← All incidents
Incident dossier · Rank #29

CyrusOne Aurora Cooling Failure Halts CME Group Trading (November 2025)

CyrusOne (tenant: CME Group) 2025-11-01 11h 0m core impact CoolingHuman error

A human-error cooling-tower switchover during a cold-weather changeover triggered a chiller-plant failure and temperatures above 100°F at CyrusOne's Aurora facility, halting CME Group's global futures and options trading for more than ten hours.

Failure cascade

Failure cascade: trigger → fault → downstream impactTriggerPrimary faultDownstream impactTrigger — Cooling (2025-11-01)Trigger · Cooling2025-11-012025-11-01Primary fault at CyrusOne (tenant: CME Group) — CyrusOne Aurora (Chicago-area)CyrusOneCyrusOne Aurora (Chicago-area)CyrusOne AuroraDownstream service degraded by the fault: CME Globex futures/options tradingCME Globex futures/optionstrading…Downstream service degraded by the fault: Market data feedsMarket data feeds

Trigger → primary fault → downstream blast radius, derived from the sourced root cause and affected-services record.

Facility & location

Operator
CyrusOne (tenant: CME Group)
Data center
CyrusOne Aurora (Chicago-area)
Location
Aurora, Illinois, United States
Date
2025-11-01

Impact & scale

Users affected
Global derivatives market participants; CME futures/options across equities, rates, FX, commodities
Financial
Market-wide trading halt; direct loss not published
Scope
Sev-1 facility cooling loss (>10h trading halt)
Services / systems down
  • CME Globex futures/options trading
  • Market data feeds

Impact data & metrics

Total outage duration~11 hours (reported 'over 11 hours')
Cooling units affected'multiple cooling units' (common-mode; exact count not disclosed)
Aurora campus IT capacity109 MW across 3 data centers, 450,000 sq ft
Corrective capacity added'additional redundancy to the cooling systems' (tonnage not disclosed)
Peak data-hall temperature (reported)>100degF (UNVERIFIED - not disclosed by CyrusOne; from a secondary incident summary)
EBS markets resume time~07:00 ET, 2025-11-28 (not independently reconfirmed)
Full market reopen time~08:30 ET, 2025-11-28 (not independently reconfirmed)
Aurora sale-leaseback (2016)~$130 million, 15-year term (UNVERIFIED facility-profile detail)
Financial falloutCyrusOne reportedly postponed/halted a bond sale after the failure

Magnitude profile

Magnitude sub-scores (0–10)Magnitude sub-scores (0–10)Users 6Users affected (0–10) — breadth of the user/customer population impacted. — scored 6/10.Financial 8Financial impact (0–10) — direct + consequential cost. — scored 8/10.Duration 6Outage duration (0–10) — how long service was degraded/down. — scored 6/10.Blast 7Blast radius (0–10) — how wide the fault propagated across systems/regions. — scored 7/10.
Magnitude 6.8 = blast 7×0.35 + users 6×0.25 + financial 8×0.20 + duration 6×0.20 (sub-scores 0–10 · weighted composite)

Global futures/options market halt >10h from a cooling-plant failure — sub-scores ESTIMATED from public impact reporting, pending deep research.

Sequence of events (SOE)

