← ColoCrossing

2025 ColoCrossing / ColoCloud — SSO flaw exposed ~7.2k customer emails and MD5-Crypt hashes

2025 7.2K records affected Share on X

Data compromised

Email addresses, names, MD5-Crypt password hashes

Technical writeup

Have I Been Pwned describes a May 2025 ColoCrossing breach affecting customers of the ColoCloud virtual server product. ColoCrossing characterized the incident as isolated to the cloud/VPS platform and stemming from a single sign-on vulnerability. The exposed dataset contained roughly 7.2k email addresses along with names and MD5-Crypt password hashes.

Root cause

Single sign-on vulnerability in cloud/VPS platform context

References