Mastodon Skip to content
pulseofnations. Real News. Global Impact.
live markets
S&P 5007,652.86▲ 3.25%NASDAQ25,980.19▲ 4.02%DOW53,417.16▲ 2.83%GOLD4,710.00▲ 15.79%WTI84.98▼ 4.85%BRENT91.99▼ 4.95%EUR/USD1.1669▲ 2.57%USD/JPY159.05▼ 2.92%DXY98.99▼ 2.45%BTC$78,857▲ 1.48%ETH$2,480▲ 0.70%SOL$97.43▲ 2.31%TOTAL CRYPTO$2.67T▼ 0.82%

ShinyHunters Hits CyrusOne, BOK Financial in Ransomware Blitz

Ransomware group demands 3M from major US data center provider and issues final deadline for Oklahoma bank as wave of extortion claims escalates

Partner Surfshark VPN

The ShinyHunters ransomware group has launched an aggressive extortion campaign against major US companies, listing data center giant CyrusOne and regional bank BOK Financial on its leak site within hours of each other.

The group demanded $13 million from CyrusOne, a provider of data-center and colocation infrastructure services for enterprise clients. ShinyHunters claimed to hold 12.9 million Salesforce records, 645 gigabytes of uncompressed SharePoint files comprising nearly 290,000 documents, 182,000 rows of customer data, and 8,300 employee records including names, emails, and phone numbers. The group said CyrusOne refused to pay and gave the company 24 hours to engage.

BOK Financial faces deadline today

On August 22, the same group listed BOK Financial, a Tulsa-based bank with $49 billion in assets, issuing what it called a final warning. The message read: This is a final warning to reach out by end of day 24 Aug 2026 before we leak along with several annoying digital problems that will come your way. Security researchers linked the BOK Financial intrusion to CVE-2026-35273, a critical vulnerability in Oracle PeopleSoft rated 9.8 out of 10 on the CVSS scale, which allows unauthenticated attackers to compromise systems over HTTP.

The timeline means the deadline expires today, August 24, putting BOK Financial under immediate pressure to respond publicly or risk a data dump.

Cybersecurity firm and healthcare also targeted

ShinyHunters also listed ReliaQuest, a major cybersecurity company that provides detection and response services to enterprise customers, on August 23. The firm has not confirmed the claim. NovoCure, a medical device company listed on NASDAQ, was added on August 22. Neither company has publicly verified the allegations.

The pattern across these four victims – a data center provider, a bank, a cybersecurity firm, and a medical device company – suggests ShinyHunters is casting a wide net across high-value sectors rather than focusing on a single industry.

Company Sector Listed Key Claim
CyrusOne Data Centers Aug 23 $13M ransom, 12.9M Salesforce records
BOK Financial Banking Aug 22 Deadline Aug 24, PeopleSoft exploit
ReliaQuest Cybersecurity Aug 23 Details undisclosed
NovoCure Healthcare Aug 22 Details undisclosed

ShinyHunters has been linked to major breaches including Ticketmaster via Snowflake and PowerSchool. French authorities arrested four members in August 2025, but the group continues to operate, with 145 victims tracked on ransomware.live. Security experts note the group has recently shifted toward targeting organizations with large Salesforce deployments, exploiting the concentration of customer and employee data in CRM platforms.

None of the targeted companies have publicly confirmed any breach. Experts warn that a leak-site listing is an extortion tactic, not proof of compromise, but advise organizations to review access controls, vendor-risk procedures, and incident-response plans in light of the accelerating campaign.

SourcesRansomLook; recentbreaches.com; dexpose.io; ransomware.live; CTIWatch
React to this dispatch
Share this dispatch X WhatsApp Bluesky Report an error
Written by

Founder and editor of Pulse of Nations, an independent wire service covering war, geopolitics, markets and technology.

discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Next dispatch 768 Leaked AWS Keys Expose Corporate Cloud Admin Access Read →