CyrusOne Breach: 373K Emails & Phone Numbers Leaked
In August 2026, data centre operator CyrusOne was the target of a ShinyHunters "pay or leak" extortion attempt . The group subsequently published data allegedly obtained from the company, which included 373k unique email addresses across records relating to users, sales leads and CyrusOne employees....
Overview
In August 2026, data center operator CyrusOne became the target of a “pay or leak” extortion attempt by the ShinyHunters group. When CyrusOne did not meet the group’s demands, ShinyHunters published data it claimed to have stolen from the company. That dataset, now logged by Have I Been Pwned, contains 373,460 unique email addresses tied to customer records, sales leads, and CyrusOne’s own employees.
CyrusOne is a major colocation provider, meaning it houses servers and networking equipment for other businesses. A breach at a company like this matters beyond its own walls, because its customers trust it to protect the physical and digital infrastructure their operations depend on.
What Was Exposed
The leaked records are largely corporate contact information rather than financial or login data. Specifically:
- Email addresses - 373,460 unique addresses, the core of the dataset
- Names - full names tied to each contact record
- Phone numbers - direct business lines for individuals
- Physical addresses - office and possibly facility locations
- Job titles - role information that reveals who does what
- Support tickets and operational data - internal correspondence about the company’s operations
The support ticket data is the quiet concern here. Tickets often contain details about systems, access issues, and vendor relationships that were never meant to be public.
Why This Data Matters
At first glance, corporate contact details seem low-stakes. They are not. This is a ready-made target list for business email compromise and phishing. Attackers who know your name, title, employer, phone number, and that you file support tickets can craft messages that look completely legitimate.
Job titles are especially valuable. A message addressed to a “Network Operations Manager” about an urgent ticket carries far more weight than a generic phishing email. The combination of operational data and verified contact details turns an ordinary list into a precision tool for social engineering.
Recommendations
If your information appears in this breach, take these steps:
- Treat unexpected messages with suspicion. Any email or call referencing CyrusOne, support tickets, or your job title should be verified through a known channel before you act.
- Watch for vishing. With phone numbers exposed, expect calls from people impersonating IT, vendors, or colleagues.
- Never click login links in unsolicited email. Navigate to sites directly instead.
- Enable multi-factor authentication on all work and personal accounts, prioritizing email and banking.
- Flag suspicious contacts to your security team, especially if you work at an organization that does business with CyrusOne.
- Consider a password manager and unique passwords if you reuse credentials anywhere, since exposed emails fuel credential-stuffing attacks.
How to Check If You’re Affected
CyrusOne-related records are searchable through Have I Been Pwned at haveibeenpwned.com/Breach/CyrusOne. Enter any email address you use for work to see whether it appears in this dataset. If it does, assume the associated name, phone number, and job title are also in circulation.
Security Insight
A “pay or leak” campaign against an infrastructure provider is a pointed warning: attackers increasingly target companies whose value is not customer data but customer access. Unlike a retail breach where stolen cards can be reissued, leaked operational details and contact hierarchies cannot simply be reset. CyrusOne’s exposure also highlights a growing pattern of extortion groups publishing data specifically to pressure victims publicly, meaning the reputational and phishing damage often outlasts the breach itself. For companies in the data center space, where physical and network trust is the entire product, this is a reputational risk as much as a technical one.
Further Reading
Never miss a data breach report
Get real-time security alerts delivered to your preferred platform.
Related Breach Reports
In August 2026, the French intellectual property software and services company Questel was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published an extensive corpus of data they alleged was obtained from the company, largely comprising corporate contact inf...
In June 2026, Inter-Con Security was targeted in a ShinyHunters “pay or leak” extortion campaign . The group subsequently published data it alleged was taken from the company, including 276k unique email addresses along with names, physical addresses, job titles and phone numbers. The data encompass...
In June 2026, the food distribution company Sysco was targeted by a ShinyHunters "pay or leak" extortion campaign . Data was subsequently published containing 2.7M unique email addresses belonging to staff and customers. The data also contained largely corporate contact information including names, ...
In May 2026, the telecommunications company Charter Communications (the parent company behind the consumer broadband and cable brand Spectrum) was named by the ShinyHunters group in a "pay or leak" extortion campaign . The group later published the data, which exposed 4.9M unique email addresses alo...