SyloSpace

How do attacks on data centres affect internet services and the companies that run them?

Attacks on data centres can be physical strikes or cyber operations, and their effects can spread to critical services, while the law on what counts as an 'attack' is still unsettled.

Updated 1 hour ago4 min readVersion 2
CommentsFollow

Covers: The technical, operational and business impacts of physical and cyber attacks on data centres, including service outages, data loss, recovery costs and effects on cloud providers and their customers. It does not provide instructions for carrying out attacks or cover unrelated topics like natural disasters.

Also answers: What happens when a data centre is attacked? · Impact of data centre attacks on internet services · How do data centre attacks affect companies? · Data centre security breaches and service disruption

Rows of black server racks with white logos in a data center
Photo: imgix

The short answer

Interpretation AI-prepared starting map

Attacks on data centres can take at least two forms: physical strikes on facilities and cyber operations against the systems they host. A reported example is a strike on a Yandex data centre, described as the third attack that week on the Russian tech giant, which forced the company to suspend its operations. Research on complex cyber-physical-social systems argues that cyber-attacks and network outages can cascade through interconnected systems and cause devastating effects on critical services across society, which is why identifying critical nodes and the percolation of consequences matters for resilience. Separately, legal scholarship argues that the concept of 'attack' in international humanitarian law needs reinterpretation to account for indirect civilian harm from cyber operations, including harm to civilian digital data.123

What this rests on5 independent sources
  • Evidence 9
  • Interpretation 4

Did this answer your question?

Be the first to vote
Your perspective belongs in the picture.Join free to vote

In brief

  1. A reported strike on a Yandex data centre was the third attack that week on the company and forced it to suspend operations.1

    Evidence-backed
    Join free to vote
  2. Modelling work suggests cyber-attacks and network outages can cascade through interconnected systems and hit critical services across society, making critical nodes and knock-on effects the key things to map.2

    Evidence-backed
    Join free to vote
  3. Cyber resilience is being formalised in frameworks such as EU NIS2 implementation, though the term itself still lacks one settled definition.4

    Evidence-backed
    Join free to vote
  4. Legal scholars argue 'attack' in international humanitarian law should be reinterpreted to cover indirect civilian harm from cyber operations, including harm to civilian digital data.3

    Evidence-backed
    Join free to vote

At a glance

What this page stands on

Live · updated just now

The evidence behind it

5 sources
  • Other studies and data3
  • Background2

Published in 2025 and 2026

Sources on this page by kind and year
SourceKindYear
Ukraine strikes Yandex data centre in third attack on Russian tech giantBackground2026
Data center (Wikipedia)BackgroundUnknown
Modelling Cascading Failure in Complex CPSS to Inform Resilient Mission Assurance: An Intelligent Transport System Case Study.Other studies and data2025
Cyber resilience conceptual model for European Union NIS2 standards implementation in Slovakia.Other studies and data2025
Cyber Military Operations under International Humanitarian Law: Interpreting the Concept of "Attack" and Challenges in Protecting Civilians.Other studies and data2026

The community around it

No one has added to this page yet. Firsthand experience, a newer study or a different reading of the numbers would show up here, credited to you.

What it means for you

Which fits you?

Pick the situation closest to yours. Each answer says what it rests on.

If you run or depend on services hosted in a single facility

the cascading-failure research points to mapping critical nodes and how consequences percolate, rather than assuming an outage stays contained.2

Interpretation

If you work on compliance in an EU country

the NIS2-oriented resilience model treats cyber resilience as a crisis-management problem and notes the term is still defined inconsistently, so align internal definitions before assuming shared meaning.4

Interpretation

If you are assessing whether a cyber operation counts as an 'attack' in a conflict

the legal analysis argues for reading 'attack' to include indirect civilian harm and harm to civilian digital data, which broadens what must be weighed under distinction, proportionality and precaution.3

Interpretation

The full story · 3 chapters

01

Reported attacks and their immediate effects

AI summary:A reported strike on a Yandex data centre was the third attack that week on the company and forced it to suspend operations.

