CyrusOne LLC Data Breach

Alleged

Ransomware claim involving CyrusOne LLC.

Published: Aug 23, 2026 ShinyHunters
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
CyrusOne LLC
Industry
Data Center
Threat Actor
ShinyHunters
Date of Incident
Aug 23, 2026

Executive Summary

CyrusOne, LLC., a technology company based in the United States, was listed as a victim on the ShinyHunters extortion group’s platform on August 23, 2026. The company operates in the data center and technology infrastructure sector within the US market. CyrusOne’s listing by ShinyHunters adds a high-profile technology infrastructure name to the group’s recent US-focused extortion activity. Over the past 60 days, ShinyHunters has claimed approximately 20 victims, with Technology, Healthcare, and Professional Services as its top targeted industries. The United States, Israel, and Switzerland are the most frequently affected countries. Other US technology companies listed by ShinyHunters in the current period include ReliaQuest, LLC, while BOK Financial represents another high-profile US-based target in a different sector. CyrusOne’s technology infrastructure profile reflects ShinyHunters’ demonstrated interest in data-rich US technology organizations during this campaign window.

Technical Analysis

Initial-access correlation against SOCRadar’s stealer-log telemetry returned no records for cyrusone.com in the queried slice. ShinyHunters operates primarily as a data extortion group rather than a ransomware operator, and the technical access mechanisms favored by this actor class — including direct database exposure, API exploitation, and third-party breach pivots — differ from the infostealer-driven initial-access patterns typical of ransomware groups. A null stealer-log result for this domain does not meaningfully constrain the likely access pathway for a ShinyHunters listing.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.