CyrusOne Aurora Cooling Failure Halts CME Group Trading (November 2025)
A human-error cooling-tower switchover during a cold-weather changeover triggered a chiller-plant failure and temperatures above 100°F at CyrusOne's Aurora facility, halting CME Group's global futures and options trading for more than ten hours.
Failure cascade
Trigger → primary fault → downstream blast radius, derived from the sourced root cause and affected-services record.
Facility & location
- Operator
- CyrusOne (tenant: CME Group)
- Data center
- CyrusOne Aurora (Chicago-area)
- Location
- Aurora, Illinois, United States
- Date
- 2025-11-01
Impact & scale
- Users affected
- Global derivatives market participants; CME futures/options across equities, rates, FX, commodities
- Financial
- Market-wide trading halt; direct loss not published
- Scope
- Sev-1 facility cooling loss (>10h trading halt)
- CME Globex futures/options trading
- Market data feeds
Impact data & metrics
| Total outage duration | ~11 hours (reported 'over 11 hours') |
| Cooling units affected | 'multiple cooling units' (common-mode; exact count not disclosed) |
| Aurora campus IT capacity | 109 MW across 3 data centers, 450,000 sq ft |
| Corrective capacity added | 'additional redundancy to the cooling systems' (tonnage not disclosed) |
| Peak data-hall temperature (reported) | >100degF (UNVERIFIED - not disclosed by CyrusOne; from a secondary incident summary) |
| EBS markets resume time | ~07:00 ET, 2025-11-28 (not independently reconfirmed) |
| Full market reopen time | ~08:30 ET, 2025-11-28 (not independently reconfirmed) |
| Aurora sale-leaseback (2016) | ~$130 million, 15-year term (UNVERIFIED facility-profile detail) |
| Financial fallout | CyrusOne reportedly postponed/halted a bond sale after the failure |
Magnitude profile
Global futures/options market halt >10h from a cooling-plant failure — sub-scores ESTIMATED from public impact reporting, pending deep research.
Sequence of events (SOE)
- TRIGGER On the live approach to a hard freeze in the Chicago suburbs (Thanksgiving-window reopen), onsite staff and contractors began preparing/draining CHI1's cooling towers for freezing weather but failed to follow standard procedures for the winterization changeover (CyrusOne, confirmed to Bloomberg).
- CASCADE The procedural lapse induced a chiller-plant failure: CHI1 'experienced a chiller plant failure affecting multiple cooling units' - a common-mode trip taking more than one unit offline at once.
- CASCADE Chilled-water circulation to the data halls was lost; against ~109MW of IT capacity with low thermal mass, rack-inlet/room temperatures began climbing (a widely-cited summary reports >100degF; not disclosed by CyrusOne).
- DETECTION Thermal detection (not fire): plant/building monitoring (BMS/DCIM) and rising room/rack temperatures would have driven high-temperature alarms as the chiller plant failed. No accessible source states the exact minute the high-temp threshold tripped.
- MITIGATION Protective compute shutdown: to stop generating heat and protect hardware, CME's trading systems (Globex and related markets) were halted/failed over - an 'evacuation of compute' rather than any occupant evacuation (unmanned mechanical failure, no life-safety event).
- IMPACT Global markets knocked out: the halt prevented traders from accessing futures prices for commodities and stocks across CME Group's derivatives markets (specific benchmark list per trade reporting: S&P 500, Nasdaq, Treasuries, WTI, gold, Nikkei, palm oil - not independently reconfirmed).
- MITIGATION CME issued a public notice that its markets were halted due to a cooling issue at the CyrusOne data center and that it was working to resolve the issue (exact wording attributed to trade reporting, not independently reconfirmed).
- MITIGATION Emergency MECHANICAL response (no fire department / 911): CyrusOne mobilized engineering teams and contractors on-site to restart chillers and reconstitute chilled-water circulation.
- MITIGATION No suppression discharge occurred or was needed (no fire); the 'suppression analogue' - the cooling plant - had failed. Redundancy/backup cooling did not carry the load, forcing an orderly thermal de-rating/shutdown of IT.
- RECOVERY Chillers restarted at limited capacity and cooling reconstituted to rebuild chilled-water circulation to a stable state (any 'temporary/supplemental chillers and pipework' detail is attributed to DC Pulse and is unverified).
- RECOVERY EBS markets resumed trading as chilled-water circulation stabilized enough to bring IT load back safely (resume time per CNBC; not independently reconfirmed).
- RESTORED Stock futures and options trading fully reopened; CME reported all its markets were open and trading (per CNBC; not independently reconfirmed).
- RESTORED Trading in FX, stock and bond futures had resumed after being knocked out for roughly/over 11 hours; regulators (CFTC and SEC) reportedly aware and monitoring (per Reuters; not independently reconfirmed).