Evidence-backed

Evidence-backed: Ukraine struck a Yandex data centre, the third attack that week on the Russian tech giant, forcing the company to suspend its operations. The report does not say which services were suspended, for how long, or how many users were affected.1

Evidence-backed

Evidence-backed: For context on what is being targeted: a data centre is a physical room, building or facility for storing, managing and disseminating data and information, housing IT infrastructure and used for workloads including training artificial intelligence. US law defines it as any facility that primarily contains electronic equipment used to process, store and transmit digital information, whether free-standing or inside a larger structure, using environmental control equipment to maintain operating conditions.5

02

Why effects can spread beyond the facility

AI summary:Modelling suggests cyber-attacks and outages can cascade through interconnected systems and hit critical services, so critical nodes and knock-on effects matter.

Evidence-backed

Evidence-backed: Research modelling cascading failure in complex cyber-physical-social systems finds that emergent behaviour caused by events such as cyber-attacks and network outages has the potential to have devastating effects on critical services across society. The model, tested on an intelligent transport system scenario, highlighted the value of identifying both critical nodes and the percolation of consequences during a cyber failure, and the importance of including social nodes for accurate simulation. The authors argue that understanding the relationships between cyber, physical and social nodes is key to understanding failures that occur because of, or involve, cyber systems.2

Evidence-backed

Evidence-backed: A separate strand of work on cyber resilience, developed for implementing EU NIS2 requirements in Slovakia, frames resilience as a crisis-management problem and notes that the term lacks a single settled definition. It aims to raise the level of cyber resilience through a model tied to national structures, with principles the authors suggest could apply in other EU countries.4

Your turn

Have your say

See where others stand. Join free to add your perspective. One answer per account.

How do you feel about this?

No votes yet
Your perspective belongs in the picture.Join free to vote

Quick questions from connected pages

Before you go

What to remember

The few things worth keeping from this page.

  1. A reported strike on a Yandex data centre was the third attack that week on the company and forced it to suspend operations.

  2. Modelling work suggests cyber-attacks and network outages can cascade through interconnected systems and hit critical services across society, making critical nodes and knock-on effects the key things to map.

  3. Cyber resilience is being formalised in frameworks such as EU NIS2 implementation, though the term itself still lacks one settled definition.

This answer keeps changing

When new evidence or a better source comes in, this page is updated (it's on version 2, last changed 1 hour ago). Follow it to be told when that happens.

Rows of black server racks with white logos in a data centerUp nextHow do attacks on data centres disrupt internet services?

Ask this Sylo

Still wondering about something?

Answers come only from this page's reviewed material, with citations, and say plainly when the page doesn't cover it yet.

Behind this page

Who's adding to it, where it comes from, how it changed and what would make it better. Always open to everyone.

Discussion

Nobody has added anything yet. If you have experience, evidence or a different view, you could be the first.

Sources

Numbers match the citations in the article. A working link isn't proof that a page supports a claim; check the quoted passage and date.

