Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Shells Virtual Desktop
BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
Shells Virtual Desktop
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

ColoCrossing Database Breach

1282931333439

Comments

  • sixsix Member

    @Xrmaddness said:
    Someone shared this on Reddit:

    As outlined in our previous email, there was an event affecting the ColoCloud platform. The issue has since been fully mitigated; however, your VPS was on a small ground of servers that experienced data loss as a result of the incident.

    We’ve gone ahead and recreated your VPS and have sent the new access details to you. Please review them at your earliest convenience.

    The ColoCloud team is working diligently to ensure full recovery for all customers and we sincerely thank you for the opportunity to service you. If you have any questions or need further assistance, feel free to reach out. We’re here to help.

    George M,
    Cloud Colocrossing

    https://www.reddit.com/r/VPS/comments/1kudww5/comment/muvtqnc/

    I got this same message, and although I'm paying LET prices, this response feels devoid, and I still have no idea why this happened in the first place and what ColoCrossing has and will do about it. I probably will not renew my services anymore because I no longer trust how they handle these situations.

    Thanked by 2Xrmaddness lothos
  • RubbenRubben Member

    @six said:

    @Xrmaddness said:
    Someone shared this on Reddit:

    As outlined in our previous email, there was an event affecting the ColoCloud platform. The issue has since been fully mitigated; however, your VPS was on a small ground of servers that experienced data loss as a result of the incident.

    We’ve gone ahead and recreated your VPS and have sent the new access details to you. Please review them at your earliest convenience.

    The ColoCloud team is working diligently to ensure full recovery for all customers and we sincerely thank you for the opportunity to service you. If you have any questions or need further assistance, feel free to reach out. We’re here to help.

    George M,
    Cloud Colocrossing

    https://www.reddit.com/r/VPS/comments/1kudww5/comment/muvtqnc/

    I got this same message, and although I'm paying LET prices, this response feels devoid, and I still have no idea why this happened in the first place and what ColoCrossing has and will do about it. I probably will not renew my services anymore because I no longer trust how they handle these situations.

    if i were you id accept my losses and move to a different provider asap

    Thanked by 3Xrmaddness six Ed_Chd
  • NJa64FNJa64F Barred

    @CVPS_Chris said:

    We’re pleased to see that Virtualizor has included additional security enhancements in their most recent patch released yesterday.

    The vagueness of this statement is not fooling anyone here.

  • sixsix Member

    @Rubben said:

    @six said:

    @Xrmaddness said:
    Someone shared this on Reddit:

    As outlined in our previous email, there was an event affecting the ColoCloud platform. The issue has since been fully mitigated; however, your VPS was on a small ground of servers that experienced data loss as a result of the incident.

    We’ve gone ahead and recreated your VPS and have sent the new access details to you. Please review them at your earliest convenience.

    The ColoCloud team is working diligently to ensure full recovery for all customers and we sincerely thank you for the opportunity to service you. If you have any questions or need further assistance, feel free to reach out. We’re here to help.

    George M,
    Cloud Colocrossing

    https://www.reddit.com/r/VPS/comments/1kudww5/comment/muvtqnc/

    I got this same message, and although I'm paying LET prices, this response feels devoid, and I still have no idea why this happened in the first place and what ColoCrossing has and will do about it. I probably will not renew my services anymore because I no longer trust how they handle these situations.

    if i were you id accept my losses and move to a different provider asap

    CC refugee dealz?

    Thanked by 1oloke
  • RubbenRubben Member

    @six said:

    @Rubben said:

    @six said:

    @Xrmaddness said:
    Someone shared this on Reddit:

    As outlined in our previous email, there was an event affecting the ColoCloud platform. The issue has since been fully mitigated; however, your VPS was on a small ground of servers that experienced data loss as a result of the incident.

    We’ve gone ahead and recreated your VPS and have sent the new access details to you. Please review them at your earliest convenience.

    The ColoCloud team is working diligently to ensure full recovery for all customers and we sincerely thank you for the opportunity to service you. If you have any questions or need further assistance, feel free to reach out. We’re here to help.

