The extortion crew tracked as ShinyHunters added US data center operator CyrusOne, LLC to its leak site on 23 August 2026, claiming to hold 12.9 million Salesforce records and roughly 645 GB of uncompressed SharePoint data, and demanding $13 million with a 24-hour deadline to engage. The claim is, at this stage, exactly that: a claim. CyrusOne has issued no public statement confirming or denying the intrusion, and both TechNadu and GalaxyWarden explicitly flag the breach as unverified. What raises the analytic floor here is not the leak-site post itself but the pattern around it: Microsoft's own threat research, published 13 July 2026, documents a sustained ShinyHunters-associated campaign against Salesforce tenants using vishing and OAuth abuse, and the same actor has run near-identical playbooks against Brinks Home, RingCentral, and Ernst & Young over the preceding six weeks.
What Happened
According to the leak-site listing reproduced by HookPhish and summarised by TechNadu, ShinyHunters initially posted CyrusOne without naming it, then updated the entry on 23 August with the victim identified. The stated reason for the unmasking is that the company is "refusing to pay a $13 million demand." The post gives a final deadline of end of day 24 August 2026 before publication, and threatens "several annoying (digital) problems" alongside the leak, language consistent with the group's habit of pairing data publication with follow-on harassment of customers and staff.
Timestamps across the aggregator sources are close but not identical. HookPhish records a breach date of 23 August 2026 11:10 UTC and a discovery timestamp of 23 August 2026 20:27 UTC, but these are almost certainly leak-site scraping artefacts rather than forensic dates. Neither figure should be read as the actual intrusion window. In the comparable Brinks Home case, BleepingComputer reported a 13 July intrusion identified on 20 July, a week-long gap invisible from the leak-site post alone. The realistic assumption for CyrusOne is that any access predates the listing by weeks or months.
Note also that the entity named in the listing is CyrusOne, LLC. The company's legacy SEC filings are under CyrusOne Inc., a Dallas-headquartered Maryland REIT formerly listed on NASDAQ under commission file number 001-35789, which went private following its 2022 acquisition. That corporate change matters for disclosure expectations: a private operator faces no Item 1.05 8-K materiality obligation, so the SEC-filing channel that would normally corroborate or refute a claim like this is not available. Absence of a filing is not evidence of absence of a breach.
What Was Taken
All quantities below are the attacker's own figures, self-reported on a leak site and unverified by CyrusOne or any independent party. Where sources describe the same claim differently, the variance is in rounding rather than substance: HookPhish and GalaxyWarden both cite 12.9 million Salesforce records, while TechNadu characterises the same figure as "almost 13 million." TechNadu's headline cites "640+ GB" against the listing's stated 645 GB uncompressed.
The claimed haul, per the listing:
- 12.9 million Salesforce records in aggregate, including more than 182,000 rows extracted from the Salesforce "Contacts" object.
- Over 8,300 rows of employee PII: full names, email addresses, job titles, and phone numbers.
- SharePoint: 369.6 GB compressed / approximately 645 GB uncompressed, spanning 288,729 files across 60,513 folders.
- Thousands of executed contracts, MSAs, NDAs, amendments, leases, and SOWs.
- Physical key inventory logs, verification photos, and contractor Green Badge audits.
- Data center drawings, floor plans, electrical one-line diagrams, security system drawings, and site schematics.
- The full CERM (Critical Environment Reliability Management) process library, physical and information security policy suites, and governance material.
- Regional security scorecards, KPI workbooks, GAM sheets, and signed performance packages.
- Credential and access-control artefacts, named in the listing as including
PasswordList.xlsx, Okta SSC access lists, active badge reports, and multiple Data Center Access Control forms.
GalaxyWarden's assessment, which we broadly share, is that the document set outweighs the record count in sensitivity. No permanent government identifiers, Social Security or passport numbers, appear anywhere in the listing. What does appear are contracts, NDAs, and physical access records: material that discloses business relationships, pricing, security procedures, and building access details, and that retains value for years. GalaxyWarden also notes the listing does not disclose how any credentials in that alleged password file were stored, so the hashing or encryption posture is simply unknown.
Why It Matters
A data center operator is a concentration point. CyrusOne's Salesforce estate is, by definition, a directory of who runs infrastructure in which of its facilities, and the SharePoint material claimed here is the operational layer beneath that: floor plans, one-line diagrams, security system drawings, badge audits, key inventories. If accurate, this is not a consumer PII incident. It is a physical-security intelligence package on multi-tenant facilities, and the affected parties are downstream tenants who never had a contractual relationship with the attacker's victim.
The second-order risk is the 182,000 contact rows. ShinyHunters' entire access model in this campaign family is social engineering against helpdesks and employees. A verified list of named contacts at organisations known to colocate with CyrusOne is precisely the raw material for the next round of vishing, and the group has demonstrated it will use exfiltrated contact data to pressure a victim's customers directly.
