CyrusOne Data Breach Exposes Contact Information and Employee Records

Published: 8 October 2026
Other Commercial data breach illustration
Breach Discovery: August 2026Breach Notification: October 2026

In August 2026, the extortion group ShinyHunters claimed to steal data from data centre operator CyrusOne and later leaked it after an apparent failed ransom demand. The leak reportedly includes names, emails, phone numbers, addresses, job titles and support tickets for about 373,000 people, including customers, sales leads and employees. Affected individuals should watch closely for phishing attempts referencing their employer or past CyrusOne contact.

CompanyCyrusOne
IndustryOther Commercial
Data Types ExposedNames, Email Addresses, Physical Addresses, Phone Numbers, Job Titles, Employer Information, Support Ticket Records
People Affected373,000 individuals
Attack MethodExtortion/Data Theft
Regulators NotifiedNot Publicly Disclosed

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the CyrusOne Data Breach?

CyrusOne, a company that builds and runs large data centre facilities, is now notifying people after a data breach tied to an extortion attempt. According to available reporting, unauthorized access to its network or systems occurred in August 2026. A group known as ShinyHunters claimed responsibility for the incident.

The attackers reportedly ran a “pay or leak” scheme. This means they allegedly stole data first, then threatened to publish it unless CyrusOne paid a ransom. When no payment reportedly followed, the group released the data publicly. As a result, information that was supposed to stay private became exposed to anyone who found it online.

The leaked files reportedly include around 373,000 unique email addresses. These records span customers, sales leads, and CyrusOne employees. Because the breach became public through a criminal group’s own leak rather than a formal company disclosure, many specific forensic details remain unclear. It is not publicly known exactly how the attackers first got in, or how long they had access before the leak occurred.

Who was affected?

customers, job applicants, sales prospects, and current or former employees of CyrusOne may all be affected by this breach. The leaked dataset reportedly mixes several types of records together. This includes people who simply interacted with CyrusOne’s sales team, as well as staff whose employment details were stored internally.

The number of affected individuals has not been separately confirmed beyond the reported figure of roughly 373,000 unique email addresses. However, that number likely represents a mix of distinct people rather than a single clearly defined group. Because CyrusOne operates data centres used by large businesses across the country, affected individuals could be spread across many states.

There is no indication in available information that minors were involved in this breach. Still, anyone who has ever corresponded with CyrusOne, applied for a job there, or worked for the company should consider themselves potentially included until more specific notifications are issued.

What Information Was Potentially Exposed?

The data allegedly published by the attackers was largely corporate and professional contact information. In addition, it reportedly included internal records tied to how CyrusOne manages customer support and daily operations.

  • Names
  • Email addresses
  • Physical addresses
  • Phone numbers
  • Job titles
  • Employer information
  • Support ticket records

At first glance, this may look less sensitive than a breach involving Social Security numbers or financial accounts. However, the combination of names, direct contact details, and employer information is still valuable to scammers. For example, a fraudster could use someone’s job title and employer to craft a convincing phishing email that looks like it comes from a coworker or vendor.

Support ticket data adds another layer of risk because it may reveal details about internal problems, account issues, or operational concerns. If attackers reference this information in follow-up messages, victims may be more likely to trust a fraudulent request. In addition, widespread exposure of direct phone numbers and addresses raises the risk of targeted scam calls, mail fraud, or social engineering attempts aimed at both individuals and the business itself.

What is the company doing?

Public information currently available describes this incident mainly through the attacker’s own leak-site claims. CyrusOne has not publicly confirmed every detail of the incident in the same reporting. Because of this, it is not yet clear what internal investigation steps the company has taken or announced.

Notification efforts tied to this breach reportedly began reaching affected people in October 2026. If CyrusOne has engaged forensic investigators, improved network security, or arranged credit monitoring services, those specifics have not been confirmed in the available source material. Affected individuals should watch for official written notices from CyrusOne, since those notices would contain the most accurate details about any support being offered.

What Should Affected Individuals Do?

Watch for Phishing and Scam Attempts

Because email addresses, names, and phone numbers were reportedly exposed, phishing is the most immediate risk. Be cautious of unexpected emails, texts, or calls that reference your job, employer, or any past dealings with CyrusOne. Scammers often use real personal details to make fake messages look legitimate.

Never click links or download attachments from unsolicited messages, even if they appear to come from a known contact. Instead, verify requests by contacting the sender directly through a phone number or website you already trust. This simple habit can stop many scams before they start.

Monitor Your Credit Reports

Even though this breach did not reportedly expose Social Security numbers or financial account details, it’s still wise to check your credit reports regularly. Identity thieves sometimes combine leaked contact information with data from other breaches to build a fuller profile of a victim. As a result, monitoring for unfamiliar accounts or inquiries is a smart precaution.

You can request free credit reports from the three major bureaus and review them for anything unusual. If you notice unfamiliar activity, report it immediately. Catching fraud early often limits the damage significantly.

Protect Your Professional and Personal Identity

Because job titles and employer names were included in the leak, there is a risk of targeted business email compromise attempts. These scams often impersonate executives or vendors to trick employees into wiring money or sharing sensitive data. Therefore, employees of affected organizations should alert their IT or security teams about this breach.

In addition, consider updating passwords tied to your work email, especially if you reuse them elsewhere. Enabling multi-factor authentication adds another strong layer of protection against unauthorized account access.

Stay Alert for Official Notifications

If you believe you may be affected, keep an eye out for any formal letter or email from CyrusOne. Official notices typically explain exactly what data was involved and what resources, if any, are being offered. This information will be more detailed and specific than general public reporting.

Meanwhile, document any suspicious contact you receive that references this breach. This record could be useful if you ever need to report fraud or consult an attorney about your options.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



Related Data Breaches

View the full list of tracked data breaches →