ShinyHunters Targets ReliaQuest and Unmasks CyrusOne in New Leak Site Updates

ShinyHunters has unmasked CyrusOne in a major extortion claim while separately targeting ReliaQuest over its reporting on the group.
Screenshot of the ShinyHunters leak site showing CyrusOne and ReliaQuest listings, including a claimed $13 million demand tied to CyrusOne.
ShinyHunters has unmasked CyrusOne in a new extortion update while separately targeting ReliaQuest over its reporting on the group.

ShinyHunters has published 2 notable updates to its data leak site, targeting cybersecurity company ReliaQuest while also removing the redaction from a previously obscured victim listing and identifying it as data center operator CyrusOne.

The ReliaQuest post, updated Aug. 23, is unusual because it does not contain a ransom demand or explicitly claim that customer data was stolen. Instead, ShinyHunters directly criticized the security company for its reporting on the group and told it to stop covering the operation.

The listing comes after ReliaQuest spent months publishing research into ShinyHunters and the wider data-extortion ecosystem, including the group’s use of phishing infrastructure, phone-based social engineering and identity-focused attacks against cloud and SaaS environments.

ReliaQuest becomes the subject of the campaign it tracks

The ShinyHunters post appears more like a warning or retaliatory message than a conventional victim listing. The group references Mandiant in the message and tells ReliaQuest to allow the Google-owned security company to report on its activity instead.

ShinyHunters did not publish a deadline, stolen-data inventory, ransom amount or technical evidence demonstrating access to ReliaQuest systems in the Aug. 23 post.

ReliaQuest has repeatedly analyzed ShinyHunters and related extortion activity. Its research has documented the group’s use of branded subdomain impersonation, phone-guided adversary-in-the-middle phishing and identity attacks designed to gain access to SaaS platforms without deploying traditional malware.

ReliaQuest has also tracked phishing infrastructure associated with the operation and documented how compromised identities can provide access to platforms including Salesforce and SharePoint, where attackers can use legitimate functionality to exfiltrate data.

The timing also follows public friction between the threat actor and ReliaQuest’s researchers. An account purporting to represent the group reportedly taunted ReliaQuest Threat Research following recent reporting on ShinyHunters infrastructure. Those exchanges may provide context for the wording of the Aug. 23 listing, but they do not substantiate a breach of ReliaQuest.

At time of publication, no data samples, file listings or other evidence publicly accompanying the listing established that ReliaQuest itself had been compromised. ReliaQuest had not issued any public statement confirming a breach at time of publication.

CyrusOne named after earlier redacted listing

Separately, ShinyHunters has removed the redaction from a listing first published on Aug. 20 and identified the alleged victim as CyrusOne, LLC.

CyrusOne is a global data center owner, developer and operator headquartered in Dallas. The company says it operates more than 60 data centers across 9 countries, giving the latest allegations additional significance because of the potentially sensitive nature of infrastructure and security information held by a data center operator.

The Aug. 23 update substantially expands the group’s claims. ShinyHunters alleges it holds approximately 12.9 million Salesforce records and hundreds of gigabytes of SharePoint data belonging to CyrusOne.

The group further claims the material includes more than 182,000 customer contact records, more than 8,300 employee records, contracts, leases, statements of work, security governance material, access-control documentation, physical key inventory information and data center design documentation.

ShinyHunters also claims to possess floor plans, electrical diagrams, site schematics and other materials relating to CyrusOne’s physical infrastructure. BreachNews is not reproducing filenames, access-control artifacts or other potentially sensitive operational details from the listing.

ShinyHunters claims $13 million demand

ShinyHunters says CyrusOne refused to pay what the group describes as a negotiable $13 million extortion demand.

The group gave CyrusOne until the end of Aug. 24 to engage before it claims it will publish the allegedly stolen information and cause additional unspecified “digital problems.”

The deadline is consistent with ShinyHunters’ recent pressure campaign. BreachNews previously reported that the group issued similar final-warning notices to Logitech and Streamlabs, threatening publication if the organizations did not make contact.

CyrusOne had not issued any public statement addressing the ShinyHunters claims at time of publication. BreachNews has not independently verified the claimed data volumes or established whether the listed material was obtained from CyrusOne systems.

Physical infrastructure claims raise the stakes

The CyrusOne listing stands out because the alleged data extends beyond conventional Salesforce and employee information into documentation related to data center operations and physical security.

If authentic, architectural drawings, access-control records and security documentation could present risks beyond those associated with ordinary customer records because they could reveal details about the design, operation or security of physical facilities. However, ShinyHunters has not provided enough public evidence to independently establish the authenticity or completeness of the claimed materials.

The group has also not explained how it allegedly gained access to CyrusOne’s Salesforce and SharePoint environments.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site