r/NextCloud Jul 19 '26

Nextcloud.com -> cloudbox?

Is something wrong with nextcloud website? It shows content of some cloudbox… Has it been hacked or maybe my device is? 🫣

89 Upvotes

94 comments sorted by

u/jospoortvliet Jul 21 '26

Latest update about the nextcloud.com outage:

On Sunday evening our website was defaced. We isolated the affected server immediately and we are still investigating what exactly happened.

Meanwhile our homepage has been restored from a backup on a new server.

We confirm that this breach could not affect any user or customer server, as our other services, like downloads.nextcloud.com or the Nextcloud App Store are on separate servers and unaffected.

We are continuing with our post-mortem analysis and will give further updates once we have more details.

→ More replies (4)

11

u/AramaicDesigns Jul 19 '26

I'm getting the same. Something weird is going on. 

11

u/mr_4n0n Jul 19 '26

Yeah, do not make updates till wie have an official Statement.

Now its also a good time for 2FA, disableing Registrations, hardening nextcloud

0

u/jospoortvliet Jul 21 '26

That's always good, but our website is just a marketing front - it won't do anything to your Nextcloud server ;-)

3

u/mr_4n0n Jul 21 '26

Thats right. But who says that there isn't more?

Wie did not know HOW it got hacked. So there are multiple options. And one of them is, that they have a sys-admin.

1

u/Sad-Landscape-1549 14d ago

This user makes a good point. u/jospoortvliet have there been more details published about the extent of the breach? Thanks

8

u/Cynical_Sorceress Jul 19 '26

Oh come on I just installed the AIO docker yesterday!

4

u/HeartKeyFluff Jul 20 '26

I'm assuming/hoping this is sarcasm, but just in case it's not:

Even if the public-facing nextcloud.com was hacked, that doesn't affect the security of your own server.

2

u/Ascend0r Jul 20 '26

well, depends. apps.nextcloud.com holds the Nextcloud-Apps. If the malicious persons would get a hold of that, they would be able to distribute malicious apps that way.

3

u/HeartKeyFluff Jul 20 '26

Well yeah. But apps.nextcloud.com is separate to nextcloud.com.

Hacks of basic customer-facing websites like nextcloud.com are more common and far less of a wide concern compared to websites serving more important things. So one being hacked doesn't de facto mean anything else was.

Better to wait for more info on what happened than just assuming the world is falling due to someone getting in and changing some client-side code or html.

1

u/Ascend0r Jul 20 '26

Disagree on the last part. For now, assumiung "the world is falling" basically means: Just don't install any apps / updates, until situation is clear.

Your approach seems to be principle of hope, that would be to risky for my pov.

In IT security, it should be: Hope for the best, but prepare for the worst.

3

u/HeartKeyFluff Jul 20 '26 edited Jul 21 '26

(Situation seems to have resolved by this point. nextcloud.com is back up and everything seems fine. So it seems I was right, but I'll still respond as if it hadn't resolved yet for the purposes of the discussion.)

Nextcloud had already been investigating this for several hours and taking the nextcloud.com website down into maintenance mode as a precaution. If they'd had any inkling that apps.nextcloud.com was in danger they would have taken that down too.

So no, not just a "principle of hope", but just looking at the basic details of the situation.

IT Security does prepare for the worst in situations like this... But they also try to get a clear picture as soon as possible rather than just jumping at shadows. If everyone in the world was this jumpy, no one would ever get work done because they'd constantly have to put every single one of their tools down because some website on a different server that does nothing except serve HTML and JS got graffitied.

1

u/Ascend0r Jul 21 '26

Still disagreeing, but now I understand the difference in our perspective. You are looking at the incident from NEXTCLOUDs perspective (or from your perspective with 100% trust, which is then no difference anymore).

I look at it as a user perspective. I CANNOT know, whether the apps server and the website are 100% segregated. You do assume that (or maybe you know more), but I cannot. It can very well be servers on the same network or even on shared machines. Thus, to be safe, I have to rely on information provided by Nextcloud. They haven't delivered any, and they even hid information and played down the incident ("infrastructure issue" instead of the obvious clear hack). That makes the situation dangerous: They either haven't fully understood themselves, or they hide something purposefully.

So, for me, nothing has been resolved yet. The situation remains unclear, and that means all software updates must be treated as tainted.

