Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Shells Virtual Desktop
BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
Shells Virtual Desktop
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

ColoCrossing Database Breach

1272830323339

Comments

  • olokeoloke Member, Host Rep
    edited May 2025

    @lirrr said:
    hello i need ipv10 possible to giv?

    eWVh.dmVy.eWZ1.bm55/4269 subnet give lease possibel

  • angstromangstrom Moderator

    Virtualizor issued a minor update ("patch 1") yesterday -- the first update since the incident at CC -- but based on my reading of the (unspectacular) details given, it's far from clear that this update was motivated by the incident at CC:

    https://www.virtualizor.com/blog/virtualizor-3-2-5-patch-1/

    Which increasingly suggests that the incident at CC was largely due to a human error at CC

    (But perhaps Virtualizor haven't revealed something important)

  • beanman109beanman109 Member, Host Rep, Megathread Squad

    @angstrom said:
    Virtualizor issued a minor update ("patch 1") yesterday -- the first update since the incident at CC -- but based on my reading of the (unspectacular) details given, it's far from clear that this update was motivated by the incident at CC:

    https://www.virtualizor.com/blog/virtualizor-3-2-5-patch-1/

    Which increasingly suggests that the incident at CC was largely due to a human error at CC

    (But perhaps Virtualizor haven't revealed something important)

    [Feature] Server Firewall is now added in Premium License to improve server security.

    what an interesting and innovative feature to add in 2025!

  • tentortentor Member, Host Rep

    @angstrom said:
    Virtualizor issued a minor update ("patch 1") yesterday -- the first update since the incident at CC -- but based on my reading of the (unspectacular) details given, it's far from clear that this update was motivated by the incident at CC:

    https://www.virtualizor.com/blog/virtualizor-3-2-5-patch-1/

    Which increasingly suggests that the incident at CC was largely due to a human error at CC

    (But perhaps Virtualizor haven't revealed something important)

    https://www.virtualizor.com/blog/virtualizor-3-2-5/

    1. [Task] Missing API ACL added.

    Just an interesting fix

  • RubbenRubben Member

    Thanked by 2Blembim admax
  • Outages and security incidents can and do happen, but the lack of transparency from CC is alarming and reflects super poorly on them.

  • angstromangstrom Moderator

    @tentor said:

    @angstrom said:
    Virtualizor issued a minor update ("patch 1") yesterday -- the first update since the incident at CC -- but based on my reading of the (unspectacular) details given, it's far from clear that this update was motivated by the incident at CC:

    https://www.virtualizor.com/blog/virtualizor-3-2-5-patch-1/

    Which increasingly suggests that the incident at CC was largely due to a human error at CC

    (But perhaps Virtualizor haven't revealed something important)

    https://www.virtualizor.com/blog/virtualizor-3-2-5/

    1. [Task] Missing API ACL added.

    Just an interesting fix

    Right, but just to note that that fix (for version 3.2.5) predates the incident at CC

    Thanked by 1admax
  • tentortentor Member, Host Rep

    @angstrom said:

    @tentor said:

    @angstrom said:
    Virtualizor issued a minor update ("patch 1") yesterday -- the first update since the incident at CC -- but based on my reading of the (unspectacular) details given, it's far from clear that this update was motivated by the incident at CC:

    https://www.virtualizor.com/blog/virtualizor-3-2-5-patch-1/

    Which increasingly suggests that the incident at CC was largely due to a human error at CC

    (But perhaps Virtualizor haven't revealed something important)

    https://www.virtualizor.com/blog/virtualizor-3-2-5/

    1. [Task] Missing API ACL added.

    Just an interesting fix

    Right, but just to note that that fix (for version 3.2.5) predates the incident at CC

    However, hacker claimed that they had two month of access prior leak. Don't get me wrong but without clear statements from CC or Virtualizor (or both) we can only speculate

  • angstromangstrom Moderator

    @tentor said:

    @angstrom said:

    @tentor said:

    @angstrom said:
    Virtualizor issued a minor update ("patch 1") yesterday -- the first update since the incident at CC -- but based on my reading of the (unspectacular) details given, it's far from clear that this update was motivated by the incident at CC:

    https://www.virtualizor.com/blog/virtualizor-3-2-5-patch-1/

    Which increasingly suggests that the incident at CC was largely due to a human error at CC

    (But perhaps Virtualizor haven't revealed something important)

    https://www.virtualizor.com/blog/virtualizor-3-2-5/

    1. [Task] Missing API ACL added.

