INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
CyrusOne Experiences Breach of 373,460 Accounts
| 2026-10-07 23:19 DATA BREACH
Executive Summary
AI-generated
In August 2026, data centre operator CyrusOne was the target of a ShinyHunters "pay or leak" extortion attempt, resulting in the breach of approximately 373k unique email addresses across records relating to users, sales leads and CyrusOne employees. The group subsequently published this allegedly obtained data, which included corporate contact information such as names, physical addresses, phone numbers and job titles. This incident is classified as an Extortion cyber operation type attack carried out by the ShinyHunters APT Group against CyrusOne, affecting approximately 373k individuals with compromised email addresses. The breach also impacted CyrusOne directly, resulting in a total of 373,460 breached accounts.
Technical Mitigations AI-generated
• Patch CyrusOne's systems to address potential vulnerabilities in the ShinyHunters exploit.
• Monitor for indicators of a "pay or leak" extortion attempt, such as unusual login activity and support ticket requests.
• Implement rate limiting on employee email addresses to prevent mass phishing attempts.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Global Scope
Incident Timeline
Intelligence Sources
Have I Been Pwned
2026-10-07
CyrusOne - 373,460 breached accounts
Have I Been Pwned