Third, the tempo is the story. The Register cites Dominic Alvieri describing ShinyHunters as his "top threat group and probably is for most analysts," and reports the crew has hit hundreds of organisations since the start of 2026, spanning education technology, healthcare, and communications. The RingCentral case is the instructive one for anyone weighing the $13 million demand: RingCentral disclosed on 28 July, apparently did not pay, and on 3 August the group dumped the data, with Have I Been Pwned subsequently confirming 1.6 million unique email addresses alongside names, physical addresses, and phone numbers. This group follows through on publication deadlines.
The Attack Technique
The CyrusOne listing does not state an initial access vector, and no source confirms one. What can be established is the technique set this actor has been using against exactly this class of target.
Microsoft's July 2026 research, the strongest-sourced document in this set, describes campaigns observed from mid-2025 through mid-2026 with tradecraft overlapping ShinyHunters, targeting customer Salesforce instances via two primary intrusion paths. The first is vishing aimed at obtaining OAuth consent from a targeted employee. The second is supply chain compromise through trusted workflows and integrations, with Salesloft and Gainsight named specifically. Both paths yield inherited user and application privileges, allowing enumeration and querying of CRM records while evading conventional authentication detections, because the resulting API access looks like a legitimate connected app rather than an anomalous login. Microsoft is unambiguous that this is not a Salesforce vulnerability: it is abuse of trusted OAuth relationships for access, exfiltration, and persistence.
The press record corroborates both branches. For Brinks Home, ShinyHunters told BleepingComputer it gained access on 13 July through a Microsoft Entra vishing attack, calling an employee and walking them through an Entra authentication or registration flow that handed over account access, then pulling more than 1.1 million rows from the Salesforce "Contacts" object and over 4,000 rows of employee PII. That structure, a large aggregate record count, a "Contacts" object extraction in the low millions or hundreds of thousands, and a few thousand employee PII rows, is the same shape as the CyrusOne claim, which is itself a reason to treat the listing as plausible. For RingCentral, a ShinyHunters spokesperson told The Register the group voice-phished an employee into surrendering a password. For Ernst & Young, the group told BleepingComputer it obtained credentials through a supply chain attack and used them to reach Jira, GitHub, and Azure environments, after EY disclosed that a third-party IT service management platform had been compromised between 28 March and 12 April and detected on 23 April.
One deliberate note on terminology: this is being reported as a "ransomware attack," and the leak-site aggregators categorise it that way. Nothing in any source indicates file encryption or operational disruption at CyrusOne. Every documented case in this set is theft-and-extortion against SaaS estates, with no encryption stage. Defenders should plan against exfiltration, not encryption.
What Organizations Should Do
- Audit every OAuth-connected application in your Salesforce and Microsoft 365 tenants now. Inventory connected apps, the scopes they hold, and who consented. Revoke anything unrecognised, unused, or over-scoped. Per Microsoft, this is the primary persistence mechanism in this campaign, and it survives password resets and MFA re-enrolment.
- Restrict end-user OAuth consent. Move to admin-approved consent workflows so a single vished employee cannot authorise an attacker-controlled application against your CRM.
- Enable Salesforce event monitoring and alert on bulk API and query volume. Microsoft worked with Salesforce to improve telemetry granularity in Defender for Cloud Apps, including near-real-time detection, connected-application attribution, and expanded permission insights. The detection signature for this actor is anomalous mass querying of CRM objects, not a suspicious login.
- Harden the helpdesk against Entra vishing specifically. Both the Brinks Home and RingCentral intrusions began with a phone call. Require out-of-band identity verification before any MFA reset, device registration, or authentication-flow assistance, and give staff explicit authority to refuse and escalate a call regardless of the caller's claimed seniority or urgency.
- Treat third-party integrations as an access path with its own review cycle. The Salesloft, Gainsight, and EY service-desk cases show the compromise entering through a trusted vendor. Enumerate which vendors hold tokens into your environment, scope those tokens to least privilege, and rotate them on a defined schedule.
- Get facility documentation out of general-purpose SharePoint. Floor plans, one-line diagrams, security system drawings, badge audits, key inventories, and access-control forms belong in a segmented, access-logged repository, not a broadly indexed collaboration site. Colocation customers should ask their provider directly what facility documentation is stored where, and never store credential material in spreadsheets.
Organisations with facilities in CyrusOne data centers should assume, pending any company statement, that their contact details and any shared facility documentation may be in the dataset, and should brief staff to expect targeted vishing referencing genuine contract, badge, or facility details.
Sources: Ransomware Group shinyhunters Hits: CyrusOne, LLC. | Defending SaaS-based applications against ShinyHunters OAuth abuse... | CyrusOne Inc. | ShinyHunters claims Brinks Home breach, threatens to leak stolen data | 1.6M RingCentral accounts' data dumped after ShinyHunters extortion... | Ernst & Young data breach claimed by ShinyHunters extortion gang | ShinyHunters Claims CyrusOne Breach, Demands $13 Million - TechNadu | CyrusOne, LLC. Listed by Shinyhunters Ransomware Group