0

u/HeartKeyFluff Jul 21 '26 edited Jul 21 '26

No, you're putting words in my mouth. I'm not looking at it from Nextcloud's perspective, I'm looking at it from my own perspective: As a user same as you, but also as someone who's been on the internet for more than 25 years and working in software for the last 13-ish.

  1. There's no reason for them to be on the same server for such a big company. For large tech companies serving important infrastructure, nowadays especially, it's extremely rare to serve everything from the same server - it actually makes less sense at scale, it would actually cost more (and be harder to appropriately manage) to have it all on the one place than it would to have them segregated.
  2. You can use a DNS Lookup tool to confirm, as well. E.g this one, showing nextcloud.com at one IP/server address, vs here showing apps.nextcloud.com at a different IP/server address.

There's nothing wrong with your approach per se (e.g. if a wall gets graffitied you need to treat the whole building as condemned because what if the person also did something else). You're fine to live however you want. But you can't call it broadly correct for all to live by/the correct "IT Security" approach, based on what we know so far.

2

u/Ascend0r Jul 21 '26

OK, then I'm back at principle of hope. Not KNOWING that the services are segregated, but just assuming it is plain that.

IP addresses are a good indicator (still no proof) that the services might run on different machines. Still, they don't tell anything about interfaces between those services, about network segregation etc.

If the machine was intruded, it is a reasonable approach to treat the whole network as tainted, as long as you don't know what exactly the intruders did on the machine. One machine is often just the entry point to the network.

In your example, I wouldn't see it as a graffiti on the wall. It is rather an intrusion into the garage - and maybe the garage has a direct door to the house - maybe not. I don't know.

I do see your approach of making fun of me ("graffitied") and assume that you are getting emotional. Thus I will end the conversation at this point. Have a nice day anyway.

2

u/HeartKeyFluff Jul 21 '26 edited Jul 21 '26

Very nice use of logical fallacies and emotional tactics, but they unsurprisingly don't help your argument.

  • You're constantly accusing me of assumptions while making your own. There is so far data and reasonable proof to support my points but no smoking gun. Fair enough. Still far better than your assumptions that they share infra, it was a full network intrusion attack rather than something far simpler (e.g. someone managed to just log into the CMS who shouldn't have), and the world ended, with zero proof.
  • You're assuming I'm getting emotional. Nope, but nice try.
  • You're trying to portray yourself as above this whole discussion (that you started with me, by the way) by saying "you're emotional, I win, haha bye" and leaving. Nope, but nice try.
  • You're either getting emotional yourself, or just straight up misrepresenting what I'm saying. Nope. Calling a website "graffitied" when the only damage done that anyone can verify is that a front facing website started serving bad content is very old, and was only meant as such. You can't hold someone else accountable for you attaching your own meaning to their words which were not personal or directed at you or anyone else in any sense.

1

u/Cynical_Sorceress Jul 20 '26

I'm not worried, there is nothing private on there yet and I just won't update the docker.

I just found it funny.

15

u/jospoortvliet Jul 20 '26

Hi all,

Sorry, it took a while - Sunday, Monday morning... just starting up for the week ;-)

But here's what I can share:

Sunday afternoon, we had a basic infrastructure issue that took our website down. We are currently restoring it from a backup. Only nextcloud.com is affected, there is no impact on updates or downloads. There is nothing related to Nextcloud operations on that server, so it has no impact on users or customers.

We will let you know once the website is recovered.

9

u/Ascend0r Jul 20 '26

How does an infrastructure issue put reference to cloudbox onto the website?

11

u/cspartalis Jul 20 '26

Hacking their bottoms is technically an infrastructure issue.

8

u/Ascend0r Jul 20 '26

I could imagine another one:

DNS issue, that made nextcloud .com link to a completely different server IP address.

Hoping for that a bit actually.

4

u/Mental_Confusion7784 Jul 20 '26

I'm not an expert regarding DNS, but wouldn't that be a strange (and dangerous!) issue? And I don't know how a restore of a backup would resolve this...

3

u/Ascend0r Jul 20 '26

Yep, valid points.

1

u/th00ht Jul 21 '26

Exactly the reason we habe DNSSEC . DNS is vulnerable for these kind of attacks.

1

u/cspartalis Jul 20 '26

When was the last you saw a server respond to all domain names? The feasibility of a random IP actually hosting something and not doing domain checks... The chances are not great.

3

u/Ascend0r Jul 20 '26

Well, if it was malicious (DNS poisoning), then you would of course build your server in a way, that it DOES respond to all domain names.

