Microsoft’s and Meta’s data center may have been breached in $13 million extortion attempt
Floor plans, electrical diagrams and security policies may have been exposed.

Image by Cybernews
A major US data center operator, CyrusOne, is facing an alleged $13 million extortion demand from notorious cybercrime group ShinyHunters.
The claims appeared on the dark net, on a leak site belonging to Shinyhunters. “They are refusing to pay a $13 million demand. They have 24 hours left to engage with us. We hold 12.9 million Salesforce records,” attackers wrote desperately, putting pressure on the company.
According to the attackers, the stolen data includes contracts, security documentation, data center floor plans, electrical diagrams, access-control records, badge audits, physical key inventories, password lists, and other credential artifacts.
CyrusOne had not publicly commented on the claims at the time of publication. Also, at the moment, attackers have not published any data samples to back up their claims. This may be part of the extortion strategy, when data samples are released gradually to create pressure for the victim.
What the hackers claim to have taken
According to claims of ShinyHunters, the allegedly breached data include:
- 12.9 million Salesforce records
- More than 182,000 rows from the Salesforce Contacts object
- Approximately 369.6GB of compressed SharePoint data, estimated at around 645GB uncompressed
- More than 8,300 employee records containing personally identifiable information
- Executed contracts, master service agreements, non-disclosure agreements, and service agreements
- Data center floor plans and electrical diagrams
- Access-control records and badge audits
- Physical key inventories
- Security policies
- Critical Environment Reliability Management documentation
- Password lists and other credential artifacts
If accurate, the alleged breach would contain information that could be useful not only for conventional data theft, but also for attacks against physical facilities. That is what makes the claim particularly concerning.
You can patch a server, but you cannot patch a building
Cybernews researchers warn that if the claims prove to be legitimate, it may put the data centers in danger.
Data center security is not purely digital, and attackers with information about the facility's physical layout, access-control systems, electrical architecture, and surveillance arrangements could use it to break in or conduct an espionage attack.
“Floor plans, electrical diagrams, and security policies show where the cages, mantraps, cameras, and doors are, and how guards operate,” the research team said.
Badge audits and physical key inventories could also identify which employees have access to particular areas, potentially giving attackers a roadmap for highly targeted social engineering, impersonation, or coercion.
Unlike a compromised password, a physical security system cannot simply be reset overnight. “Passwords rotate in hours, re-keying facilities and redesigning access zones across dozens of sites takes months and real money,” the researchers said.
“You can’t patch a building. Passwords rotate in hours, re-keying facilities and redesigning access zones across dozens of sites takes months and real money. Tenants are exposed but were not breached,” the researchers added.
Cybernews journalists reached out to CyrusOne for a comment. We will update article once the response is received.
Customers may be impacted as well.
The alleged theft of contracts and facility documentation introduces another layer of risk.
Data centers host infrastructure belonging to other companies. Information about where particular customers are located, what services they receive, their contractual arrangements, pricing, service-level agreements, and account contacts can collectively reveal much more than a conventional customer database.
According to Cybernews researchers, the alleged facility documentation could effectively turn CyrusOne's own infrastructure map into a map of its customers.
“Contracts, MSAs, and NDAs identify the tenants as a customer list overlaid on a building map, with pricing and SLAs attached,” the researchers said.
That information could make highly convincing impersonation attempts easier.
An attacker who knows a customer's account manager, contract terms, facility location, rack location, or other operational details could potentially craft requests that look indistinguishable from legitimate business communications.
The result could be a new wave of targeted phishing, business email compromise, social engineering, or attempts to manipulate employees with knowledge that should never have been available to outsiders.
Cooling and power systems may be comprised
The alleged data also reportedly includes documentation related to CyrusOne's power, cooling, and critical-environment reliability processes.
For a data center operator, those systems are the machinery behind availability.
Power distribution and cooling architectures determine how facilities respond to failures, maintenance events, and emergencies. Detailed documentation could therefore reveal potential single points of failure or dependencies that attackers could attempt to exploit.
Cybernews researchers described the alleged reliability documentation as potentially providing “a guide to causing an outage.”
That does not mean an attacker could automatically shut down a data center using the documents. It does mean that, if authentic and sufficiently detailed, the information could help an attacker understand how a facility works and where disruption might have the greatest effect.
The stakes are particularly high because data centers underpin services used by industries including finance, healthcare, government, and other critical sectors.
Employees may be at risk
Potentially exposed password lists and credentials are the most immediate danger. Password reuse or poorly rotated credentials could provide attackers with opportunities to move between systems.
And where CyrusOne personnel interact with customer environments, compromised accounts could potentially become stepping stones toward attacks involving tenants.
Also, detailed information about the operator's infrastructure could make future attacks against tenants more convincing and more difficult to distinguish from legitimate requests.
The alleged dataset also contains more than 8,300 employee records with personally identifiable information. If authentic, that would create a second wave of risk for CyrusOne personnel.
Employee information can be used for identity theft, phishing, impersonation, fraud, and highly targeted social engineering.
Attackers are really trying: from “final warning” to a $13 million demand
ShinyHunters first listed the victim on its leak site on August 20th, initially keeping the company's name redacted while labeling the entry “FINAL WARNING PAY OR LEAK.”
The accompanying message gave the unnamed victim until the end of August 24th to make contact, warning that otherwise the attackers would publish the stolen data.
On August 23rd, the listing was updated and identified the company as CyrusOne, LLC. The updated post included the alleged $13 million ransom demand. This post gave the company a 24-hour negotiation window, and a detailed inventory of the data the attackers claimed to possess.
So far, no data samples. Maybe they are coming soon as Shinyhunters last resort?
A potential hit to a key player in data center industry
CyrusOne operates data centers across the US and internationally and is backed by investment firms KKR and Global Infrastructure Partners.
The company operates roughly 50 facilities, making any credible compromise potentially significant well beyond the company's own corporate network.
CyrusOne has said it serves hundreds of customers, including 185 Fortune 1000 companies, giving the data center operator a vast enterprise footprint.
Its reported customer base has included some of the world’s biggest technology, telecommunications, and financial companies, such as Microsoft, Meta, Verizon, AT&T, IBM, and CME Group.