Phased sequence of events2025-11-27 evening (CT) · TRIGGER — On the live approach to a hard freeze in the Chicago suburbs (Thanksgiving-window reopen), onsite staff and contractors began preparing/draining CHI1's cooling towers for freezing weather but failed to follow standard procedures for the winterization changeover (CyrusOne, confirmed to Bloomberg).TRIGGER2025-11-27 evening (C2025-11-27 evening (CT) · CASCADE — The procedural lapse induced a chiller-plant failure: CHI1 'experienced a chiller plant failure affecting multiple cooling units' - a common-mode trip taking more than one unit offline at once.CASCADE2025-11-27 evening (C2025-11-27 evening (CT) · CASCADE — Chilled-water circulation to the data halls was lost; against ~109MW of IT capacity with low thermal mass, rack-inlet/room temperatures began climbing (a widely-cited summary reports >100degF; not disclosed by CyrusOne).CASCADE2025-11-27 evening (C2025-11-27 late evening (CT) · DETECTION — Thermal detection (not fire): plant/building monitoring (BMS/DCIM) and rising room/rack temperatures would have driven high-temperature alarms as the chiller plant failed. No accessible source states the exact minute the high-temp threshold tripped.DETECTION2025-11-27 late evening (C2025-11-27 late evening (ET) · MITIGATION — Protective compute shutdown: to stop generating heat and protect hardware, CME's trading systems (Globex and related markets) were halted/failed over - an 'evacuation of compute' rather than any occupant evacuation (unmanned mechanical failure, no life-safety event).MITIGATION2025-11-27 late evening (E2025-11-27/28 overnight · IMPACT — Global markets knocked out: the halt prevented traders from accessing futures prices for commodities and stocks across CME Group's derivatives markets (specific benchmark list per trade reporting: S&P 500, Nasdaq, Treasuries, WTI, gold, Nikkei, palm oil - not independently reconfirmed).IMPACT2025-11-27/28 ov2025-11-27/28 overnight · MITIGATION — CME issued a public notice that its markets were halted due to a cooling issue at the CyrusOne data center and that it was working to resolve the issue (exact wording attributed to trade reporting, not independently reconfirmed).MITIGATION2025-11-27/28 ov2025-11-27/28 overnight · MITIGATION — Emergency MECHANICAL response (no fire department / 911): CyrusOne mobilized engineering teams and contractors on-site to restart chillers and reconstitute chilled-water circulation.MITIGATION2025-11-27/28 ov2025-11-27/28 overnight · MITIGATION — No suppression discharge occurred or was needed (no fire); the 'suppression analogue' - the cooling plant - had failed. Redundancy/backup cooling did not carry the load, forcing an orderly thermal de-rating/shutdown of IT.MITIGATION2025-11-27/28 ov2025-11-28 early hours · RECOVERY — Chillers restarted at limited capacity and cooling reconstituted to rebuild chilled-water circulation to a stable state (any 'temporary/supplemental chillers and pipework' detail is attributed to DC Pulse and is unverified).RECOVERY2025-11-28 early2025-11-28 ~07:00 ET · RECOVERY — EBS markets resumed trading as chilled-water circulation stabilized enough to bring IT load back safely (resume time per CNBC; not independently reconfirmed).RECOVERY2025-11-28 ~07:00 E2025-11-28 ~08:30 ET · RESTORED — Stock futures and options trading fully reopened; CME reported all its markets were open and trading (per CNBC; not independently reconfirmed).RESTORED2025-11-28 ~08:30 E2025-11-28 by ~13:35 GMT · RESTORED — Trading in FX, stock and bond futures had resumed after being knocked out for roughly/over 11 hours; regulators (CFTC and SEC) reportedly aware and monitoring (per Reuters; not independently reconfirmed).RESTORED2025-11-28 by ~13:35 GM2025-11-28 onward · RECOVERY — CyrusOne reported it had 'restored stable and secure operations at its Chicago 1 (CHI1) data center in Aurora, Illinois' and 'installed additional redundancy to the cooling systems.'RECOVERY2025-11-28 onwar2025-12 (early) · IMPACT — Financial/reputational fallout: CyrusOne reportedly postponed/halted a bond sale after the data-center failure that disrupted CME, and confirmed to Bloomberg the ~11-hour outage was caused by human error.IMPACT2025-12 (early)

