Data breach

CyrusOne: a data breach

In August 2026, data centre operator CyrusOne was the target of a ShinyHunters "pay or leak" extortion attempt . The group subsequently published data allegedly obtained from the company, which included 373k unique email addresses across records relating to users, sales leads and CyrusOne employees. The data largely consisted of corporate contact information, including names, physical addresses, phone numbers and job titles. It also included support tickets and other information related to the organisation's operations.

The record

Organisation
CyrusOne →
Identity
CyrusOneidentified by its domain in a verified breach record
Records affected
373,460 records
Data exposed
Email addresses, Employers, Job titles, Names, Phone numbers, Physical addresses, Support tickets
Sector
Not recorded
Occurred
2026-08-05
Disclosed
2026-10-07
First recorded here
2026-10-08

Fastnexa security experts

Worried the same could happen to your company?

If you are a customer or supplier of CyrusOne, or work in the same industry, a Fastnexa security expert can tell you what this means for your data and test whether the same attack would work on you.

Book a 30-min callWhatsApp us

Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →

Sources (1)

One source so far.

  1. Have I Been Pwned ↗First reported

    2026-10-07