Ask Runable forDesign-Driven General AI AgentTry Runable For Free
Runable
Back to Blog
Technology6 min read

ShinyHunters hackers claim to have hit data center provider used by Microsoft and Meta | TechRadar

The hackers are asking for $13 million Discover insights about shinyhunters hackers claim to have hit data center provider used by microsoft and meta | techrada

TechnologyInnovationBest PracticesGuideTutorial
ShinyHunters hackers claim to have hit data center provider used by Microsoft and Meta | TechRadar
Listen to Article
0:00
0:00
0:00

Shiny Hunters hackers claim to have hit data center provider used by Microsoft and Meta | Tech Radar

Overview

News, deals, reviews, guides and more on the newest computing gadgets

Start exploring exclusive deals, expert advice and more

Details

Unlock and manage exclusive Techradar member rewards.

Unlock instant access to exclusive member features.

Get full access to premium articles, exclusive features and a growing list of member rewards.

Shiny Hunters hackers claim to have hit data center provider used by Microsoft and Meta

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

Shiny Hunters adds Cyrus One to its victim list, demanding $13m ransom

Claimed theft includes 12.9 million Salesforce records, 600GB Share Point data, PII, contracts, and facility diagrams

Breach could enable physical intrusions and supply‑chain attacks; Cyrus One has not commented or paid

The infamous Shiny Hunters ransomware crew has added Cyrus One, a major US data center operator, to its list of victims, claiming to have stolen a treasure trove of highly sensitive data which, if proven true, could turn this into a bonafide catastrophe for the company and its customers.

Overall, Shiny Hunters claims to have exfiltrated 12.9 million Salesforce records, more than 182,000 rows from the Salesforce Contacts object, more than 600 GB of Share Point data, more than 8,300 employee records containing personally identifiable information (PII), executed contracts, master service agreements, NDAs, and service agreements, data center floor plans, electrical diagrams, access-control records and badge audits, physical key inventories, security policies, critical Environment Reliability Management documentation, and various passwords and credential artifacts.

No samples have been posted just yet, but researchers don’t see it as suspicious, but rather as a pressure tactic.

In exchange for deleting all of the stolen data, Shiny Hunters is demanding $13 million from Cyrus One which, at this time, is not commenting on the claims, and is seemingly not interested in negotiations.

“They are refusing to pay a $13 million demand. They have 24 hours left to engage with us. We hold 12.9 million Salesforce records,” the attackers allegedly wrote.

Organized criminals are increasingly targeting data center cargo

Hackers target data center equipment, including critical power devices

Millions of stolen records allegedly dumped online by mystery "Hatman" hacker — Mc Donalds, Vodafone and more see Microsoft Azure records stolen

Ransomware groups steal sensitive corporate data all the time, but this incident has the potential to be among the most devastating data breaches ever. Some of the secrets that were nabbed cannot simply be changed: data center floor plans, electrical diagrams, access-control records, badge audits, physical key inventories, this kind of intelligence can be used for physical breaches.

If criminals know how keys are assigned, how the data center is organized, where surveillance cameras are located, and how guards operate, it makes it easier to physically break it.

“You can’t patch a building,” the researchers warned, noting that some of the things that can be changed, such as physical keys and access zones, still take months and “real money”, they added, hinting at just how big the problem could be.

Cyrus One runs some 50 facilities all across the United States and serves hundreds of companies and corporations. Some of its clients include Fortune 1000 companies, as well as big tech names such as Microsoft, Meta, Verizon, AT&T, IBM, and CME Group.

Compounding the problem even further is the fact that Shiny Hunters stole information about Cyrus One’s customers, such as Meta, or Microsoft. Information about the locations of certain customers, the services they’re paying for, the NDAs, service-level agreements, and contact information, can all be used for highly tailored, sophisticated phishing attacks that could turn this incident into an unprecedented third-party supply-chain attack.

2.6 million Denta Quest accounts exposed by data breach – Shiny Hunters claim 234GB of data stolen

NAIC confirms data breach with Shiny Hunters claiming 3.1TB of data stolen in Oracle zero-day attack

Microsoft introduces security upgrades to tackle Shiny Hunters

“Contracts, MSAs, and NDAs identify the tenants as a customer list overlaid on a building map, with pricing and SLAs attached,” the researchers added.

To add insult to injury, Shiny Hunters also seems to have stolen information about the company’s power, cooling, and critical-environment reliability processes, which they could leverage to physically attack the servers, causing disruptions, outages, and possibly fires.

The group first added Cyrus One to their site on August 20 2026, although at that moment, the name of the victim was redacted, the researchers said. Instead, Shiny Hunters posted a warning, saying “Final warning - pay or leak”. The company was given until August 24 to reach out which, it would seem, did not happen.

Three days later, on August 23, Shiny Hunters publicly named Cyrus One as their victim, and stated that they demanded $13 million for the files. We are now well past the deadline, and nothing’s changed - the victim hasn’t spoken out, and Shiny Hunters did not leak the files.

➡️ Read our full guide to the best antivirus

  1. Best overall: Bitdefender Total Security
  2. Best for families: Norton 360 with Life Lock
  3. Best for mobile: Mc Afee Mobile Security

Follow Tech Radar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, Io T, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

FDA approves world-first CGM wearable in diabetes 'breakthrough'

Google just fixed one of the most annoying things about talking to AI

Nvidia's Ge Force Now is coming to the Steam Machine later in 2026

Meta thought AI could do the job instead of humans — what happened next should surprise absolutely nobody

Surfshark adds category-based web filtering to its post-quantum Dausos protocol

Tech Radar is part of Future US Inc, an international media group and leading digital publisher. Visit our corporate site.

© Future US, Inc. Full 7th Floor, 130 West 42nd Street, New York, NY 10036.

Key Takeaways

  • News, deals, reviews, guides and more on the newest computing gadgets
  • Start exploring exclusive deals, expert advice and more
  • Unlock and manage exclusive Techradar member rewards
  • Unlock instant access to exclusive member features
  • Get full access to premium articles, exclusive features and a growing list of member rewards

Cut Costs with Runable

Cost savings are based on average monthly price per user for each app.

Which apps do you use?

Apps to replace

ChatGPTChatGPT
$20 / month
LovableLovable
$25 / month
Gamma AIGamma AI
$25 / month
HiggsFieldHiggsField
$49 / month
Leonardo AILeonardo AI
$12 / month
TOTAL$131 / month

Runable price = $9 / month

Saves $122 / month

Runable can save upto $1464 per year compared to the non-enterprise price of your apps.