ownCloud has issued an urgent advisory to users of its Community Edition, emphasizing the immediate need to enable multi-factor authentication (MFA) following a series of credential theft incidents. According to a threat intelligence report by Hudson Rock, attackers leveraged infostealer malware such as RedLine, Lumma, and Vidar to compromise employee endpoints and harvest login credentials. These stolen credentials were then used to access ownCloud instances that did not have MFA enabled, resulting in unauthorized access to sensitive data. ownCloud clarified that its platform was not breached and that no zero-day vulnerabilities were exploited; instead, the attacks succeeded due to misconfigurations and the absence of enforced MFA on self-hosted deployments.
The company recommends several mitigation steps: enabling MFA across all user accounts, resetting passwords, auditing access logs for suspicious activity, and invalidating active sessions to force re-authentication. Security experts highlight that MFA can block over 99% of account takeover attempts, yet adoption remains low among self-hosted platforms. The incident has drawn attention to the broader risks facing open-source file-sharing solutions like ownCloud, Nextcloud, and Seafile, especially as infostealer malware becomes more prevalent and corporate data is increasingly targeted for sale on dark web markets. Organizations are urged to prioritize MFA and robust credential management to defend against similar attacks.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
ownCloud published a security advisory urging Community Edition users to enable multi-factor authentication, reset passwords, invalidate sessions, and review access logs after reports of credential-theft-driven compromises. The company stated that ownCloud itself was not breached and said the incidents stemmed from stolen credentials and weak security configurations, especially missing MFA.
Threat intelligence reporting found that infostealer malware including RedLine, Lumma, and Vidar had infected employee devices, stolen credentials, and enabled unauthorized access to some self-hosted ownCloud instances without MFA. The reporting indicated the activity relied on compromised credentials rather than any ownCloud zero-day or platform breach.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.