INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

CyrusOne Experiences Breach of 373,460 Accounts

| 2026-10-07 23:19 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
In August 2026, data centre operator CyrusOne was the target of a ShinyHunters "pay or leak" extortion attempt, resulting in the breach of approximately 373k unique email addresses across records relating to users, sales leads and CyrusOne employees. The group subsequently published this allegedly obtained data, which included corporate contact information such as names, physical addresses, phone numbers and job titles. This incident is classified as an ‎Extortion‎ cyber operation type attack carried out by the ShinyHunters APT Group against CyrusOne, affecting approximately 373k individuals with compromised email addresses. The breach also impacted CyrusOne directly, resulting in a total of 373,460 breached accounts.
Technical Mitigations AI-generated
• Patch CyrusOne's systems to address potential vulnerabilities in the ShinyHunters exploit. • Monitor for indicators of a "pay or leak" extortion attempt, such as unusual login activity and support ticket requests. • Implement rate limiting on employee email addresses to prevent mass phishing attempts.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
Target & Sectors
Global Scope
Incident Timeline
‎August 2026
Threat actors ShinyHunters attempted to extort CyrusOne by threatening to leak sensitive data, which they subsequently published online.
tactic Extortion
organisation CyrusOne
threat_actor ShinyHunters
organisation 373k
Intelligence Sources
Have I Been Pwned 2026-10-07