Nextcloud—the German company behind the popular self-hosted cloud suite—left an internal Elasticsearch cluster open on the internet. Researchers at Cybernews counted about 367,000 records (~8GB).
What this is not: a mass breach of every customer’s Nextcloud home directory. Nextcloud says the mistake was in its own hosting infrastructure, and that customer/partner/user Nextcloud servers were not hit.
What was exposed
Internal files: invoices, contracts, email messages, employee addresses, client company names and addresses, and scripts built to help clients stand up Nextcloud. Some invoices were unencrypted and referenced domains such as IONOS, STRATO, and German education-ministry addresses.
What Nextcloud did
After contact, the company closed the cluster within about two days, notified the state data protection officer, and said it found no evidence of unauthorized access.
Action items
- Nextcloud staff and named contacts on invoices: watch for invoice and BEC phishing.
- Customers who received custom integration scripts: treat those scripts as potentially public and rotate any embedded secrets.
- Self-hosters: this incident is a reminder to inventory your own search/analytics endpoints—misconfigured Elasticsearch remains a recurring leak pattern.