← Nextcloud

2026 Nextcloud — misconfigured Elasticsearch; ~367K internal records (staff/client files)

2026 367.0K records affected Share on X

Data compromised

Per Cybernews: ~367,000 records / ~7.92GB including invoices, contracts, email messages, employee emails, client company names/addresses, and client integration scripts. Company: no customer Nextcloud servers affected; no evidence of unauthorized access found.

Technical writeup

Verified exposure with company response — discovered May 18, 2026 by Cybernews; covered in July 2026 reporting. Researchers found a publicly accessible Elasticsearch cluster holding about 7.92GB / 367,000 internal Nextcloud records (invoices, contracts, emails, staff and client company details, and client setup scripts). Nextcloud said the issue was a hosting-infrastructure misconfiguration unrelated to the Nextcloud product, that customer/partner/user Nextcloud servers were not affected, that it notified the state data protection officer, and that it found no evidence of exploitation; the cluster was closed about two days after contact. Domains observed in unencrypted invoices included hosts such as IONOS and STRATO and German education-ministry addresses. BreachHistory indexes 367,000 per the researcher record count with company acknowledgment of the exposure.

Root cause

Hosting-infrastructure misconfiguration left an Elasticsearch cluster publicly accessible with internal Nextcloud files (~8GB / ~367K records); closed after researcher notification (company statement via Cybernews)

References