Data centre operator CyrusOne had data on approximately 373,000 accounts published by the ShinyHunters group following an extortion attempt in August 2026.
Loading page…
Loading page…
Data centre operator CyrusOne had data on approximately 373,000 accounts published by the ShinyHunters group following an extortion attempt in August 2026.
According to Have I Been Pwned, in August 2026 the ShinyHunters hacking group targeted CyrusOne, a data centre operator, with a "pay or leak" extortion attempt. When the demand was not met, the group published data allegedly obtained from the company.
Reported by Have I Been Pwned, the published data contained roughly 373,000 unique email addresses drawn from records relating to customers, sales leads, and CyrusOne employees. The exposed information largely consisted of corporate contact details, including names, physical addresses, phone numbers, job titles, and employer information. Support tickets and other operational records were also included.
According to Have I Been Pwned, those affected include CyrusOne customers, prospective sales contacts, and company employees whose information appeared in the leaked records.
If you have ever interacted with CyrusOne as a customer, sales contact, or employee, assume your corporate contact details may be exposed. Be alert to targeted phishing emails or phone calls that use your name, employer, or job title to appear legitimate. Consider using a unique email address for business communications going forward, and report any suspicious contact to your IT or security team.