    George M,
    Cloud Colocrossing

    https://www.reddit.com/r/VPS/comments/1kudww5/comment/muvtqnc/

    I got this same message, and although I'm paying LET prices, this response feels devoid, and I still have no idea why this happened in the first place and what ColoCrossing has and will do about it. I probably will not renew my services anymore because I no longer trust how they handle these situations.

    if i were you id accept my losses and move to a different provider asap

    CC refugee dealz?

    No. Maybe this was a good learning lesson if you dont want to get fucked over by noname LET companies, rent VMs from big players like Amazon, Tencent or Oracle...

  • CloudHopperCloudHopper Member
    edited May 2025

    "an event affecting the ColoCloud platform"

    I really think they should tell their customers that they've leaked personal data and there are known cases of that data being abused.

    @ColoCrossing provide services from Ireland, to EU citizens, so the GDPR clearly applies here, and the Irish Data Protection Agency's website is clear about their responsibilities in the event of a breach:

    From 25 May 2018, the General Data Protection Regulation (GDPR) introduces a requirement for organisations to report personal data breaches to the relevant supervisory authority, where the breach presents a risk to the affected individuals. Organisations must do this within 72 hours of becoming aware of the breach.

    Where a breach is likely to result in a high risk to the affected individuals, organisations must also inform those individuals without undue delay.

    https://www.dataprotection.ie/en/organisations/know-your-obligations/breach-notification

  • Like sands through the hourglass, so are the days of our lives.

  • zedzed Member

    https://colocrossingbreach.com/ not updated with latest handwave, am disappoint.

    Thanked by 1x0x0x
  • x0x0xx0x0x Member

    @beanman109 said:

    @angstrom said:
    Virtualizor issued a minor update ("patch 1") yesterday -- the first update since the incident at CC -- but based on my reading of the (unspectacular) details given, it's far from clear that this update was motivated by the incident at CC:

    https://www.virtualizor.com/blog/virtualizor-3-2-5-patch-1/

    Which increasingly suggests that the incident at CC was largely due to a human error at CC

    (But perhaps Virtualizor haven't revealed something important)

    [Feature] Server Firewall is now added in Premium License to improve server security.

    what an interesting and innovative feature to add in 2025!

    Update CCB please sar.

  • vovlervovler Member

    the classic surprise decentralized backup

  • TrKTrK Member

    We were pretty quick with red demands for charitpeeping but i don't see any thing for cockcrosing, what went wrong? Apart from obvious Biloh owning both(atleast used to be).

  • @TrK said:
    We were pretty quick with red demands for charitpeeping but i don't see any thing for cockcrosing, what went wrong? Apart from obvious Biloh owning both(atleast used to be).

    For me personally, the ColoCrossing situation is concerning and potentially ban or warning-worthy, but the people behind CC don't seem malicious and vindictive against people who speak out against them. They are also not doing ridiculous, meltdown-level damage control here on LET.

  • defaultdefault Veteran

    @ServerBachelor said:

    @TrK said:
    We were pretty quick with red demands for charitpeeping but i don't see any thing for cockcrosing, what went wrong? Apart from obvious Biloh owning both(atleast used to be).

    For me personally, the ColoCrossing situation is concerning and potentially ban or warning-worthy, but the people behind CC don't seem malicious and vindictive against people who speak out against them. They are also not doing ridiculous, meltdown-level damage control here on LET.

    Because they decided to reduce the volume by saying nothing. They should have been banned, but they're not.

    Thanked by 2orangejoose ahnlak
  • @CloudHopper said:
    "an event affecting the ColoCloud platform"

    I really think they should tell their customers that they've leaked personal data and there are known cases of that data being abused.

    @ColoCrossing provide services from Ireland, to EU citizens, so the GDPR clearly applies here, and the Irish Data Protection Agency's website is clear about their responsibilities in the event of a breach:

    From 25 May 2018, the General Data Protection Regulation (GDPR) introduces a requirement for organisations to report personal data breaches to the relevant supervisory authority, where the breach presents a risk to the affected individuals. Organisations must do this within 72 hours of becoming aware of the breach.