- RECOVERY CyrusOne reported it had 'restored stable and secure operations at its Chicago 1 (CHI1) data center in Aurora, Illinois' and 'installed additional redundancy to the cooling systems.'
- IMPACT Financial/reputational fallout: CyrusOne reportedly postponed/halted a bond sale after the data-center failure that disrupted CME, and confirmed to Bloomberg the ~11-hour outage was caused by human error.
Root cause
Contributing factors
- PROCEDURAL EXECUTION FAILURE DURING FREEZE-PREP (root, CONFIRMED): CyrusOne confirmed to Bloomberg that onsite staff and contractors failed to follow standard procedures when draining/preparing the cooling towers ahead of freezing weather (via DatacenterDynamics) - a seasonal cold-weather changeover mishandled on the live approach to a hard freeze.
- INADEQUATE / COMMON-MODE MECHANICAL REDUNDANCY: a single procedural lapse took 'multiple cooling units' offline at once with no backup cooling carrying the load, evidenced by CyrusOne's post-incident fix of having 'installed additional redundancy to the cooling systems' (confirmed verbatim via DCD) - i.e. the fault-tolerant protection a resilient plant should have provided was effectively absent for this failure mode.
- COLD-WEATHER / SEASONAL-TRANSITION TIMING RISK: the failure hit during a hard-freeze approach in the Chicago suburbs on the Thanksgiving-window reopen (evening of Nov 27, into Nov 28), a known high-risk winterization window for water-cooled tower plants, executed under live IT load (CyrusOne statement; DCD).
- SINGLE-SITE CONCENTRATION OF CRITICAL WORKLOAD: CME's matching engines ran from the single Aurora campus, so one plant's thermal failure halted global futures/options price discovery - a concentration-risk / missing geographic-diversity theme raised in trade commentary (attributed to DC Pulse; that specific commentary could not be independently re-fetched).
- CONTRACTOR-BOUNDARY / CHANGE-MANAGEMENT GAP: the lapse spanned both onsite personnel and contractors, implying a method-statement / supervision boundary where the freeze-prep steps were not verified - though no accessible source names the specific procedure document, the contracting firm, or which checklist step was skipped (disclosed uncertainty; CyrusOne via Bloomberg/DCD).
Correction of errors (COE)
- Rebuild cooling-tower freeze-prep/winterization SOP as a checklist-gated changeover with independent two-person sign-off and seasonal dry-run
- Install additional redundancy to the CHI1 cooling systems
- Restore stable and secure operations at CHI1 Aurora
- Impose change-management controls (method statements, supervision, two-person verify) at the contractor boundary for live freeze-prep
- Pursue geographically diverse cooling/power architecture for critical matching engines and review single-site concentration
- Wire thermal early-warning to automated IT load-shed thresholds (BMS/DCIM)
- Regulatory awareness and market-integrity review of the outage
Lessons learnt
- A cooling plant is a single point of failure equal to any power system: a mishandled seasonal winterization step - not equipment age or a fire - halted a global exchange for ~11 hours, so freeze-prep is a critical, life-of-the-facility procedure, not routine maintenance.
- Redundancy that shares a common human/procedural mode is not redundancy: one mis-sequenced changeover took 'multiple cooling units' offline together, and the operator's after-the-fact addition of redundancy is proof the pre-incident backup path did not carry the load.
- Concentration risk is systemic risk: running globally-critical matching engines from one campus means one plant's thermal failure becomes worldwide market downtime - geographic diversity is a resilience requirement, not a luxury.
- Contractor-boundary work needs the tightest change control: because the lapse spanned staff and contractors, method statements, supervision, and independent verification must gate any live-load seasonal switchover.
- Detection must be wired to protection: rising hall temperatures should auto-trigger load-shed/throttling before safe inlet limits are crossed, rather than relying on a downstream tenant (CME) to halt compute to save the hardware.
- Public disclosure was partial: the operator confirmed human error and 'multiple cooling units' but never released chiller counts, refrigerant, peak sensor temperatures, or mobile-cooling tonnage - post-incidents should not be reconstructed as if those undisclosed specifics are established fact.
Improvements & remediation
- MaintenanceRebuild the cooling-tower freeze-prep / winterization procedure as a verified, checklist-gated seasonal changeover with independent two-person sign-off - CyrusOne's own confirmed root cause is that staff and contractors failed to follow standard procedures when draining/preparing the cooling towers ahead of freezing weather, so procedure EXECUTION and verification, not just the document, must be hardened.
- DesignProvide genuine common-mode-resistant mechanical redundancy (N+1/N+2 with procedurally diverse changeover steps) plus pre-staged rapid-response mobile cooling - implementing the very fix CyrusOne applied after the fact (it 'installed additional redundancy to the cooling systems').
