-
Nextcloud confirmed that hackers breached its main website after first calling the outage an infrastructure issue.
-
Some users saw Nextcloud.com links redirect to a website called “Cloudbox” before the main site went offline.
-
The company says the attack did not affect its main services, software downloads, or update systems.
Nextcloud has confirmed that hackers attacked its main website after the company first described the outage as an infrastructure problem. The European open-source platform later admitted that attackers had breached the website.
The company shared the update with Dutch technology news outlet Tweakers. Nextcloud has not explained how the attackers entered the website. It has also not said how much access the hackers gained during the incident.
Attackers hit Nextcloud on Sunday as the website blanks out
The attack started on Sunday when users noticed problems with Nextcloud.com. Some people could not open the website at all. Other users noticed strange activity when they tried to visit links connected to the domain. Some Reddit users reported that Nextcloud.com links briefly sent visitors to a website called “Cloudbox.” The main Nextcloud website later went offline. Similarly, Telegram users worldwide lost access to t.me links after a .ME registry action.
Nextcloud has since started restoring the website from a backup. The company says the attack only affected its website setup. The company also says the breach did not reach the systems that run its main services.
It says customers should not have faced problems using those services. Nextcloud also stated that the attack did not affect software downloads or updates. Users could still get the software and receive updates through the systems that handle those tasks.
However, the company has not shared a full report about the attack. It remains unclear how the hackers gained entry or what they did after getting inside. It also remains unknown how long the attackers had access to the website. Nextcloud has not said whether hackers changed, copied, or removed any information.
Nextcloud works to restore its website
Nextcloud says the affected server does not host the systems needed to operate its main services. The company therefore believes the breach stayed within the public website setup. It also says the incident did not affect customers or the main tools they use. Nextcloud has been working to bring the website back online. The company plans to use a backup as part of that recovery process.
The strange “Cloudbox” redirection remains one of the key details from the incident. Users noticed the redirect before the website became unavailable. Nextcloud has not publicly explained why visitors saw the Cloudbox website. The company has also not confirmed whether the redirect formed part of the attack. The company has not released details about the exact attack method. It has also not confirmed whether the hackers stole any information from the affected server.
The lack of those details means the full size of the incident remains unclear. Nextcloud’s statement about the attack also has not been independently verified. For now, the company maintains that its main services remain safe.
It also says its software download and update systems were not affected. The incident has drawn attention because of Nextcloud’s growing role in Europe. The company offers tools that help people store files and work together online.
Many European governments and public groups have shown more interest in open-source technology. Some organizations also want alternatives to major American technology companies. Microsoft 365 remains one of the biggest platforms in this space.
Nextcloud has become a well-known European option for organizations seeking more control over their digital systems. That makes the attack against its public website notable. However, the company says the hackers did not reach the systems that support its main services.
No evidence links the attack to WordPress vulnerabilities
The timing of the attack has also raised questions about a recent WordPress security issue. Nextcloud’s website uses WordPress. Security researchers recently warned about serious WordPress flaws that attackers could combine to run harmful code on affected websites. The group of flaws is known as “wp2shell.” The issues received fixes shortly before the Nextcloud website incident.
Reports of attackers scanning for vulnerable WordPress websites also appeared around the same period. Public reports also discussed possible attacks involving the flaws. However, there is currently no evidence that hackers used WP2Shell to attack Nextcloud.
The timing may appear similar, but that does not prove that the two events connect. Nextcloud has not said that attackers used the WordPress flaws to enter its website. Security researchers have also not confirmed that link. The exact method used by the attackers remains unknown.
Nextcloud has yet to explain how the hackers entered the server. The company has also not said what the attackers did after gaining access. The incident, therefore, leaves several important questions unanswered.
Investigators would need more information before they could confirm the attack method. The company also needs to determine whether hackers accessed any information stored on the affected server.
It must also establish whether attackers changed anything before the website went offline. For now, Nextcloud says its main services continue to operate normally. The company also says customers, software downloads, and update systems remain unaffected.