Ransomware victim disclosure
← All victimsZayo.com & Allstream.com
Claimed by Shinyhunters · listed 3 days ago
Status timeline
- ListedJun 12, 2026
- Data leakeddate unknown
At a glance
- Group
- Shinyhunters
- Status
- Data leaked
- Country
- United States
- Sector
- Telecommunication
- Listed on leak site
- Jun 12, 2026
About the victim
AI dossier — public-source company profileZayo.com and Allstream.com are telecommunications and network infrastructure companies operating in North America. Zayo Group is a major provider of bandwidth, colocation, and cloud connectivity services; Allstream is a Canadian telecom subsidiary.
- Industry
- Telecommunications
Attack summary
Severity: critical — Exfiltration from major telecommunications infrastructure providers affecting operational continuity; threat actors self-assessed criticality at 9/10 and explicitly threatened operational disruption alongside data publication. Telecommunications is critical infrastructure.ShinyHunters claims to have exfiltrated data from Zayo and Allstream, assigning a criticality score of 9/10. The threat actors have withheld details of the stolen data and issued a final warning for June 16, 2026, threatening full publication and additional operational disruption if demands are not met.
Data the group says was taken
AI dossier — extracted from the leak post- Unspecified business-critical data
- Potentially customer records
- Potentially network/infrastructure data
What the group claims
You wouldn't want us to describe what data was taken from you publicly here. A fair assessment of this breach in terms of criticality is a 9/10. We urge you to reach out. Read our emails. Failure to do so will result in the full publication and we very much intend to carry that out if you do not engage with us. This is a final warning to reach out by 16 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 12 June 2026 | Warning: FINAL WARNING PAY OR LEAK
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

