Potential Customer Impact

Data Center Operator CyrusOne Hit by $13 Million Extortion Demand

CyrusOne, CyrusOne breach, ShinyHunters, data center hack, ShinyHunters CyrusOne data breach, hackers demand $13 million from CyrusOne, CyrusOne data center cyberattack
Facebook
X
LinkedIn
Reddit
WhatsApp
Source: JHVEPhoto/Shutterstock.com

The extortion group ShinyHunters claims to have breached U.S. data center operator CyrusOne and is demanding $13 million.

The group says it will otherwise publish the data it allegedly stole. CyrusOne has not yet commented publicly on the claims, and no data samples have been released so far to substantiate them.

Ad

ShinyHunters first listed its alleged victim on its leak site on August 20, initially without naming the company and labeling the post as a “final warning.” On August 23, the attackers updated the entry, identified CyrusOne for the first time and issued a 24-hour ultimatum along with the specific demand for $13 million.

According to the group, the allegedly stolen dataset includes 12.9 million Salesforce records, more than 182,000 entries from the Salesforce Contact object, approximately 369.6 GB of compressed SharePoint data and more than 8,300 employee records containing personally identifiable information. The attackers also claim to possess completed contracts and non-disclosure agreements, data center floor plans and electrical diagrams, access control logs, ID verification records, physical key inventories, security policies and documentation related to critical infrastructure reliability management.

A Physical Attack Surface, Not Just a Digital One

Security researchers at Cybernews warn that a breach involving this type of information could put more than data processing at risk. It could also affect the physical security of data centers.

Ad

Floor plans, electrical diagrams and security policies could reveal the locations of cages, mantraps, cameras and doors, as well as details of how security personnel operate, according to the research team. Unlike a compromised password, physical security infrastructure cannot simply be reset overnight. While passwords can be changed within hours, rekeying systems and redesigning access zones across multiple sites can take months and require significant investment.

The alleged incident could also have consequences for CyrusOne customers. Contract documents, pricing information and contact details could provide detailed insights into individual tenants of the data center operator, potentially making targeted fraud and impersonation attempts easier. Documentation related to power and cooling systems could also expose potential vulnerabilities or dependencies.

Major Operator With a High Profile Customer Base

According to its own information, CyrusOne operates around 50 data centers across the United States and internationally. The company is backed by investment firms KKR and Global Infrastructure Partners and says it serves hundreds of customers, including 185 companies on the Fortune 1000 list.

Reported customers include Microsoft, Meta, Verizon, AT&T, IBM and CME Group.

(Editorial Team)

Ad

Artikel zu diesem Thema

Weitere Artikel