The ShinyHunters ransomware group has launched an aggressive extortion campaign against major US companies, listing data center giant CyrusOne and regional bank BOK Financial on its leak site within hours of each other.
The group demanded $13 million from CyrusOne, a provider of data-center and colocation infrastructure services for enterprise clients. ShinyHunters claimed to hold 12.9 million Salesforce records, 645 gigabytes of uncompressed SharePoint files comprising nearly 290,000 documents, 182,000 rows of customer data, and 8,300 employee records including names, emails, and phone numbers. The group said CyrusOne refused to pay and gave the company 24 hours to engage.
BOK Financial faces deadline today
On August 22, the same group listed BOK Financial, a Tulsa-based bank with $49 billion in assets, issuing what it called a final warning. The message read: This is a final warning to reach out by end of day 24 Aug 2026 before we leak along with several annoying digital problems that will come your way. Security researchers linked the BOK Financial intrusion to CVE-2026-35273, a critical vulnerability in Oracle PeopleSoft rated 9.8 out of 10 on the CVSS scale, which allows unauthenticated attackers to compromise systems over HTTP.
The timeline means the deadline expires today, August 24, putting BOK Financial under immediate pressure to respond publicly or risk a data dump.
Cybersecurity firm and healthcare also targeted
ShinyHunters also listed ReliaQuest, a major cybersecurity company that provides detection and response services to enterprise customers, on August 23. The firm has not confirmed the claim. NovoCure, a medical device company listed on NASDAQ, was added on August 22. Neither company has publicly verified the allegations.
The pattern across these four victims – a data center provider, a bank, a cybersecurity firm, and a medical device company – suggests ShinyHunters is casting a wide net across high-value sectors rather than focusing on a single industry.
| Company | Sector | Listed | Key Claim |
|---|---|---|---|
| CyrusOne | Data Centers | Aug 23 | $13M ransom, 12.9M Salesforce records |
| BOK Financial | Banking | Aug 22 | Deadline Aug 24, PeopleSoft exploit |
| ReliaQuest | Cybersecurity | Aug 23 | Details undisclosed |
| NovoCure | Healthcare | Aug 22 | Details undisclosed |
ShinyHunters has been linked to major breaches including Ticketmaster via Snowflake and PowerSchool. French authorities arrested four members in August 2025, but the group continues to operate, with 145 victims tracked on ransomware.live. Security experts note the group has recently shifted toward targeting organizations with large Salesforce deployments, exploiting the concentration of customer and employee data in CRM platforms.
None of the targeted companies have publicly confirmed any breach. Experts warn that a leak-site listing is an extortion tactic, not proof of compromise, but advise organizations to review access controls, vendor-risk procedures, and incident-response plans in light of the accelerating campaign.
discussion