AI News Feed
Market watch
Cybersecurity

ShinyHunters claims breach of data center operator CyrusOne as ransomware hits record high in July

ShinyHunters claimed it breached CyrusOne, a US data center operator serving Microsoft and Meta, demanding $13 million, as research shows ransomware activity hit a 2026 high in July.

According to TechRadar, ShinyHunters said it exfiltrated 12.9 million Salesforce records, more than 600 GB of SharePoint data, over 8,300 employee records with personally identifiable information, contracts, non-disclosure agreements, data center floor plans, electrical diagrams, access-control records, badge audits, physical key inventories, security policies and credentials. The group first posted a redacted victim on its leak site on August 20 with a "Final warning - pay or leak" message, then named CyrusOne publicly on August 23. The company was given until August 24 to engage, but it has not commented or paid, and no stolen data has been released so far, TechRadar reported. Researchers described the lack of sample postings as a pressure tactic rather than a sign of a hoax.

Experts warned that building floor plans and physical security data can be used for physical intrusions, since "you can't patch a building." Information about CyrusOne's customers, including pricing, service agreements and contact details, could be leveraged for highly targeted phishing and third-party supply-chain attacks. CyrusOne operates around 50 data centers across the US, serving clients including Microsoft, Meta, Verizon, AT&T, IBM and CME Group.

Separately, NCC Group's July threat report, reported by ZDNet, recorded 894 victim organizations listed on ransomware leak sites in July, a 22% month-over-month increase and the highest level this year. The industrial sector accounted for nearly a third of attacks, followed by consumer services, technology, critical services, finance and healthcare. The US was the most targeted region with 41% of incidents, followed by Europe at 29%, Asia at 14% and South America at 9%.

NCC Group attributed most attacks to ten major cybercriminal groups, but cautioned that high numbers may not always reflect real successful extortion. The report highlighted CRPxO, a new ransomware-as-a-service group that claimed 36 victims shortly after its emergence in July, including Johnson & Johnson and Turkish Airlines, with no confirmation. NCC Group assessed CRPxO's credibility as "low to moderate," since it had not released datasets and the quality of evidence was inconsistent.

July also saw the first documented fully agentic AI-driven ransomware attack chain, believed to be carried out by a group called JadePuffer, according to ZDNet. NCC Group's report said new groups may inflate numbers to build reputation, and the long-term success of such groups will depend on showing credible victim compromises and maintaining trust among affiliates.