Root cause

PRIMARY EQUIPMENT / FAILURE MECHANISM. This was a loss-of-cooling (thermal) event, not a fire — no ignition source, no combustion. The failed system was the primary water-cooled CHILLER PLANT serving CyrusOne's CHI1 (Chicago 1 / "CH1") data center in Aurora, Illinois. In CyrusOne's own words the CHI1 facility "experienced a chiller plant failure affecting multiple cooling units" (CyrusOne statement, relayed by DatacenterDynamics). Multiple cooling units dropped offline together, chilled-water circulation to the data halls was lost, and rack-inlet/room temperatures rose until CME Group's trading engines had to be halted to protect hardware. STATED ROOT CAUSE — HUMAN / PROCEDURAL (CONFIRMED). CyrusOne confirmed to Bloomberg that the ~11-hour outage was caused by human error: onsite staff and contractors failed to follow standard procedures when DRAINING/PREPARING the cooling towers ahead of freezing weather (CyrusOne to Bloomberg, via DatacenterDynamics). It occurred on the Thanksgiving-window reopen (evening of Nov 27, 2025, into Nov 28) as a hard freeze approached the Chicago suburbs. The confirmed mechanism is specifically the cooling-tower freeze-preparation/draining step being mishandled — which cascaded into a chiller-plant trip taking multiple cooling units offline. The fault sits in operating-procedure execution during a seasonal cold-weather changeover, not equipment age or a design defect. NOTE: the widely-repeated exact phrasing "preparing the cooling towers for freezing temperatures" is a paraphrase; the confirmed source wording describes staff/contractors failing to follow standard procedures when DRAINING cooling towers ahead of freezing weather. LATENT / SYSTEMIC ROOT. First, MECHANICAL REDUNDANCY DID NOT CARRY THE LOAD: a single procedural lapse during freeze-prep took "multiple cooling units" down at once with no effective backup cooling path — a common-mode failure that a fault-tolerant plant with procedurally diverse changeover steps should have survived. CyrusOne's own remedy — it "installed additional redundancy to the cooling systems" (CyrusOne, confirmed verbatim via DCD) — is an admission that pre-incident backup cooling did not save the load. Second, CONCENTRATION RISK: CME ran globally-critical matching engines out of the single Aurora campus, so one plant's thermal failure halted worldwide futures/options price discovery. No chiller make/model, refrigerant, unit age, or the exact hydraulic detail (frozen tower basin, condenser-water freeze, free-cooling/glycol changeover valve, or low-ambient lockout) has been publicly disclosed — the confirmed record stops at the mishandled cooling-tower freeze-preparation.

Contributing factors

Correction of errors (COE)

Lessons learnt

Improvements & remediation

Comprehensive analysis

What happened

On the evening of Nov 27, 2025 (into Nov 28), CyrusOne's CHI1 (Chicago 1 / 'CH1') data center in Aurora, Illinois 'experienced a chiller plant failure affecting multiple cooling units' (CyrusOne, confirmed via DatacenterDynamics). Chilled-water cooling to the halls was lost as a hard freeze approached the Chicago suburbs, and CME Group - a tenant whose trading engines run from the campus - halted its markets to protect hardware. Trading resumed after roughly 11 hours. This was a loss-of-cooling (thermal) event, not a fire: there was no ignition, combustion, or suppression discharge.

Why it happened (root and latent causes)

CyrusOne confirmed to Bloomberg the outage was caused by human error - onsite staff and contractors failed to follow standard procedures when draining/preparing the cooling towers ahead of freezing weather. Beneath that sit two latent gaps: (1) common-mode redundancy failure, since one mis-sequenced changeover took 'multiple cooling units' down together with no effective backup path - later confirmed by CyrusOne 'installing additional redundancy to the cooling systems'; and (2) single-site concentration of globally-critical workload. No chiller make/model, refrigerant, unit age, or exact hydraulic detail was disclosed.

Why it mattered (impact and concentration risk)

Because CME's matching engines run from the single Aurora campus, a plant-level thermal failure became worldwide market downtime - traders lost access to futures prices for commodities and stocks across CME Group's derivatives markets for ~11 hours. Trade reporting listed benchmarks including S&P 500, Nasdaq, Treasuries, WTI, gold, Nikkei and palm oil (not independently reconfirmed here). The event also carried financial/reputational fallout: CyrusOne reportedly postponed a bond sale afterward (Bloomberg; not independently reconfirmed).

