Europe

Nextcloud Hacked

Nextcloud Hacked

Nextcloud, the European open-source collaboration suite that governments are eyeing as a Microsoft 365 replacement, has confirmed that the outage of its main website was caused by a hack. The company acknowledged the attack in comments to Dutch tech outlet Tweakers, while its official forum statement continues to describe "a normal infrastructure problem" without further detail.

The site went dark on Sunday. Before it did, users on Reddit reported that links on nextcloud.com redirected to something called "Cloudbox" for a period on Sunday evening. Nextcloud is restoring the site from a backup, and it had not returned as of Tweakers' report on Monday.

The company maintains that the damage stops at the website. Only nextcloud.com is affected, it says, with no impact on updates or downloads, and nothing related to Nextcloud's operational processes sits on the compromised server, so there should be no consequences for users or customers. That is the company's own assessment, with no independent confirmation available.

The cause of the hack has not been disclosed. The site runs WordPress and the intrusion could be connected to wp2shell, the critical pre-authentication remote code execution chain in WordPress core (CVE-2026-63030 combined with CVE-2026-60137) that was patched on July 17, 2026 in versions 6.9.5 and 7.0.2. Public exploits for wp2shell began circulating over the weekend, and researchers have reported early signs of in-the-wild exploitation. The connection to Nextcloud remains unconfirmed.



International Cyber Digest

Get the ICD Newsletter

Subscribe for source-forward cyber news, OSINT notes, breach updates, and analysis. Have evidence or a lead? Send it to ICD.

Subscribe Send a tip