Skip to content
CyrusOne and Double Counter Breaches Expose Over 648,000 Accounts

CyrusOne and Double Counter Breaches Expose Over 648,000 Accounts

First seen 8 Oct 2026, 10:38 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 8, 2026 at 11:32 UTC
  • •CyrusOne breach involved 373,460 accounts, primarily corporate data.
  • •Double Counter reported a breach affecting 274,922 accounts in October 2026.
  • •Both breaches were disclosed on October 7, 2026, with strong recommendations for password changes.

In August 2026, CyrusOne, a data center operator, suffered a breach involving 373,460 accounts due to a ShinyHunters extortion attempt, which resulted in the publication of sensitive corporate data. The leaked data included email addresses, names, physical addresses, phone numbers, job titles, and operational information. Additionally, Double Counter reported a breach in October 2026, affecting 274,922 accounts, with details still emerging. Both breaches were added to Have I Been Pwned on October 7, 2026. Users are advised to change passwords and enable two-factor authentication where possible. The breaches highlight the ongoing threat of extortion tactics in the cybersecurity landscape.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-08-01
CyrusOne breach occurred
CyrusOne was targeted by ShinyHunters, leading to the exposure of 373,460 accounts.
Haveibeenpwned
2026-10-01
Double Counter breach occurred
Double Counter reported a breach affecting 274,922 accounts, details are still emerging.
Haveibeenpwned
2026-10-07
Breaches added to Have I Been Pwned
Both breaches were disclosed and added to the Have I Been Pwned database.
Haveibeenpwned

More articles in this cluster (3)

Following this threat?

Track ShinyHunters and CyrusOne in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

How many accounts were affected in each breach?
CyrusOne had 373,460 accounts affected, while Double Counter reported 274,922 accounts.
What types of data were leaked?
The CyrusOne breach included corporate data such as email addresses, names, and job titles, while details on Double Counter's data are still emerging.
What actions should users take?
Users should change passwords immediately and enable two-factor authentication where available.