Response and recovery

There was no suppression system to activate - the cooling plant itself was the failed 'suppression analogue.' Recovery was mechanical and manual: chillers were restarted at limited capacity and chilled-water circulation reconstituted until IT - and CME's markets - could be brought back in stages (EBS ~07:00 ET, full reopen ~08:30 ET per CNBC, not reconfirmed). CyrusOne then reported it 'restored stable and secure operations at its Chicago 1 (CHI1) data center' and 'installed additional redundancy to the cooling systems' (both confirmed verbatim).

Verification status and source limitations

This review directly re-confirmed, via a reader-proxy to DatacenterDynamics relaying CyrusOne's statements: the CHI1/Aurora location, the 'chiller plant failure affecting multiple cooling units' phrasing, the human-error root cause tied to cooling-tower freeze-prep, the ~11-hour duration, the 109MW / 450,000 sq ft / 3-DC campus profile, and the two CyrusOne quotes on restored operations and added redundancy. It could NOT re-fetch Bloomberg, Reuters, CNBC or DC Pulse (bot-block/CAPTCHA) - so precise resume times, the CFTC/SEC line, the benchmark product list, the bond-sale detail, the $130M/15-year sale-leaseback, the >100degF temperature, and the 'temporary and supplemental chillers and pipework' phrase remain cited-but-not-independently-reconfirmed and, where noted, unverified.

Technical deep-dive

MECHANISM OF A COLD-WEATHER CHILLER-PLANT FAILURE. Paradoxically, this data-center thermal event was triggered by COLD, not heat. Water-cooled chiller plants reject heat through cooling towers that evaporate water to open air. When ambient temperatures approach and cross freezing, exposed condenser-water in tower basins, fill, and outdoor pipework can freeze, and the plant must be transitioned for cold weather — basins drained or heated, valves switched to free-cooling/glycol loops, flows and setpoints reconfigured — following a defined freeze-prep procedure. CyrusOne's confirmed account is that this changeover was executed incorrectly by onsite personnel and contractors who failed to follow standard procedures when preparing/draining the cooling towers ahead of freezing weather, and that this procedural lapse produced a chiller-plant failure affecting multiple cooling units (CyrusOne to Bloomberg, via DCD). The word "multiple" is the critical forensic signal: this was a COMMON-MODE trip, in which one mis-sequenced changeover simultaneously compromised more than one unit rather than a single random component failure that redundancy could absorb. THERMAL CASCADE INTO IT. Data halls have low thermal mass relative to their heat load; against the campus's 109MW IT capacity, tens of megawatts of server heat with no chilled water raises room and rack-inlet temperatures within minutes. A widely-cited incident summary reports hall temperatures exceeding 100°F, but CyrusOne did NOT disclose a per-sensor peak — treat >100°F as an unverified reported figure, not a confirmed measurement. As inlet air crossed safe thresholds, the correct protective response is exactly what happened: shed the heat source. CME halted its trading systems — effectively an "evacuation of compute" — to stop generating heat and protect hardware while cooling was reconstituted, rather than risk mass server thermal damage. RECONSTITUTION OF COOLING. There was no suppression system to activate because there was no fire; the "suppression analogue" — the cooling plant — was the very thing that failed. Recovery was mechanical and manual: chillers were restarted at limited capacity and cooling reconstituted until chilled-water circulation was stable enough to bring IT load — and CME's markets — back online in stages, with all trading resumed after roughly 11 hours. CyrusOne subsequently "installed additional redundancy to the cooling systems" and reported it "restored stable and secure operations" at CHI1 (both confirmed verbatim via DCD). NOTE ON UNCERTAINTY: no accessible primary source gives the exact minute the high-temperature threshold tripped, the peak hall temperature by sensor, the number of chillers affected versus total installed, or any mobile-chiller tonnage; the phrase "temporary and supplemental chillers and pipework" is attributed to a secondary trade blog (DC Pulse) that could not be re-fetched and does NOT appear in CyrusOne's DCD-relayed statement, so it is treated as unverified.

References & provenance

Sourced from public post-incident reports. Quotes are short attributed excerpts for provenance only; the analysis above is original and substantially shorter than its sources. Last verified 2026-08-02 (seed — pending deep research).

Root access required

The DC Incidents dossier is a root-only module. Sign in with an authorized account to continue.

Back to Home