2026-07-10NOTABLENextcloud GmbH exposed 367K internal records (client setup scripts with hardcoded DB credentials, a German ministry contact) via open Elasticsearch
Nextcloud GmbH corporate Elasticsearch data exposure (2026)
incident · incident:nextcloud-gmbh-elasticsearch-exposure-2026
Misconfigured, publicly exposed Elasticsearch cluster on Nextcloud GmbH's own hosting infrastructure exposed ~367,000 internal records (invoices, contracts, client setup scripts with hardcoded database credentials, and internal/client email) for ~9 days in May 2026; discovered and disclosed by Cybernews. The open-source Nextcloud software and customer-operated servers were unaffected; exposed contacts included German state ministry MSB NRW (Cybernews/heise, 2026-07-08).
Aliases: Nextcloud data leak
Coverage
1
first 2026-07-10 → last 2026-07-10
Latest activity
2026-07-10
Nextcloud GmbH exposed 367K internal records (client setup scripts with hardcoded DB credentials, a German…
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector, technology · regions: europe, dach
Sources cited
2
2 hosts
Action items (4)
Do-now tasks recorded on the entries about Nextcloud GmbH corporate Elasticsearch data exposure (2026), newest first. Check the date before acting on an older one.
- If your organisation is a Nextcloud GmbH hosting/onboarding client, treat any credentials that appeared in vendor-supplied setup or management scripts as potentially exposed and rotate them, and review whether your deployment architecture was inferable from leaked material.2026-07-10Nextcloud GmbH exposed 367K internal records…
- Brief helpdesk and finance staff to scrutinise invoice- or contract-themed emails referencing Nextcloud or its hosting partners (IONOS, STRATO) in the near term; the leaked invoices/contracts are ready-made spearphishing pretext.2026-07-10Nextcloud GmbH exposed 367K internal records…
- Audit your own Elasticsearch/OpenSearch estate: bind clusters to internal-only interfaces or a VPC, enable the security/auth plugin (it is off by default on TCP 9200/9300), and add continuous external attack-surface scanning for unauthenticated data/management ports.2026-07-10Nextcloud GmbH exposed 367K internal records…
- Treat hardcoded credentials in infrastructure-as-code and setup scripts as a secrets-management finding to remediate regardless of whether the script is ever exposed.2026-07-10Nextcloud GmbH exposed 367K internal records…
Defender insights
What each entry about Nextcloud GmbH corporate Elasticsearch data exposure (2026) tells a defender to do, newest first.
Story timeline
ATT&CK techniques (2 across 2 tactics)
2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessPhishing
- Credential AccessUnsecured Credentials: Credentials In Files
Initial Access TA0001
T1566Phishing×1
Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.
Evidence: 2026-07-10/nextcloud-gmbh-elasticsearch-exposure-msb-nrw · ATT&CK page ↗
Credential Access TA0006
T1552.001Unsecured Credentials: Credentials In Files×1
Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.
Evidence: 2026-07-10/nextcloud-gmbh-elasticsearch-exposure-msb-nrw · ATT&CK page ↗
Entries about Nextcloud GmbH corporate Elasticsearch data exposure (2026) (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- cybernews.com1 (50%)
- heise.de1 (50%)