BREACH WATCH BRIEF High 📧 Breach

CyrusOne Data Centre Operator Breach Exposes 373 K Corporate Contacts

CyrusOne suffered a data‑centre breach in August 2026 that resulted in the public release of 373 000 corporate email addresses, names, job titles and support‑ticket details. The incident underscores the need for continuous third‑party risk monitoring and audit‑ready evidence of vendor oversight.

SeverityHigh
Type📧 Breach
ConfidenceHigh
ReportedOct 7, 2026
Cloud & Infrastructure Providers CLOUD_HOST Unknown

What happened

In August 2026, the ShinyHunters extortion group compromised CyrusOne and published a data set containing 373 000 unique email addresses, names, phone numbers, physical addresses, job titles and internal support tickets. The leak was added to Have I Been Pwned on 7 Oct 2026.

Why it matters for trust and compliance

  • This breach demonstrates how a lapse in vendor oversight can surface in your own data exposure, highlighting the importance of a continuous third‑party risk‑management program that provides auditable evidence of control effectiveness.
  • Continuous monitoring of third‑party security posture supplies the evidence needed for audit readiness.
  • Documented due‑diligence on vendor controls creates a defensible trail for regulators and partners.

Who is affected

CLOUD_HOST

Recommended actions

  1. Search the leaked data for any of your organization’s contacts and force immediate password changes.
  2. Enable multi‑factor authentication on all accounts that used the exposed credentials.
  3. Conduct a third‑party risk review of CyrusOne, updating contracts and security questionnaires.
  4. Collect and retain evidence of the review for audit purposes.

Get the Breach Digest

The incidents that matter for your vendors and your data, analysed for practitioners, in one email.