High

CyrusOne Breach: 373K Emails & Phone Numbers Leaked

By Yazoul AI · automated

In August 2026, data centre operator CyrusOne was the target of a ShinyHunters "pay or leak" extortion attempt . The group subsequently published data allegedly obtained from the company, which included 373k unique email addresses across records relating to users, sales leads and CyrusOne employees....

Overview

In August 2026, data center operator CyrusOne became the target of a “pay or leak” extortion attempt by the ShinyHunters group. When CyrusOne did not meet the group’s demands, ShinyHunters published data it claimed to have stolen from the company. That dataset, now logged by Have I Been Pwned, contains 373,460 unique email addresses tied to customer records, sales leads, and CyrusOne’s own employees.

CyrusOne is a major colocation provider, meaning it houses servers and networking equipment for other businesses. A breach at a company like this matters beyond its own walls, because its customers trust it to protect the physical and digital infrastructure their operations depend on.

What Was Exposed

The leaked records are largely corporate contact information rather than financial or login data. Specifically:

  • Email addresses - 373,460 unique addresses, the core of the dataset
  • Names - full names tied to each contact record
  • Phone numbers - direct business lines for individuals
  • Physical addresses - office and possibly facility locations
  • Job titles - role information that reveals who does what
  • Support tickets and operational data - internal correspondence about the company’s operations

The support ticket data is the quiet concern here. Tickets often contain details about systems, access issues, and vendor relationships that were never meant to be public.

Why This Data Matters

At first glance, corporate contact details seem low-stakes. They are not. This is a ready-made target list for business email compromise and phishing. Attackers who know your name, title, employer, phone number, and that you file support tickets can craft messages that look completely legitimate.

Job titles are especially valuable. A message addressed to a “Network Operations Manager” about an urgent ticket carries far more weight than a generic phishing email. The combination of operational data and verified contact details turns an ordinary list into a precision tool for social engineering.

Recommendations

If your information appears in this breach, take these steps:

  1. Treat unexpected messages with suspicion. Any email or call referencing CyrusOne, support tickets, or your job title should be verified through a known channel before you act.
  2. Watch for vishing. With phone numbers exposed, expect calls from people impersonating IT, vendors, or colleagues.
  3. Never click login links in unsolicited email. Navigate to sites directly instead.
  4. Enable multi-factor authentication on all work and personal accounts, prioritizing email and banking.
  5. Flag suspicious contacts to your security team, especially if you work at an organization that does business with CyrusOne.
  6. Consider a password manager and unique passwords if you reuse credentials anywhere, since exposed emails fuel credential-stuffing attacks.

How to Check If You’re Affected

CyrusOne-related records are searchable through Have I Been Pwned at haveibeenpwned.com/Breach/CyrusOne. Enter any email address you use for work to see whether it appears in this dataset. If it does, assume the associated name, phone number, and job title are also in circulation.

Security Insight

A “pay or leak” campaign against an infrastructure provider is a pointed warning: attackers increasingly target companies whose value is not customer data but customer access. Unlike a retail breach where stolen cards can be reissued, leaked operational details and contact hierarchies cannot simply be reset. CyrusOne’s exposure also highlights a growing pattern of extortion groups publishing data specifically to pressure victims publicly, meaning the reputational and phishing damage often outlasts the breach itself. For companies in the data center space, where physical and network trust is the entire product, this is a reputational risk as much as a technical one.

Further Reading

Share:

Never miss a data breach report

Get real-time security alerts delivered to your preferred platform.

Related Breach Reports

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.