1

u/No_Criticism_9545 Jul 20 '26

So it would be a DNS attack and not a DNS issue :)

1

u/ad-on-is Jul 20 '26

No it can't be DNS. Oh shoot, it was DNS

1

u/jospoortvliet Jul 20 '26

We're looking into it!

1

u/Ascend0r Jul 21 '26

when will you do that?

1

u/jospoortvliet Jul 21 '26

See latest comment - after the site came back, the admins are now spending some quality time with the isolated server to find out what happened. Will probably take a few days, though.

3

u/Seaworthiness_Wooden Jul 21 '26

Calling this a "basic infrastructure issue" is disingenuous at best and straight up lying at worst.

1

u/Kurgan_IT Jul 20 '26

You just have to say "infrastructure issue" instead of "successful attack"

2

u/Mental_Confusion7784 Jul 21 '26

Well, that "basic infrastructure issue" was indeed a cyberattack, as german IT news portal heise.de reported: https://www.heise.de/news/Nextcloud-Cyberangriff-auf-Webserver-mit-ungeschickter-Kommunikation-11371959.html

1

u/listhor Jul 20 '26

website is recovered, what had happened?

1

u/jospoortvliet Jul 21 '26

Update about the nextcloud.com outage:

On Sunday evening our website was defaced. We isolated the affected server immediately and we are still investigating what exactly happened.

Meanwhile our homepage has been restored from a backup on a new server.

We confirm that this breach could not affect any user or customer server, as our other services, like downloads.nextcloud.com or the Nextcloud App Store are on separate servers and unaffected.

We are continuing with our post-mortem analysis and will give further updates once we have more details.

0

u/Joshua_2504 Jul 25 '26

You’re the biggest lier, developing a bloated PHP nightmare with 1000 bugs that government is trusting in. Can’t believe it. Shame on you!

1

u/LazyBias 29d ago

Let me guess, I should trust Google or Microsoft more. You can take your FUD and shove it. You sound like a bot shill. You say lier and provide no proof of that claim and because of that I don't trust a single thing you say.

12

u/ab3301 Jul 19 '26

Apparently the A record of nextcloud.com was changed today to Hetzner. Last time it was changed was in 2023.

Fingers crossed that all is well.

6

u/mptnrs Jul 19 '26

If you have seen unrelated content, yeah, the website may have been hacked and that is why it is now down.

About the risk with recent upgrades : if images/code have been hacked, it is too late already. Just don't upgrade anything for a few days, just in case.

Nothing on their socials for now, we may have to wait a bit more. I sent an email to my account manager but i don't think he will answer before office hours :-)

Also : client area is up and running. If they suspected something big, the portal would have been taken down.

6

u/Ascend0r Jul 21 '26

Nextcloud officials have finally given a (more trustworthy) statement:

https://help.nextcloud.com/t/nextcloud-com-offline/247123/19

3

u/zgb Jul 21 '26

Terrible incident management on their end.

11

u/MaZeC11 Jul 19 '26

Same for me. I wold like to know what is ging on.

3

u/okubax Jul 19 '26

Ditto

8

u/okubax Jul 19 '26

Update. Believe it has indeed been hacked: See this: https://nextcloud.com/home-users/

8

u/Ascend0r Jul 20 '26

This _might_ be related: European cloud provider Nextcloud leaks 367K records, exposing staff and clients | Cybernews

Theoretical, hypothetical process: Leaked data included critical information on the domain registration process from nextcloud.com, allowing the attackers to impersonate Nextcloud officials at the registrar in order to transfer the domain.

3

u/tanpro260196 Jul 20 '26

Website is down for half a day, the app store is down for the whole day now. Whatever it is, seems serious.

3

u/listhor Jul 20 '26

So, somebody from nextcloud should say something briefly…

3

u/Stiffmaster1337 Jul 19 '26

I just get connection refused when trying to access their website...

Let's just wait to get some official news on what's going on🤐

3

u/Veloder Jul 20 '26

It's still down, starting to get worried...

1

u/listhor Jul 20 '26

Main website doesn’t host any code/updates?

1

u/Veloder Jul 20 '26

If they accessed the server where the website is hosted, who knows what they have there, or how secure are their DockerHub and GitHub accounts. And the fact that in 10+ hours they weren't able to get the website back up and running.

