Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
CyrusOne

CyrusOne Vendor Cyber Rating & Cyber Score

cyrusone.com

CyrusOne is a leading global data center developer and operator, delivering sophisticated digital infrastructure solutions worldwide. Headquartered in Dallas, Texas, the company operates over 60 data centers across the United States, Europe, and Japan. Specializing in comprehensive solutions for hyperscale and Fortune 1000 companies, CyrusOne enables customers to align with their unique business and sustainability goals, catering to the complex needs of AI-driven applications and services workloads. CyrusOne’s data centers offer unparalleled flexibility, enabling customers to modernize, simplify, and rapidly respond to changing demands. CyrusOne delivers tailored build-to-suit, colocation, and interconnection solutions that meet the


CyrusOne A.I CyberSecurity Scoring

CyrusOne
Company Information
Website:http://www.cyrusone.com/
Employees number:1,081
Number of followers:71,748
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:cyrusone.com
CyrusOne Risk Score (AI oriented)
Between 650 and 699
logo
CyrusOneIT Services and IT Consulting
Updated:
01/09/2026
684/1000
Weak
B
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
✖ Insurance prefers TPRM score to calculate premium
CyrusOne Global Score (TPRM)
xxxx
logo
CyrusOneIT Services and IT Consulting
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

CyrusOneWeak
Current Score
684B (WEAK)
01000
3 incidents
-32 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
684Before Incident
AUGUST 2026
715Before Incident
Cyber Attack
20 Aug 2026 • CyrusOne
Verizon, CyrusOne, AT&T and CME Group: ShinyHunters hackers claim to have hit data center provider used by Microsoft and Meta

ShinyHunters Targets CyrusOne in $13M Ransomware Attack, Stealing Highly Sensitive Data

683After Incident
CRITICAL-32
CMEVERCYRATT1787768910
ShinyHunters Targets CyrusOne in $13M Ransomware Attack, Stealing Highly Sensitive Data The notorious ransomware group ShinyHunters has added CyrusOne, a major U.S. data center operator, to its list of victims, claiming to have exfiltrated a massive trove of sensitive corporate and operational data. The breach, if verified, could pose severe risks to both CyrusOne and its high-profile clients, including Fortune 1000 companies, Microsoft, Meta, Verizon, AT&T, IBM, and CME Group. ### Stolen Data Includes Critical Infrastructure Details ShinyHunters alleges the theft of: - 12.9 million Salesforce records and 182,000+ contact entries - 600GB of SharePoint data - 8,300+ employee records containing PII (personally identifiable information) - Executed contracts, NDAs, and master service agreements - Data center floor plans, electrical diagrams, and access-control records - Physical key inventories, badge audits, and security policies - Environmental reliability documentation (power, cooling, and critical infrastructure processes) - Passwords and credential artifacts The attackers are demanding $13 million in exchange for deleting the data, threatening to leak it if CyrusOne does not comply. As of now, the company has not responded publicly or engaged in negotiations, despite the group’s 24-hour ultimatum issued on August 24, 2026. ### Potential for Physical and Supply-Chain Attacks Unlike typical ransomware incidents, this breach includes non-digital assets such as facility layouts, key inventories, and surveillance details that could enable physical intrusions into CyrusOne’s 50+ U.S. data centers. Researchers warn that such intelligence could allow attackers to bypass security measures, disable surveillance, or even sabotage infrastructure, leading to outages, fires, or supply-chain disruptions. Additionally, the theft of customer contracts, SLAs, and contact details for major clients like Microsoft and Meta raises concerns about highly targeted phishing attacks, potentially turning this into a large-scale third-party supply-chain compromise. ### Timeline of the Attack - August 20, 2026: ShinyHunters first listed a redacted victim on its leak site with a "Final warning - pay or leak" message. - August 23, 2026: The group publicly named CyrusOne as the victim and set a 24-hour deadline for payment. - August 24, 2026: Deadline passed with no response from CyrusOne; no data has been leaked yet. ShinyHunters has not released samples of the stolen data, a tactic often used to increase pressure on victims. With no public statement from CyrusOne, the full extent of the breach and its potential fallout remains unclear.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain
IMPACT
Data Compromised: 600GB+ of sensitive data, including 12.9M Salesforce records, 182K+ contact entries, 8.3K+ employee records with PII, contracts, NDAs, data center floor plans, electrical diagrams, access-control records, physical key inventories, badge audits, security policies, environmental reliability documentation, passwords, and credential artifactsOperational Impact: Potential physical intrusions, supply-chain disruptions, and targeted phishing attacksBrand Reputation Impact: SevereIdentity Theft Risk: High
DATA BREACH
Salesforce recordsContact entriesEmployee records (PII)Executed contractsNDAsMaster service agreementsData center floor plansElectrical diagramsAccess-control recordsPhysical key inventoriesBadge auditsSecurity policiesEnvironmental reliability documentationPasswordsCredential artifactsNumber Of Records Exposed: 12.9M Salesforce records, 182K+ contact entries, 8.3K+ employee recordsSensitivity Of Data: Highly sensitive (corporate, operational, and personal data)
JULY 2026
714Before Incident
JUNE 2026
713Before Incident
MAY 2026
712Before Incident
APRIL 2026
711Before Incident
MARCH 2026
710Before Incident
FEBRUARY 2026
709Before Incident
JANUARY 2026
709Before Incident
DECEMBER 2025
707Before Incident
NOVEMBER 2025
706Before Incident
OCTOBER 2025
705Before Incident
DECEMBER 2019
651Before Incident
Ransomware
05 Dec 2019 • CyrusOne
CyrusOne, CyrusOne Managed Service Customers and Louisiana Office of Technology Services: CyrusOne hit by REvil ransomware, impacting 6 managed service customers