    Where a breach is likely to result in a high risk to the affected individuals, organisations must also inform those individuals without undue delay.

    https://www.dataprotection.ie/en/organisations/know-your-obligations/breach-notification

    @CVPS_Chris could we kindly request your comments on this matter?

  • Cam2024Cam2024 Member

    Imagine having a large scale data breach of 11k customers and just letting people know via a generic forum post that there was "an outage" and it's all good now.

    I'm guessing given they're from 'merica, that they don't really care about overseas data protections and are just hoping that it'll all go away after this post.

    Thanked by 2Ed_Chd darkimmortal
  • hyunhyun Member

    I swear, if ColoCrossing dares to run another promotion, I’ll lose it in the comments. They have no right to call themselves a cloud service provider. Multiple VPS instances in Los Angeles had their data wiped, and ColoCrossing’s only response was: “Can we reinstall the server? Please confirm.”

    They don’t care about user data at all. No explanation, no accountability—just the same robotic reply: “Can we reinstall the server? Please confirm.” If you don’t understand how to run a cloud service properly, then don’t even try. ColoCrossing is a joke.

  • hyunhyun Member

    ColoCrossing is utterly incompetent. Despite a database leak and server data deletion, they never responded or offered any compensation. What makes it worse? I have multiple VPS instances—most just used as proxy nodes (with no critical data), yet the hacker specifically targeted my production servers hosting actual websites.
    Fuck you ColoCrossing bitch
    To ColoCrossing: If you can’t protect customer data, shut down your service.

  • NeoonNeoon Community Contributor, Veteran

    @angstrom said:
    Virtualizor issued a minor update ("patch 1") yesterday -- the first update since the incident at CC -- but based on my reading of the (unspectacular) details given, it's far from clear that this update was motivated by the incident at CC:

    https://www.virtualizor.com/blog/virtualizor-3-2-5-patch-1/

    Which increasingly suggests that the incident at CC was largely due to a human error at CC

    (But perhaps Virtualizor haven't revealed something important)

    So as expected, they lied.

  • @Rubben said:

    @MannDude said:

    @plumberg said:

    @Kevinf100 said:

    @plumberg said:
    Is there a repo somewhere to check if I have been compromised?

    Just assume you have. If you have a VPS from colocrossing just play it safe, change password and probably reinstall the OS.

    Haven't gone through 28 pages of gold content here.
    If I am reading right, its only impacting cloud customers and not dedicated server customers?

    Yeah, seems to be isolated to only their Virtual Servers "cloud" product and their resellers who use the same panel like HVH or whoever.

    Ok, but here's the thing. If this was really a human error on CC's part, would you trust them with anything in the future? Because personally, I wouldn't trust even if they said 'good morning'

    Why? So the next company makes the same mistake? You can be sure CC won't ever have this exact issue again.

  • @VirMach can you share your experience

    Thanked by 2borkedascii sh97
  • sixsix Member

    @TimboJones said:

    @Rubben said:

    Ok, but here's the thing. If this was really a human error on CC's part, would you trust them with anything in the future? Because personally, I wouldn't trust even if they said 'good morning'

    Why? So the next company makes the same mistake? You can be sure CC won't ever have this exact issue again.

    Well, you never know especially with these things that it won't happen again.

  • Apart from the data is anyone else concerned about the shady websites’ contents that are hosted on CC?

    Scam and phishing sites, botnet C&Cs and other stuff I don’t remember

    @ColoCrossing does it mean you offer bulletproof hosting also?

  • zedzed Member

    @barbaros said: bulletproof hosting

    I don't think they advertise as such but haven't they always been known as a place where you can get away with whatever? Doesn't everybody block cc ip ranges by default? I can't remember a time when they were considered a fine upstanding internet citizen.

    I might be wrong I guess, but that's my memory.

  • caracalcaracal Member

    3 options - Anger, nihilism or colocrossingbreach.com

  • colocrossing's ass needs to be kicked from LET for such a "statement"

    Thanked by 1darkimmortal
  • allthemtingsallthemtings Member, Megathread Squad

    @blu3bird said:
    colocrossing's ass needs to be kicked from LET for such a "statement"

    0% chance of this happening, who's going to tell him?