    Just an interesting fix

    Right, but just to note that that fix (for version 3.2.5) predates the incident at CC

    However, hacker claimed that they had two month of access prior leak. Don't get me wrong but without clear statements from CC or Virtualizor (or both) we can only speculate

    I admit that I didn't follow the hacker's precise statements (and there's also a question whether we should believe everything that the hacker says)

    In any case, this doesn't seem to be an instance of a critical bug in Virtualizor alone

  • CVPS_ChrisCVPS_Chris Member, Host Rep

    Hello everyone,

    I wanted to provide an update regarding ColoCloud.

    As of May 25th, 2025, ColoCloud has been fully operational. While a small group of customers did experience data loss, we have maintained consistent communication with those affected through our support ticket system. During the incident, we refrained from sharing specifics in real time to prioritize data integrity and give our team the best opportunity to complete mitigation efforts without introducing additional risk.

    We’re pleased to see that Virtualizor has included additional security enhancements in their most recent patch released yesterday.

    If you are a customer and have further questions or need assistance, please don’t hesitate to reach out via a support ticket. Our team is here to help. For escalation matters, your welcome to send me a private message.

    Thank you for your patience and understanding.

  • @Rubben said:

    @zed said:

    @zed said: Day 4

    Day 5?

    CockCrossing not addressing this major security breach should be a major red flag for anyone considering any services from them.

    The ship of red flags has sailed long ago.

    Thanked by 1khalequzzaman
  • emperoremperor Member

    @CVPS_Chris said: Thank you for your patience and understanding.

    So that's it? We are back and things goes to normal ? How about the breach explanation ? Someone there could have provided real info which now is stolen and can be used in various ways... Probably for your companies data leak is not serious, you only care about uptime.. WoW

  • RubbenRubben Member
    edited May 2025

    @CVPS_Chris said:
    Hello everyone,

    I wanted to provide an update regarding ColoCloud.

    As of May 25th, 2025, ColoCloud has been fully operational. While a small group of customers did experience data loss, we have maintained consistent communication with those affected through our support ticket system. During the incident, we refrained from sharing specifics in real time to prioritize data integrity and give our team the best opportunity to complete mitigation efforts without introducing additional risk.

    We’re pleased to see that Virtualizor has included additional security enhancements in their most recent patch released yesterday.

    If you are a customer and have further questions or need assistance, please don’t hesitate to reach out via a support ticket. Our team is here to help. For escalation matters, your welcome to send me a private message.

    Thank you for your patience and understanding.

    Any other company would have been long banned from LET for such a tonedeaf address of a major security breach that fucked over a lot of your customers.

  • dosaidosai Member

    @CVPS_Chris said:
    Hello everyone,

    I wanted to provide an update regarding ColoCloud.

    As of May 25th, 2025, ColoCloud has been fully operational. While a small group of customers did experience data loss, we have maintained consistent communication with those affected through our support ticket system. During the incident, we refrained from sharing specifics in real time to prioritize data integrity and give our team the best opportunity to complete mitigation efforts without introducing additional risk.

    We’re pleased to see that Virtualizor has included additional security enhancements in their most recent patch released yesterday.

    If you are a customer and have further questions or need assistance, please don’t hesitate to reach out via a support ticket. Our team is here to help. For escalation matters, your welcome to send me a private message.

    Thank you for your patience and understanding.

    What is the difference between colocloud and colocrossing?

  • techdragontechdragon Member
    edited May 2025

    @emperor said:

    @CVPS_Chris said: Thank you for your patience and understanding.

    So that's it? We are back and things goes to normal ? How about the breach explanation ? Someone there could have provided real info which now is stolen and can be used in various ways... Probably for your companies data leak is not serious, you only care about uptime.. WoW

    Would therefore imply unless that database is made public, nobody affected will be aware.

    To clarify: over five thousand ColoCrossing customer's details including their email addresses, phone numbers, full names and some addresses were leaked. Some VPS IP addresses and passwords were also leaked.

    Thanked by 2emperor Ed_Chd
  • @CVPS_Chris said:
    Hello everyone,

    I wanted to provide an update regarding ColoCloud.

    As of May 25th, 2025, ColoCloud has been fully operational. While a small group of customers did experience data loss, we have maintained consistent communication with those affected through our support ticket system. During the incident, we refrained from sharing specifics in real time to prioritize data integrity and give our team the best opportunity to complete mitigation efforts without introducing additional risk.

    We’re pleased to see that Virtualizor has included additional security enhancements in their most recent patch released yesterday.

    If you are a customer and have further questions or need assistance, please don’t hesitate to reach out via a support ticket. Our team is here to help. For escalation matters, your welcome to send me a private message.

    Thank you for your patience and understanding.

    Wow. This is really the statement from ColoCrossing? Seriously???

    You've spilt private customer data, you lost access to your services, people's VPSs were compromised and you haven't addressed any of that at all....or even any steps you e taken to ensure your infrastructure hasn't been backdoored

    I'm not your customer, but if I was Id be reporting you to the Irish Data Protection authority for a serious breach of GDPR.