  1. 1
    Ukraine strikes Yandex data centre in third attack on Russian tech giant
    BBC NewsPublished Oct 11, 2026Checked Oct 11, 2026
    “It is the third time this week that Ukraine has targeted Russian tech giant Yandex, forcing the company to suspend its operations.”
  2. 2
    Modelling Cascading Failure in Complex CPSS to Inform Resilient Mission Assurance: An Intelligent Transport System Case Study.
    Entropy (Basel, Switzerland) (Sobb & Turnbull)Published Jul 25, 2025Checked Oct 11, 2026
    “They represent unique opportunities but also have potential threats to system operation and correctness. The emergent behaviour in Complex Cyber-Physical-Social Systems (C-CPSSs), caused by events such as cyber-attacks and network outages, have the potential to have devastating effects to critical services across society. It is therefore imperative that the risk of cascading failure is minimised through the fortifying of these systems of systems to achieve resilient mission assurance. This work designs and implements a programmatic model to validate the value of cascading failure simulation and analysis, which is then tested against a C-CPSS intelligent transport system scenario. Results from the model and its implementations highlight the value in identifying both critical nodes and percolation of consequences during a cyber failure, in addition to the importance of including social nodes in models for accurate simulation results. Understanding the relationships between cyber, physical, and social nodes is key to understanding systems' failures that occur because of or that involve cyber systems, in order to achieve cyber and system resilience.”
  3. 3
    Cyber Military Operations under International Humanitarian Law: Interpreting the Concept of "Attack" and Challenges in Protecting Civilians.
    F1000Research (Hamdan et al.)Published Jul 9, 2026Checked Oct 11, 2026
    “These challenges impede the practical application of the principles of distinction, proportionality, and precaution.ConclusionsThe study concludes that the concept of "attack" needs to be reinterpreted considering the indirect harm inflicted on civilians resulting from cyber operations. It also manifests the need to raise the scope of legal protection encompassing fundamental civilian digital data and confirms the possibility of developing a specialized international legal framework that governs cyber operations whether through the creation of an additional protocol or a treaty specific for such operations. Finally, the study further affirms the necessity to establish a neutral international mechanism that can conduct fact-finding tasks, investigate violations, and assign liabilities so as to promote better adherence to humanitarian principles in contemporary armed conflicts.”
  4. 4
    Cyber resilience conceptual model for European Union NIS2 standards implementation in Slovakia.
    Scientific reports (Ristvej et al.)Published Jul 24, 2025Checked Oct 11, 2026
    “The use of modern information and communication technologies in the business environment, as well as in everyday life has become common. However, with the dynamic development of these technologies, the risk of their abuse is also increasing. In this context, cyber resilience is coming into focus. This paper discusses the development of a Cyber Resilience Model based on the implementation of the normative acts of cyber security and the NIS2 directive in the context of crisis management. The model has the ambition to increase the level of cyber resilience. Its creation has been tailored for application in the structures of the Slovak Republic. The paper also deals with the definition of cyber resilience, as the term has not received sufficient attention and there are many different definitions. The findings of this paper have the potential to be applied in other countries of the European Union too, as the principles of cyber security and the obligation to implement legislation apply to all EU countries.”
  5. 5
    Data center (Wikipedia)
    WikipediaPublished Oct 8, 2026Checked Oct 11, 2026
    “A data center is a physical room, building, or facility for storing, managing, and disseminating data and information, including computer systems and associated components, housing IT infrastructure, and training artificial intelligence. The United States' act of Congress, the Energy Independence and Security Act of 2007, defines a data center as "any facility that primarily contains electronic equipment used to process, store, and transmit digital information." This includes "a free-standing structure" or "a facility within a larger structure, that uses environmental control equipment to maintain the proper conditions for the operation of electronic equipment." According to IBM, data centers date back to the 1940s, with the U.S. military's Electrical Numerical Integrator and Computer (ENIAC) as an early example. Data centers have different models depending on their workloads.”

How it changed

Published 1 time since Oct 11, 2026.

  1. Version 2Oct 11, 2026Live now

    AI-prepared Starting Map from live research.

    • First published version.
Every version, side by side

Help improve it

The brief is open about what's uncertain. These are the specific gaps that new material would fill.

  • “How 'attack' is defined in law” rests on one independent source

    A second, independent source that confirms or challenges it would make this part more reliable.

Open questions

  • How long do service suspensions last after a strike on a data centre, and how many users or downstream services are affected?

    No answers yet

  • What do recovery and rebuilding cost the operator, and who bears that cost?

    No answers yet

  • Do these attacks cause data loss or corruption, or mainly availability outages?

    No answers yet

  • How do physical strikes and cyber operations differ in the scale and duration of impact on internet services?

    No answers yet

  • What contractual or service-level consequences fall on cloud customers when their provider's facility is attacked?

    No answers yet

Around this topic

Sylos connect: narrower topics report up to broader ones, so what's learned in one place shows up where it matters.

Ask this Sylo

Answers only from “How do attacks on data centres affect internet services and the companies that run them?”

Ask anything about this page. The AI reads only its reviewed brief, sources and contributions, cites what it used, and says when the page doesn't cover something.