  • lirrrlirrr Member

    you cannot exile the associate that has deep connection with LET overlord

  • HosteroidHosteroid Member, Patron Provider
    edited May 2025

    There has been sent official email by Virtualizor/Softaculous..

    Dear Customer,

    We are writing to inform you of a security incident concerning our employee productivity monitoring system.

    It has come to our attention that screenshots taken at regular intervals from our support employee(s) systems were inadvertently stored in a publicly accessible folder. These screenshots may have contained sensitive customer information, including server passwords submitted through our support systems between January and February 2025.

    While the likelihood of any specific password appearing in these screenshots is low, we strongly recommend that you change your server passwords immediately if you submitted them via any of our support channels during this time.

    However, we want to reassure you that there is no known or reported vulnerability in any of our software products.
    None of our infrastructure has been compromised.

    Steps We Are Taking to Mitigate Future Risk:

    • We are introducing a secure method across all products for customers to grant support access using public/private key authentication, eliminating the need to share passwords.
    • All root logins in Virtualizor and Webuzo will trigger an email notification with the IP address of the login attempt.
    • We will display a warning in the Admin Panel if a password is older than 3 months, suggesting a reset.
    • API keys will include a recommendation to restrict access to specific IPs.
    • Our support system will send a follow-up email prompting password resets once a ticket is closed.

    Important Note Regarding Password Storage:
    We have seen some misinformation regarding how we store passwords. Please be assured that all end-user passwords are securely hashed and never stored in plain text.

    Recommended Customer Action:
    We strongly advise all customers to reset any passwords submitted through our support systems (including ticket and chat) as a best practice—not just for our systems, but across any support platform you use.

    We sincerely apologize for this incident and appreciate your prompt attention and understanding as we work to enhance our systems and security protocols.

    Regards,
    The Softaculous Team

  • It has come to our attention that screenshots taken at regular intervals from our support employee(s) systems were inadvertently stored in a publicly accessible folder. These screenshots may have contained sensitive customer information, including server passwords submitted through our support systems between January and February 2025.

    Creeps got what they deserved

  • NeoonNeoon Community Contributor, Veteran
    edited May 2025

    @Hosteroid said:
    There has been sent official email by Virtualizor/Softaculous..

    Dear Customer,

    We are writing to inform you of a security incident concerning our employee productivity monitoring system.

    It has come to our attention that screenshots taken at regular intervals from our support employee(s) systems were inadvertently stored in a publicly accessible folder. These screenshots may have contained sensitive customer information, including server passwords submitted through our support systems between January and February 2025.

    While the likelihood of any specific password appearing in these screenshots is low, we strongly recommend that you change your server passwords immediately if you submitted them via any of our support channels during this time.

    However, we want to reassure you that there is no known or reported vulnerability in any of our software products.
    None of our infrastructure has been compromised.

    Steps We Are Taking to Mitigate Future Risk:

    • We are introducing a secure method across all products for customers to grant support access using public/private key authentication, eliminating the need to share passwords.
    • All root logins in Virtualizor and Webuzo will trigger an email notification with the IP address of the login attempt.
    • We will display a warning in the Admin Panel if a password is older than 3 months, suggesting a reset.
    • API keys will include a recommendation to restrict access to specific IPs.
    • Our support system will send a follow-up email prompting password resets once a ticket is closed.

    Important Note Regarding Password Storage:
    We have seen some misinformation regarding how we store passwords. Please be assured that all end-user passwords are securely hashed and never stored in plain text.

    Recommended Customer Action:
    We strongly advise all customers to reset any passwords submitted through our support systems (including ticket and chat) as a best practice—not just for our systems, but across any support platform you use.

    We sincerely apologize for this incident and appreciate your prompt attention and understanding as we work to enhance our systems and security protocols.

    Regards,
    The Softaculous Team

    So you wanna tell me, ColoCrossing handed over the password, to the virtualozor instance with 11k VM's?
    Cmon they can't be that stupid.

Sign In or Register to comment.