Download Privacy Needle App

Type to search

Data Breaches News

Hackers Demand $13M After Allegedly Stealing Data Center Floor Plans

Share
$13 Million Attack on CyrusOne

ShinyHunters Claims $13 Million Attack on CyrusOne That Could Expose Data Center Floor Plans and Security Files

  1. Hackers Demand $13 Million After Allegedly Stealing Data Center Floor Plans
  2. ShinyHunters Claims Massive CyrusOne Hack With Sensitive Data Center Secrets
  3. $13 Million Ransom Threat: Hackers Claim They Stole CyrusOne’s Data Center Files
  4. Hackers Claim They Stole 645GB of Data From Major US Data Center Operator
  5. CyrusOne Targeted by ShinyHunters in Alleged Attack on Sensitive Data Center Systems

A notorious hacking group is demanding $13 million from major US data center operator CyrusOne after allegedly stealing millions of records and highly sensitive information about the company’s facilities, including floor plans, electrical diagrams and access-control data.

The alleged attack has raised an unusual cybersecurity concern: hackers may not only have obtained corporate and employee information, but potentially data that could reveal how critical data centers are physically secured.

ShinyHunters, the cybercriminal group behind the claim, listed CyrusOne on its leak site and alleged that it had stolen 12.9 million Salesforce records as well as hundreds of gigabytes of information from the company’s SharePoint environment.

The group reportedly gave CyrusOne 24 hours to engage over a $13 million extortion demand.

However, there is an important caveat: CyrusOne had not publicly confirmed the alleged breach when the report was published, and ShinyHunters had not released samples proving its claims.

Hackers Claim to Have Stolen 645GB of Data

According to ShinyHunters, the alleged haul includes approximately 369.6GB of compressed SharePoint data, which Cybernews estimates could represent around 645GB when uncompressed.

The attackers also claim to have obtained more than 8,300 employee records containing personally identifiable information, alongside millions of Salesforce records.

But the most concerning part of the alleged breach may not be the amount of data.

It may be what the data reportedly contains.

The list includes contracts, nondisclosure agreements, security policies, access-control records, badge audits, physical key inventories, floor plans and electrical diagrams.

Why Data Center Floor Plans Could Be Dangerous

A normal corporate data breach can expose names, email addresses and other personal information.

A breach involving data center infrastructure can potentially create a different kind of threat.

Data centers are protected by layers of physical and digital security. Information showing the location of doors, cameras, restricted areas, electrical systems, security equipment and access points could potentially help an attacker understand how a facility operates.

Cybernews researchers warned that if the hackers’ claims prove accurate, the information could potentially be useful for physical intrusion, espionage or highly targeted social-engineering attacks.

That is what makes this alleged incident particularly unusual.

The attackers may have obtained information about the buildings themselves, not just the company operating them.

Employee Access Data Could Create Another Risk

The alleged stolen information reportedly includes badge audits and physical key inventories.

Such records could potentially reveal which employees have access to particular facilities or restricted areas.

In the wrong hands, that information could be used to construct highly convincing impersonation attempts.

An attacker who knows an employee’s name, role, access privileges and the physical security procedures at a facility could potentially make a social-engineering attempt appear far more legitimate.

The alleged presence of password lists and other credential-related information adds another layer of concern.

CyrusOne Has Not Confirmed the Breach

Despite the seriousness of the allegations, the incident should not yet be treated as a confirmed breach.

At the time of Cybernews’ reporting, CyrusOne had not publicly commented on the claims.

ShinyHunters had also not published data samples that could independently demonstrate that the claimed information had actually been stolen.

That distinction matters because ransomware and extortion groups sometimes publish claims before releasing evidence in an attempt to pressure victims into negotiations.

Independent breach trackers have similarly classified the CyrusOne incident as an unverified claim rather than a confirmed compromise.

The ShinyHunters Campaign Is Expanding

The CyrusOne claim comes as ShinyHunters continues to target major organizations through a combination of social engineering, stolen credentials and data extortion.

The group has recently been linked to other high-profile claims and incidents involving major companies.

In a separate case, cybersecurity company ReliaQuest confirmed that an employee had been targeted in a ShinyHunters-linked social-engineering campaign, although the company said the attackers did not gain unauthorized access to internal applications, customer environments or enterprise systems.

The activity highlights a broader shift in modern cybercrime.

Attackers do not always need to break through an organization’s most heavily protected servers.

Compromising an employee account, abusing cloud applications or obtaining access through social engineering can sometimes provide a pathway into valuable corporate information.

Why This Attack Could Be Different

If ShinyHunters’ CyrusOne claims are eventually verified, the incident could demonstrate how a data breach can move beyond traditional concerns about stolen customer information.

For a company operating critical data-center infrastructure, information about physical security, electrical systems, access controls and facility layouts could potentially have consequences far beyond privacy.

It could expose details about the physical environment supporting the digital services used by businesses around the world.

For now, however, the biggest question remains unanswered:

Did ShinyHunters actually steal the massive collection of CyrusOne data it claims to possess?

Until CyrusOne confirms the incident or credible evidence is released, the alleged 12.9 million records, 645GB of data and $13 million extortion demand should be treated as claims from the attackers rather than established facts.

But if the allegations prove true, this could become one of the more concerning data-center security incidents of the year.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.