CyrusOne Data Centre Operator Breach Exposes 373 K Corporate Contacts
CyrusOne suffered a data‑centre breach in August 2026 that resulted in the public release of 373 000 corporate email addresses, names, job titles and support‑ticket details. The incident underscores the need for continuous third‑party risk monitoring and audit‑ready evidence of vendor oversight.
ADTP Breach Watch· October 7, 2026· HIBP Latest Breaches RSS
SeverityHigh
Type📧 Breach
ConfidenceHigh
ReportedOct 7, 2026
Cloud & Infrastructure ProvidersCLOUD_HOSTUnknown
What happened
In August 2026, the ShinyHunters extortion group compromised CyrusOne and published a data set containing 373 000 unique email addresses, names, phone numbers, physical addresses, job titles and internal support tickets. The leak was added to Have I Been Pwned on 7 Oct 2026.
Why it matters for trust and compliance
This breach demonstrates how a lapse in vendor oversight can surface in your own data exposure, highlighting the importance of a continuous third‑party risk‑management program that provides auditable evidence of control effectiveness.
Continuous monitoring of third‑party security posture supplies the evidence needed for audit readiness.
Documented due‑diligence on vendor controls creates a defensible trail for regulators and partners.
Who is affected
CLOUD_HOST
Recommended actions
Search the leaked data for any of your organization’s contacts and force immediate password changes.
Enable multi‑factor authentication on all accounts that used the exposed credentials.
Conduct a third‑party risk review of CyrusOne, updating contracts and security questionnaires.
Collect and retain evidence of the review for audit purposes.
Get the Breach Digest
The incidents that matter for your vendors and your data, analysed for practitioners, in one email.