlike typical ransomware incidents, this breach includes non-digital assets such as facility layouts, key inventories, and surveillance details that could enable physical intrusions into CyrusOne’s 50+ U.S. data centers. Researchers warn that such intelligence could allow attackers to bypass security measures, disable surveillance, or even sabotage infrastructure, leading to outages, fires, or supply-chain disruptions.

Additionally, the theft of customer contracts, SLAs, and contact details for major clients like Microsoft and Meta raises concerns about highly targeted phishing attacks, potentially turning this into a large-scale third-party supply-chain compromise.

Timeline of the Attack

  • August 20, 2026: ShinyHunters first listed a redacted victim on its leak site with a "Final warning - pay or leak" message.
  • August 23, 2026: The group publicly named CyrusOne as the victim and set a 24-hour deadline for payment.
  • August 24, 2026: Deadline passed with no response from CyrusOne; no data has been leaked yet.

ShinyHunters has not released samples of the stolen data, a tactic often used to increase pressure on victims. With no public statement from CyrusOne, the full extent of the breach and its potential fallout remains unclear.

Source: https://www.techradar.com/pro/security/shinyhunters-hackers-claim-to-have-hit-data-center-provider-used-by-microsoft-and-meta

Verizon TPRM report: https://www.rankiteo.com/company/verizonbusiness

CyrusOne TPRM report: https://www.rankiteo.com/company/cyrusone

AT&T TPRM report: https://www.rankiteo.com/company/att

CME Group TPRM report: https://www.rankiteo.com/company/cme-group

"id": "cmevercyratt1787768910",
"linkid": "cme-group, verizonbusiness, cyrusone, att",
"type": "Cyber Attack",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Fortune 1000 companies, '
                                              'Microsoft, Meta, Verizon, AT&T, '
                                              'IBM, CME Group',
                        'industry': 'Data Center/Colocation Services',
                        'location': 'U.S.',
                        'name': 'CyrusOne',
                        'type': 'Data Center Operator'}],
 'data_breach': {'data_exfiltration': True,
                 'number_of_records_exposed': '12.9M Salesforce records, 182K+ '
                                              'contact entries, 8.3K+ employee '
                                              'records',
                 'personally_identifiable_information': True,
                 'sensitivity_of_data': 'Highly sensitive (corporate, '
                                        'operational, and personal data)',
                 'type_of_data_compromised': ['Salesforce records',
                                              'Contact entries',
                                              'Employee records (PII)',
                                              'Executed contracts',
                                              'NDAs',
                                              'Master service agreements',
                                              'Data center floor plans',
                                              'Electrical diagrams',
                                              'Access-control records',
                                              'Physical key inventories',
                                              'Badge audits',
                                              'Security policies',
                                              'Environmental reliability '
                                              'documentation',
                                              'Passwords',
                                              'Credential artifacts']},
 'date_detected': '2026-08-20',
 'date_publicly_disclosed': '2026-08-23',
 'description': 'The notorious ransomware group ShinyHunters has added '
                'CyrusOne, a major U.S. data center operator, to its list of '
                'victims, claiming to have exfiltrated a massive trove of '
                'sensitive corporate and operational data. The breach includes '
                'critical infrastructure details such as data center floor '
                'plans, electrical diagrams, access-control records, and '
                'employee PII, posing severe risks to CyrusOne and its '
                'high-profile clients.',
 'impact': {'brand_reputation_impact': 'Severe',
            'data_compromised': '600GB+ of sensitive data, including 12.9M '
                                'Salesforce records, 182K+ contact entries, '
                                '8.3K+ employee records with PII, contracts, '
                                'NDAs, data center floor plans, electrical '
                                'diagrams, access-control records, physical '
                                'key inventories, badge audits, security '
                                'policies, environmental reliability '
                                'documentation, passwords, and credential '
                                'artifacts',
            'identity_theft_risk': 'High',
            'operational_impact': 'Potential physical intrusions, supply-chain '
                                  'disruptions, and targeted phishing attacks'},
 'investigation_status': 'Ongoing',
 'motivation': 'Financial gain',
 'ransomware': {'data_exfiltration': True, 'ransom_demanded': '$13 million'},
 'references': [{'date_accessed': '2026-08-24',
                 'source': 'Cyber Incident Description'}],
 'response': {'communication_strategy': 'No public response or engagement in '
                                        'negotiations as of August 24, 2026'},
 'threat_actor': 'ShinyHunters',
 'title': 'ShinyHunters Targets CyrusOne in $13M Ransomware Attack, Stealing '
          'Highly Sensitive Data',
 'type': 'Ransomware'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.