Data breach
CyrusOne, LLC.
- Records
- 552,494
- Breach date
- 23 August 2026Estimated
- Added
- 27 August 2026
What was exposed
8 types of data · 2 put you at serious risk
- Email addresses552,494
- Names340,043
- Street addresses200,639
- Phone numbers185,823
- Bank account numbers153
- Licence plates38
- Social security numbers10
- Dates of birth7
About this breach
ShinyHunters, an extortion group known for attacking large companies, has added CyrusOne, LLC., a Texas-based data center operator, to its leak site, claiming it stole customer and employee records from the company. The group says it obtained nearly 13 million Salesforce records and roughly 645 GB of data from the company's SharePoint, including contracts, facility diagrams, and security documents. The claim, which carries a $13 million ransom demand, has not been independently verified, and CyrusOne has not publicly confirmed any compromise. An estimated 552,494 records tied to this listing have been reviewed, containing names, email addresses, phone numbers, and other personal details. The team estimates the attack date as August 23, 2026, and the listing was added to the database on August 27, 2026.
August 20, 2026: ShinyHunters first added an unnamed, redacted victim to its leak site, according to TechRadar, posting a warning that read "Final warning - pay or leak."
August 23, 2026: The group publicly named CyrusOne as its victim, disclosed a $13 million demand, and set an end-of-day August 24 deadline for the company to engage, as documented on ransomware.live.
August 26, 2026: TechRadar reported that the deadline had passed with no public statement from CyrusOne and no files leaked.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Email addresses: 552,494
Names: 340,043
Street addresses: 200,639
Phone numbers: 185,823
Bank account records: 153
Social Security numbers: 10
Dates of birth: 7
Vehicle plate numbers: 38
Not every individual is affected by every type of data listed here.
The figures above come from the indexed copy of the leaked data. Separately, ShinyHunters claims the larger stolen collection also includes Salesforce contact records, employee personal information, executed contracts and master service agreements, data center floor plans, electrical diagrams, badge audit logs, key inventories, and credential artifacts. Those claims have not been verified, and no samples had been posted as of the reporting above.
What Are the Potential Risks for Affected Individuals?
For most people, the immediate risk is targeted phishing. Attackers holding a person's name, email, phone number, and street address can craft convincing messages that appear to come from CyrusOne, its clients, or service providers, then use those messages to steal passwords or financial details.
The small number of bank account records and Social Security numbers raises more serious concerns for the affected individuals, including potential fraud or identity theft. Anyone whose data includes those fields should watch their accounts closely.
Because ShinyHunters claims to have taken facility schematics, access control records, and credential files, there is also a broader risk if the claims prove true. Security researchers have noted such material could theoretically enable physical intrusions or follow-on attacks against the company or its clients. These risks remain unconfirmed.
What Should You Do If You Were Affected?
Change passwords on any accounts that may share a password with exposed credentials, and turn on two-factor authentication where available.
Be cautious with unexpected emails, calls, or texts referencing CyrusOne, data centers, or account problems. Do not click links or share verification codes.
If your bank account or Social Security number may be exposed, consider placing a fraud alert or credit freeze with the major credit bureaus and review bank statements for unfamiliar activity.
Watch for any official notice from CyrusOne. If one arrives, verify it against the company's website before acting on it.
As of September 25, 2026, CyrusOne had not published a public notice about this listing, and no breach notification letters had been reported in the sources reviewed.
