CyrusOne A.I CyberSecurity Scoring
CyrusOne
Company Information
Website:http://www.cyrusone.com/
Employees number:1,081
Number of followers:71,748
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:cyrusone.com
CyrusOne Risk Score (AI oriented)
Between 650 and 699
CyrusOneIT Services and IT Consulting
Updated:
01/09/2026
01/09/2026
684/1000
Weak
B
CyrusOne Global Score (TPRM)
xxxx
CyrusOneIT Services and IT Consulting
Score locked

CyrusOneWeak
Current Score
684B (WEAK)
01000
3 incidents
-32 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
684
AUGUST 2026
715
Cyber Attack
20 Aug 2026 • CyrusOne
Verizon, CyrusOne, AT&T and CME Group: ShinyHunters hackers claim to have hit data center provider used by Microsoft and Meta
ShinyHunters Targets CyrusOne in $13M Ransomware Attack, Stealing Highly Sensitive Data
683
CRITICAL-32
CMEVERCYRATT1787768910
ShinyHunters Targets CyrusOne in $13M Ransomware Attack, Stealing Highly Sensitive Data
The notorious ransomware group ShinyHunters has added CyrusOne, a major U.S. data center operator, to its list of victims, claiming to have exfiltrated a massive trove of sensitive corporate and operational data. The breach, if verified, could pose severe risks to both CyrusOne and its high-profile clients, including Fortune 1000 companies, Microsoft, Meta, Verizon, AT&T, IBM, and CME Group.
### Stolen Data Includes Critical Infrastructure Details
ShinyHunters alleges the theft of:
- 12.9 million Salesforce records and 182,000+ contact entries
- 600GB of SharePoint data
- 8,300+ employee records containing PII (personally identifiable information)
- Executed contracts, NDAs, and master service agreements
- Data center floor plans, electrical diagrams, and access-control records
- Physical key inventories, badge audits, and security policies
- Environmental reliability documentation (power, cooling, and critical infrastructure processes)
- Passwords and credential artifacts
The attackers are demanding $13 million in exchange for deleting the data, threatening to leak it if CyrusOne does not comply. As of now, the company has not responded publicly or engaged in negotiations, despite the group’s 24-hour ultimatum issued on August 24, 2026.
### Potential for Physical and Supply-Chain Attacks
Unlike typical ransomware incidents, this breach includes non-digital assets such as facility layouts, key inventories, and surveillance details that could enable physical intrusions into CyrusOne’s 50+ U.S. data centers. Researchers warn that such intelligence could allow attackers to bypass security measures, disable surveillance, or even sabotage infrastructure, leading to outages, fires, or supply-chain disruptions.
Additionally, the theft of customer contracts, SLAs, and contact details for major clients like Microsoft and Meta raises concerns about highly targeted phishing attacks, potentially turning this into a large-scale third-party supply-chain compromise.
### Timeline of the Attack
- August 20, 2026: ShinyHunters first listed a redacted victim on its leak site with a "Final warning - pay or leak" message.
- August 23, 2026: The group publicly named CyrusOne as the victim and set a 24-hour deadline for payment.
- August 24, 2026: Deadline passed with no response from CyrusOne; no data has been leaked yet.
ShinyHunters has not released samples of the stolen data, a tactic often used to increase pressure on victims. With no public statement from CyrusOne, the full extent of the breach and its potential fallout remains unclear.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JULY 2026
714
JUNE 2026
713
MAY 2026
712
APRIL 2026
711
MARCH 2026
710
FEBRUARY 2026
709
JANUARY 2026
709
DECEMBER 2025
707
NOVEMBER 2025
706
OCTOBER 2025
705
DECEMBER 2019
651
Ransomware
05 Dec 2019 • CyrusOne
CyrusOne, CyrusOne Managed Service Customers and Louisiana Office of Technology Services: CyrusOne hit by REvil ransomware, impacting 6 managed service customers
Louisiana State Servers Disabled and CyrusOne Hit by REvil Ransomware
485
CRITICAL-166
COLCYR1788296947
Louisiana State Servers Disabled, CyrusOne Hit by REvil Ransomware in Latest Wave of Attacks
In a proactive security measure, Louisiana’s Office of Technology Services temporarily disabled state servers, disrupting email, websites, and online applications for multiple agencies. Governor John Bel Edwards confirmed the move was a precaution to prevent the spread of ransomware, following a pattern of attacks targeting government entities and school districts over the summer.
Meanwhile, data center provider CyrusOne confirmed that six of its managed service customers primarily in its New York data center experienced outages after a REvil ransomware attack encrypted devices on their networks. The company clarified that its colocation and network services remained unaffected, though an investigation with third-party experts is ongoing. Attackers left a ransom note, stating they had "the best specialists" to restore files, a tactic consistent with REvil’s operations.
The incidents are part of a broader surge in ransomware activity. Since October 1, at least 15 U.S. organizations including healthcare networks, municipalities, and police departments have been targeted, according to research from Armor. Earlier this year, Texas declared a state of emergency after a coordinated REvil attack crippled local governments, though critical services were later restored.
Security firm McAfee analyzed the malware, noting its sophisticated design, which executes rapidly to encrypt files while obfuscating Windows API calls to evade detection. The REvil strain, active since April, has been linked to multiple high-profile attacks, including those on managed service providers (MSPs). This year alone, 13 MSPs or cloud providers have fallen victim to ransomware, underscoring the growing threat to third-party infrastructure.
Louisiana’s and CyrusOne’s responses highlight the increasing adoption of preemptive shutdowns to contain ransomware, even as attackers refine their tactics to maximize disruption. Law enforcement is assisting in the CyrusOne investigation, though no further details on attribution or ransom demands have been disclosed.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2019
757
Ransomware
01 Dec 2019 • CyrusOne
CyrusOne
CyrusOne Ransomware Attack
649
CRITICAL-108
CYR391523
CyrusOne has suffered a ransomware attack, and said they are currently working with law enforcement and forensics firms to investigate the attack.
Stating that Six of their managed service customers, located primarily in New York data center, have experienced availability issues due to a ransomware program encrypting certain devices in their network.
According to a copy of the ransom note, this was a targeted attack against the company's network.
A copy of the ransomware executable that is believed to have infected the company's network was uploaded on VirusTotal.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for CyrusOne ??
What was CyrusOne's A.I Rankiteo Cyber Score in August 2026 ??
What was CyrusOne's A.I Rankiteo Cyber Score in July 2026 ??
What was CyrusOne's A.I Rankiteo Cyber Score in June 2026 ??
What was CyrusOne's A.I Rankiteo Cyber Score in May 2026 ??
What was CyrusOne's A.I Rankiteo Cyber Score in April 2026 ??
What was CyrusOne's A.I Rankiteo Cyber Score in March 2026 ??
What was CyrusOne's A.I Rankiteo Cyber Score in February 2026 ??
What was CyrusOne's A.I Rankiteo Cyber Score in January 2026 ??
What was CyrusOne's A.I Rankiteo Cyber Score in December 2025 ??
What was CyrusOne's A.I Rankiteo Cyber Score in November 2025 ??
What was CyrusOne's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on CyrusOne's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with CyrusOne ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view CyrusOne's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?