- ProcessInstitute change-management controls at the contractor boundary for any live freeze-prep switchover - approved method statements, on-site supervision, and a two-person verify step - since the lapse spanned both onsite personnel and contractors and no verification caught the mis-sequenced changeover before multiple units tripped.
- SafetyTighten thermal early-warning and automated load-shed thresholds (BMS/DCIM high-temp alarms tied to protective IT throttling) so a chiller-plant trip is caught and heat load shed before halls exceed safe inlet temperatures - closing detection-to-protection latency.
- Design/Resilience: For globally-critical workloads such as exchange matching engines, pursue redundant, geographically diverse cooling and power architectures so a single site's thermal failure cannot halt worldwide price discovery.
- Maintenance/Assurance: Run a pre-winter commissioning and dry-run of the full freeze-prep sequence each season, with an independent audit of tower drain-down, basin-heater energization, and free-cooling/glycol valve line-ups before the first hard freeze.
Comprehensive analysis
What happened
On the evening of Nov 27, 2025 (into Nov 28), CyrusOne's CHI1 (Chicago 1 / 'CH1') data center in Aurora, Illinois 'experienced a chiller plant failure affecting multiple cooling units' (CyrusOne, confirmed via DatacenterDynamics). Chilled-water cooling to the halls was lost as a hard freeze approached the Chicago suburbs, and CME Group - a tenant whose trading engines run from the campus - halted its markets to protect hardware. Trading resumed after roughly 11 hours. This was a loss-of-cooling (thermal) event, not a fire: there was no ignition, combustion, or suppression discharge.
Why it happened (root and latent causes)
CyrusOne confirmed to Bloomberg the outage was caused by human error - onsite staff and contractors failed to follow standard procedures when draining/preparing the cooling towers ahead of freezing weather. Beneath that sit two latent gaps: (1) common-mode redundancy failure, since one mis-sequenced changeover took 'multiple cooling units' down together with no effective backup path - later confirmed by CyrusOne 'installing additional redundancy to the cooling systems'; and (2) single-site concentration of globally-critical workload. No chiller make/model, refrigerant, unit age, or exact hydraulic detail was disclosed.
Why it mattered (impact and concentration risk)
Because CME's matching engines run from the single Aurora campus, a plant-level thermal failure became worldwide market downtime - traders lost access to futures prices for commodities and stocks across CME Group's derivatives markets for ~11 hours. Trade reporting listed benchmarks including S&P 500, Nasdaq, Treasuries, WTI, gold, Nikkei and palm oil (not independently reconfirmed here). The event also carried financial/reputational fallout: CyrusOne reportedly postponed a bond sale afterward (Bloomberg; not independently reconfirmed).
Response and recovery
There was no suppression system to activate - the cooling plant itself was the failed 'suppression analogue.' Recovery was mechanical and manual: chillers were restarted at limited capacity and chilled-water circulation reconstituted until IT - and CME's markets - could be brought back in stages (EBS ~07:00 ET, full reopen ~08:30 ET per CNBC, not reconfirmed). CyrusOne then reported it 'restored stable and secure operations at its Chicago 1 (CHI1) data center' and 'installed additional redundancy to the cooling systems' (both confirmed verbatim).
Verification status and source limitations
This review directly re-confirmed, via a reader-proxy to DatacenterDynamics relaying CyrusOne's statements: the CHI1/Aurora location, the 'chiller plant failure affecting multiple cooling units' phrasing, the human-error root cause tied to cooling-tower freeze-prep, the ~11-hour duration, the 109MW / 450,000 sq ft / 3-DC campus profile, and the two CyrusOne quotes on restored operations and added redundancy. It could NOT re-fetch Bloomberg, Reuters, CNBC or DC Pulse (bot-block/CAPTCHA) - so precise resume times, the CFTC/SEC line, the benchmark product list, the bond-sale detail, the $130M/15-year sale-leaseback, the >100degF temperature, and the 'temporary and supplemental chillers and pipework' phrase remain cited-but-not-independently-reconfirmed and, where noted, unverified.
Technical deep-dive
References & provenance
- press DatacenterDynamics - CME data-center shutdown attributable to human error (relaying CyrusOne/Bloomberg)“a chiller plant failure affecting multiple cooling units; staff and contractors failed to follow standard procedures when draining cooling towers ahead of freezing weather”https://www.datacenterdynamics.com/en/news/cme-data-center-shutdown-attributable-to-human-error-report/
- press DatacenterDynamics - After CME outage, CyrusOne adds backup cooling capacity (relaying CyrusOne)“CyrusOne has restored stable and secure operations at its Chicago 1 (CHI1) data center in Aurora, Illinois”https://www.datacenterdynamics.com/en/news/after-cme-outage-cyrusone-adds-backup-cooling-capacity/
Sourced from public post-incident reports. Quotes are short attributed excerpts for provenance only; the analysis above is original and substantially shorter than its sources. Last verified 2026-08-02 (seed — pending deep research).