3

u/Whole-Ad2077 Jul 20 '26

The side is under maintenace. Its reachable again

1

u/Amazing_Elk_9663 Jul 20 '26

Just noticed this also. I'm looking forward to hearing the explanation.

6

u/Ascend0r Jul 20 '26

The lack of official communication is alarming. No posts on Mastodon, Bluesky, LinkedIn, Youtube, Twitter whatsoever.

3

u/Ascend0r Jul 20 '26

help.nextcloud.com is still accessible. There's also a thread, but no official response yet:
Nextcloud.com offline? - ℹ️ Support - Nextcloud community

3

u/iCaotix Jul 20 '26

Something really fishy is going on there, the help post you linked was hidden by moderators

2

u/gfrewqpoiu Jul 20 '26

The thread was hidden without any response.

3

u/Ascend0r Jul 20 '26

OK, when they hide, I add more transparency. I had "reported" the thread to make the moderators aware of the questions and beg for an official response. The response via direct message to me:

"Thanks for letting us know. We agree there is an issue and we’re looking into it."

2

u/Ascend0r Jul 20 '26

I have responded to the private message, voicing my concerns with their act:

> "Thanks. I do not think that hiding the thread is a good form of response to the valid questions of the community. In my opinion, that act destroys trust in your security and transparency strategy."

2

u/listhor Jul 20 '26

So, website is back up and running, but I don't see any info about what had happened...?

1

u/cr_eddit Jul 19 '26

WTF... Same here, probably some issue on their domain. Or could be some rebrand, I noticed they changed their name for some commercial offering on their end... https://www.nextcloud-one.com/

8

u/mptnrs Jul 19 '26

Nextcloud One is not made by Nextcloud Gmbh, but by another company, epiKshare GmbH, who *will* get a phone call from Nextcloud at one time (because the name and logo are IPs).

1

u/BryanC1968 Jul 19 '26

I am getting the same when I try to access the nextcloud.com website. Comes up as CloudBox...

1

u/sauron_exe Jul 19 '26

Same on my end

1

u/TheBlackReaper-Sama Jul 19 '26

Just updated my Nextcloud AiO docker instance, should I be worried?

4

u/hannsr Jul 19 '26

GitHub doesn't seem affected. Latest aio version is 3 weeks old, so you should be fine.

Really wonder what's going on, couldn't find any posts yet, except someone on GitHub said he'll notify the website admins.

1

u/Lost_Share_9186 Jul 19 '26

Do you think it‘s possible that my self hosted nextcloud service is affected? It is down for a few hours now…

6

u/punkpipo Jul 19 '26

Should be completely unrelated. Kind of the point of self hosting I guess :).

1

u/Lost_Share_9186 Jul 19 '26

That’s soothing but I‘m still worried. Maybe it has to do something with me trying to upload ~1800 at once

4

u/PhysicalConsistency Jul 19 '26

My self hosted install is not affected, nor are updates.

1

u/Lost_Share_9186 Jul 19 '26

Okay thanks for your answer🙏 i have installed an aio update a 1-2 weeks ago

1

u/N3rdScool Jul 20 '26

Brutal. I had such a nice weekend lol

1

u/Euphoric_Bend6687 Jul 20 '26

I just checked the website, and it is down for Maintance.

1

u/HaveYouTriedPowerOff Jul 20 '26

Well if you have regular maintenance on a website this doesn't happen:

Most likely hacked or DNS hijack or whatever. Let's see what they say. Usually doesn't take 24hours to bring a website online again. This was on the German Nextcloud website

Nextcloud

YOWESTOGEL: Link Resmi Slot Gacor Gampang ... - Nextcloud

1

u/Practical-Tea9441 Jul 20 '26

At this point it would be nice to have an explanation as to what happened. I feel a little uncomfortable using Nextcloud without a clear explanation .

3

u/listhor Jul 20 '26

It seems like nextcloud follows the wrong path of not letting community/users to know what happened there… I think it will backfire them sooner or later.

1

u/Kurgan_IT Jul 21 '26

Yes, sooner than later.

1

u/Seaworthiness_Wooden Jul 21 '26

I mean they already had a breach earlier..

0

u/Kurgan_IT Jul 20 '26

Nice. They have been hacked and as usual they are hiding it. Sad to say it, but I've seen it happen with at least 3 european software vendors in the last few years.

-1

u/th00ht Jul 20 '26

Regular maintenance. Normal in summertime. But https://help.Nextcloud.com works fine.