CyrusOne, LLC. Listed by Shinyhunters Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.
CyrusOne, LLC. has been listed by the Shinyhunters ransomware group, with the disclosure reported on August 23, 2026. An undisclosed number of individuals had personal data exposed; anyone who may have been affected should verify their status and take protective steps.
A ransomware group known as Shinyhunters has listed CyrusOne, LLC. on its leak site and claims to hold a large volume of internal and customer-related material. As of writing, CyrusOne has not publicly confirmed the claim. For people who work with, or whose employers rely on, data-center and colocation providers, the practical question is conditional: if the group’s claims were accurate, what kinds of information might be involved and what steps are worth taking either way.
Public detail is limited to the group’s own listing language. No independent confirmation of theft, scale, or contents has been established in the material available for this article. That distinction matters. A leak-site post is an extortion tactic, not a verified inventory.
Inside the listing
According to the listing attributed to Shinyhunters, the group named CyrusOne, LLC. and, in an update dated 23 August 2026, stated that it was removing the client’s name from the post while asserting that the company was refusing to pay a demand the group put at $13 million. The same update claimed the organisation had 24 hours left to engage. The listing further claims the group holds 12.9 million Salesforce records, together with SharePoint material described as about 369.6 GB compressed and 645 GB uncompressed, comprising 288,729 files and 60,513 folders. It also claims more than 182,000 rows of customer data extracted from a Salesforce “Contacts” object, over 8,300 rows of employee personal information (described as including full name, email, job title, phone number, and similar fields), thousands of executed contracts, MSAs, NDAs, amendments, leases, and statements of work, and extensive physical key inventory logs and verification photographs.
The number of people affected is unknown. Method of access, initial intrusion path, and whether any files were actually published beyond the listing’s marketing language are not established in the available facts. The company has not publicly confirmed the claim as of writing. Everything above is the group’s claim, not a verified breach report.
Who is Shinyhunters?
Shinyhunters is a name that has appeared for years in public reporting on data theft and extortion. Groups using that banner have typically been associated with stealing large datasets—often from cloud applications, customer databases, or compromised credentials—and then threatening to publish or sell the material if a payment is not made. In more recent cycles, actors under this and related labels have also been linked in open reporting to leak-site pressure campaigns and to claims involving CRM and collaboration platforms.
Their public playbook, as described across industry and law-enforcement reporting over time, often includes posting a victim’s name, asserting a volume of records or file stores, setting payment deadlines, and using countdown-style language to increase pressure. None of that pattern, by itself, proves that any particular claim about CyrusOne is true. For this incident, the only specifics on record here are those in the group’s listing; no separate confirmation is included in the facts provided.
About CyrusOne, LLC.
CyrusOne, LLC. is known publicly as a provider of data-center and related infrastructure services—facilities and operations that host computing, networking, and storage for enterprise and other customers. Organisations in this sector sit in a sensitive position in the supply chain: they may hold commercial contracts, facility access records, employee directories, and customer contact or account information needed to run colocation, interconnection, and support relationships.
A credible compromise at a data-center operator would matter not only to staff but also to business customers who depend on those sites for uptime and confidentiality. That consequence is why leak-site claims against such firms draw attention. It does not, however, establish that this particular listing is accurate. A listing shows that a group chose to name a company and to describe supposed holdings; it does not by itself prove intrusion, exfiltration, or the completeness of any claimed dataset.
What data was at risk
The structured record does not independently verify exposed data types; the detail comes from the attackers’ description. Shinyhunters claims Salesforce records at very large scale, SharePoint file stores measured in hundreds of gigabytes, customer contact rows, employee PII fields, large volumes of commercial legal documents, and physical key inventory material with verification photos. Those categories are claims on a leak site, not a confirmed inventory.
If files of the kinds the group describes were taken from an organisation in this sector, firms typically hold employee identity and contact data, customer and prospect contact records in CRM systems, contracts and operational documents, and sometimes physical-security related logs. Whether any of that was actually copied from CyrusOne remains unconfirmed. Exact contents, completeness, and whether anything has been released beyond the listing language are undisclosed in verified public terms.
What's at stake
For individuals, the conditional risks track the categories the group names. If employee rows matching the listing’s description were real, staff could face phishing, social engineering, or account-takeover attempts that misuse name, title, email, and phone details. If customer contact data from a CRM were real, business contacts could see targeted fraud or spoofed outreach that appears to come from a familiar vendor relationship. If contracts, MSAs, NDAs, leases, and similar documents were real, commercial counterparties could face competitive or negotiation harm from exposure of terms. Physical key inventory claims, if accurate, would raise facility-access concerns for anyone responsible for site security—again, only if the material exists as claimed.
For the organisation, an extortion listing creates reputational and customer-trust pressure regardless of eventual proof. The group’s stated dollar demand and deadline language are part of that pressure campaign. None of this should be read as a finding that data left CyrusOne’s control; it is an account of what the claimants say and of the ordinary harms that follow when such claims turn out to be true in other cases.
Steps worth taking either way
Treat the situation as unconfirmed and act on prudence, not panic. If you are a current or former employee or a business contact who might appear in CRM or contract systems, watch for unexpected messages that cite internal project names, contract details, or facility access—and verify through known official channels rather than links or numbers in an unsolicited note. Prefer unique passwords and multi-factor authentication on email and work accounts. If you receive a notice from CyrusOne or from a regulator later, follow those instructions; until then, do not assume your data is in this claimed set.
Organisations that depend on CyrusOne for hosting or related services should use their normal vendor-risk channels to ask what, if anything, the company is prepared to say, and should review their own access, logging, and contract-notification clauses without treating a leak-site post as proof. Individuals who want a simple check on whether their email address has appeared in other known breach corpora can run a free exposure scan of their email; that kind of check does not confirm or deny this specific listing, but it can highlight credentials that deserve a password change and closer monitoring.
In short: Shinyhunters has listed CyrusOne, LLC. and made detailed claims about Salesforce, SharePoint, employee and customer rows, contracts, and key logs, including a stated multi-million-dollar demand. CyrusOne has not publicly confirmed the claim as of writing. Until independent confirmation exists, the responsible stance is conditional vigilance—not a conclusion that any particular person’s data has been stolen.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
ReliaQuest, LLC Listed by Shinyhunters Ransomware GroupNovoCure Limited Listed by Shinyhunters Ransomware GroupBOK Financial Listed by Shinyhunters Ransomware GroupCyrus****** Listed by Shinyhunters Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the CyrusOne, LLC. Listed by Shinyhunters Ransomware Group →
Publicly posted by shinyhunters — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.