Louisiana State Servers Disabled and CyrusOne Hit by REvil Ransomware

485After Incident
CRITICAL-166
COLCYR1788296947
Louisiana State Servers Disabled, CyrusOne Hit by REvil Ransomware in Latest Wave of Attacks In a proactive security measure, Louisiana’s Office of Technology Services temporarily disabled state servers, disrupting email, websites, and online applications for multiple agencies. Governor John Bel Edwards confirmed the move was a precaution to prevent the spread of ransomware, following a pattern of attacks targeting government entities and school districts over the summer. Meanwhile, data center provider CyrusOne confirmed that six of its managed service customers primarily in its New York data center experienced outages after a REvil ransomware attack encrypted devices on their networks. The company clarified that its colocation and network services remained unaffected, though an investigation with third-party experts is ongoing. Attackers left a ransom note, stating they had "the best specialists" to restore files, a tactic consistent with REvil’s operations. The incidents are part of a broader surge in ransomware activity. Since October 1, at least 15 U.S. organizations including healthcare networks, municipalities, and police departments have been targeted, according to research from Armor. Earlier this year, Texas declared a state of emergency after a coordinated REvil attack crippled local governments, though critical services were later restored. Security firm McAfee analyzed the malware, noting its sophisticated design, which executes rapidly to encrypt files while obfuscating Windows API calls to evade detection. The REvil strain, active since April, has been linked to multiple high-profile attacks, including those on managed service providers (MSPs). This year alone, 13 MSPs or cloud providers have fallen victim to ransomware, underscoring the growing threat to third-party infrastructure. Louisiana’s and CyrusOne’s responses highlight the increasing adoption of preemptive shutdowns to contain ransomware, even as attackers refine their tactics to maximize disruption. Law enforcement is assisting in the CyrusOne investigation, though no further details on attribution or ransom demands have been disclosed.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain (ransomware extortion)
IMPACT
Data Compromised: Files encrypted (data exfiltration possible)Systems Affected: State servers (Louisiana), managed service customer devices (CyrusOne)Downtime: Disrupted email, websites, and online applications (Louisiana); outages for CyrusOne customersOperational Impact: Temporary shutdown of state services (Louisiana); service outages for CyrusOne customersBrand Reputation Impact: Likely negative impact on CyrusOne and Louisiana state agencies
DATA BREACH
Type Of Data Compromised: Encrypted files (potential data exfiltration)Data Exfiltration: Possible (REvil known for double extortion)Data Encryption: Yes (files encrypted by REvil)
DECEMBER 2019
757Before Incident
Ransomware
01 Dec 2019 • CyrusOne
CyrusOne

CyrusOne Ransomware Attack

649After Incident
CRITICAL-108
CYR391523
CyrusOne has suffered a ransomware attack, and said they are currently working with law enforcement and forensics firms to investigate the attack. Stating that Six of their managed service customers, located primarily in New York data center, have experienced availability issues due to a ransomware program encrypting certain devices in their network. According to a copy of the ransom note, this was a targeted attack against the company's network. A copy of the ransomware executable that is believed to have infected the company's network was uploaded on VirusTotal.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial Gain
IMPACT
Devices in the networkNew York data centerDowntime: Availability issuesOperational Impact: Availability issues
DATA BREACH
Data Encryption: Encrypting certain devices

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for CyrusOne ?
?
What was CyrusOne's A.I Rankiteo Cyber Score in August 2026 ?
?
What was CyrusOne's A.I Rankiteo Cyber Score in July 2026 ?
?
What was CyrusOne's A.I Rankiteo Cyber Score in June 2026 ?
?
What was CyrusOne's A.I Rankiteo Cyber Score in May 2026 ?
?
What was CyrusOne's A.I Rankiteo Cyber Score in April 2026 ?
?
What was CyrusOne's A.I Rankiteo Cyber Score in March 2026 ?
?
What was CyrusOne's A.I Rankiteo Cyber Score in February 2026 ?
?
What was CyrusOne's A.I Rankiteo Cyber Score in January 2026 ?
?
What was CyrusOne's A.I Rankiteo Cyber Score in December 2025 ?
?
What was CyrusOne's A.I Rankiteo Cyber Score in November 2025 ?
?
What was CyrusOne's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on CyrusOne's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with CyrusOne ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view CyrusOne's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
CyrusOne Cyber Scoring History | Rankiteo