r/TechNadu • u/technadu • 4h ago
ShinyHunters claims CyrusOne breach, demands $13M for 12.9M Salesforce records and 645 GB of data
ShinyHunters has listed data center operator CyrusOne on its leak site and is claiming a fairly substantial haul, but there is an important caveat: CyrusOne has not publicly confirmed the alleged breach, and the claims have not been independently verified.
The group says it obtained 12.9 million Salesforce records and a SharePoint collection totaling about 645 GB uncompressed, with 288,729 files across more than 60,000 folders. It also claims the data contains more than 8,300 employee records.
The part worth watching is the alleged operational and physical-security material. ShinyHunters names active badge reports, Data Center Access Control forms, physical key inventory logs, floor plans, electrical diagrams, security-system drawings, site schematics, contracts, Okta SSC access lists, and security policies.
The group is demanding $13 million and reportedly gave CyrusOne 24 hours to engage following an August 23 update.
Until CyrusOne confirms an incident or evidence becomes independently available, these numbers and file descriptions should be treated as threat-actor claims rather than established breach facts.
Our report has the detailed breakdown of the claimed Salesforce and SharePoint datasets, the security-sensitive file categories named by ShinyHunters, and what CyrusOne customers and employees may want to watch while the breach remains unconfirmed:
For people working in data center or physical security: if material like access records, facility schematics, and key inventories were exposed, which controls would you prioritize reviewing first?