  • I think at this point it's better to push https://colocrossingbreach.com/ higher up on the google results so people can get more detailed about what actually happened.

  • zedzed Member
    edited May 2025

    @CVPS_Chris said: Hello everyone,

    These aren't the droids you're looking for. Move along.

    Thanked by 1analog
  • donkodonko Member

    @dosai said: What is the difference between colocloud and colocrossing?

    forwarding the responsibility to a non-existent brand so "cockcrossing" stays clean and this never happened to them :smiley:

    THEY HACKED COLOCLOUD OK, NOT COLOCROSSING OK
    YOUR PERSONAL DATA IS SAFE AND UPLOADED TO MEDIAFIRE OK

    RESGUARDS.

  • zedzed Member

    Does this need to be shopped around more to industry related and adjacent publications so these guys are forced to do standard disclosures about the breach?

    Thanked by 1Ed_Chd
  • @barbaros said:
    I think at this point it's better to push https://colocrossingbreach.com/ higher up on the google results so people can get more detailed about what actually happened.

    I need SEO experts @allthemtings @plumberg

  • NeoonNeoon Community Contributor, Veteran

    @CVPS_Chris said:
    Hello everyone,

    I wanted to provide an update regarding ColoCloud.

    As of May 25th, 2025, ColoCloud has been fully operational. While a small group of customers did experience data loss, we have maintained consistent communication with those affected through our support ticket system. During the incident, we refrained from sharing specifics in real time to prioritize data integrity and give our team the best opportunity to complete mitigation efforts without introducing additional risk.

    We’re pleased to see that Virtualizor has included additional security enhancements in their most recent patch released yesterday.

    If you are a customer and have further questions or need assistance, please don’t hesitate to reach out via a support ticket. Our team is here to help. For escalation matters, your welcome to send me a private message.

    Thank you for your patience and understanding.

    If you have 11k servers and 500 get wiped.
    Its 5% so a small amount, true story.

  • plumbergplumberg Veteran, Megathread Squad

    @nghialele said:

    @barbaros said:
    I think at this point it's better to push https://colocrossingbreach.com/ higher up on the google results so people can get more detailed about what actually happened.

    I need SEO experts @allthemtings @plumberg

    Send 22k btc first

  • Someone shared this on Reddit:

    As outlined in our previous email, there was an event affecting the ColoCloud platform. The issue has since been fully mitigated; however, your VPS was on a small ground of servers that experienced data loss as a result of the incident.

    We’ve gone ahead and recreated your VPS and have sent the new access details to you. Please review them at your earliest convenience.

    The ColoCloud team is working diligently to ensure full recovery for all customers and we sincerely thank you for the opportunity to service you. If you have any questions or need further assistance, feel free to reach out. We’re here to help.

    George M,
    Cloud Colocrossing

    https://www.reddit.com/r/VPS/comments/1kudww5/comment/muvtqnc/

    Thanked by 1PolyAnthi
  • LeviLevi Member

    Passwords in plain text.

  • @servarica_hani said:
    For other Providers and other sellers here

    Review all orders done since 25th
    We found out a couple of the account got accessed by same person who made orders from those users accounts

    So users started going through the leaked DB and they are trying the passwords on all known VPS hosts hoping users used the same password and they got lucky on some accounts

    @CVPS_Chris @ColoCrossing

    Do you think your customers should know that their passwords have been compromised and might be used to access other services?

  • @Xrmaddness said:
    Someone shared this on Reddit:

    As outlined in our previous email, there was an event affecting the ColoCloud platform. The issue has since been fully mitigated; however, your VPS was on a small ground of servers that experienced data loss as a result of the incident.

    We’ve gone ahead and recreated your VPS and have sent the new access details to you. Please review them at your earliest convenience.

    The ColoCloud team is working diligently to ensure full recovery for all customers and we sincerely thank you for the opportunity to service you. If you have any questions or need further assistance, feel free to reach out. We’re here to help.

    George M,
    Cloud Colocrossing

    https://www.reddit.com/r/VPS/comments/1kudww5/comment/muvtqnc/

    Does seem like they're avoiding responsibility if I am being honest, especially with 0 clear communication besides those cryptic "Thanks for your patience" messages that do not address any of the issues raised.

  • darkimmortaldarkimmortal Member
    edited May 2025

    So when is colocrossing getting banned/warned? They cannot be allowed to continue with business as usual on LET after such a cock up

    I'm sure there will be a hit squad in the comments of any future offer thread they post, but not everyone reads that, especially with the LET signal to noise ratio at new lows

Sign In or Register to comment.