Critical security breach

I have Windows desktop app installed. Yesterday I noticed that there are other personā€™s files in my NextCloud folder instead of mine!
I opened the app and saw that some other person is logged in! I donā€™t know this person, based on files I can say he is from another country.
I logged into NextCloud web storage - there are my files.
I am the only person who use my PC.

How is it possible?

I e-mailed support yesterday, but still got not any answer. I think this is urgent.

We need a lot more Info like Severconfig, Versionā€¦
Never seen this before butā€¦

How to get that? Iā€™m new to NextCloud.

See in the Admin configurations

That sounds strange. They gave out login details twice. Did you change your password? The e-mail address linked to your account is right (you can do both in the settings in the web-interface).

No, I didnā€™t change anything since registration.

In the web-interface everything is fine. As I said above I see my files there.
But desktop seems just as someone else logged in. Not even a hint of my account (other profile, other files). Wierd!

I donā€™t if it is important: I was logged into my Nextcloud account on my Sailfish smartphone. Right after this accident I logged out for privacy sake.

Just to clarify:

  • You see your own files only in web interface?
  • You see someone elseā€™s files only OR yours and others in the desktop client?
  • This is a hosted account and you do not have access to the server?

Yes.

Someone elseā€™s only. Just like if someone else has logged in.

Not sure if I got you right, but most likely itā€™s hosted account. I just registered for free plan on https://emma.cloud.tabdigital.eu

Change your password, check on your personal page, that no clients are connected that you did not authorize. Remove app keys of unknown devices.

Be careful with operators, especially if it is free. Itā€™s nice to get a look and feel of Nextcloud. If you want to store serious data, check out a trustworthy provider or, even better, host it yourself. Consider client-side encryption with sensitive data (currently best with 3rd-party software like cryptomator).

I do not see such section on my personal page.

I think Karl was asking if youā€™re running your own instance, or logging into a third-party service. Which apparently you are.

This forum is mostly for developers of Nextcloud, and for users that run their own instance of the software. Nextcloud (the organisation that runs this forum) provides the software, but has no influence or control over whoever runs the site ā€œemma.cloud.tabdigital.euā€.

Honestly, it looks like tabdigital are terrible system administrators. Going by your description, Iā€™m guessing they host multiple instances of Nextcloud under multiple domains on one server. Their sysadmin managed to mess up their config, resulting in your desktop app syncing to ā€œwrong.cloud.tabdigital.euā€ instead of ā€œemma.cloud.tabdigital.euā€.

I wish you luck, but thereā€™s very little anyone here can do. Only your service provider (emma.cloud.tabdigital.eu) can answer your questions or make you feel better about your lost privacy.

1 Like

Emma support said that was user mistake:

ā€œthere was wrong sharing settings from user sideā€.

But I wonder how that guy know my account name, we never got in touch with, I do not know him.

I would cancel the account.

I had the same with mark.nl.tab.digital after ons month i got an email asking me to pay 750 euroā€™s.

Didnā€™t pay, deleted my account.

Not sure how the gained access, i was using totp and strong password. I think their servers are breached, or a big hole in nextcloud, i dont know.

I had an with tab.digital where my account would randomly lock for a day or more at a time and when I contacted support they said that it was maintenance. I lost confidence in the provider and decided to self-host instead.