Cloudie Networks, LLC. Data Leakage

AbdullahAbdullah ProviderOG
edited December 2023 in Industry News

Just got this email. WHMCSec security team (?) anyone knows who that is.
I saw someone mention here about LetBox staff stating their system was compromised and all VMs need to be reinstalled. So this seems credible.

Dear name

Hello and Merry Christmas.

We are the WHMCSec security team. Recently we broke into Cloudie and obtained complete data.

We tried to communicate with him in a friendly manner and offered him $200 to help him improve security and avoid data leakage.

But he replied to us that he doesn't care about the security of user data.

And lied to you, claiming that the data was not leaked

Therefore we decided to release its complete database SQL DUMP within 24 hours, please join our Telegram group to learn more

[redacted]

Our goal is to clean up all hosting providers who are not responsible for customer data

In addition, we will also release data on SmartHost, LetBox, etc. in the near future.

«1

Comments

  • FrankZFrankZ ModeratorOG

    Checks inbox.

  • edited December 2023

    Extortion season.

  • Three similar emails received at MetalVPS. Plus also an invoice email for $0 and a payment confirmation email. That's 5 emails all together.

    Checking the headers on two of the emails showed different sending MTAs. I haven't checked the other three emails.

    Unfortunately I don't have a Telegram account. Maybe WHMCSec will send further email updates. Or maybe someone will post here.

    @Cloudie Hope all is okay! Best wishes!

  • AbdullahAbdullah ProviderOG
    edited December 2023

    @Not_Oles said:
    Three similar emails received at MetalVPS. Plus also an invoice email for $0 and a payment confirmation email. That's 5 emails all together.

    Checking the headers on two of the emails showed different sending MTAs. I haven't checked the other three emails.

    Unfortunately I don't have a Telegram account. Maybe WHMCSec will send further email updates. Or maybe someone will post here.

    @Cloudie Hope all is okay! Best wishes!

    They released the whmcs SQL dump some minutes ago. I hope most people don't re-use same details everywhere! :#

  • @Abdullah said:
    I hope most people don't re-use same details everywhere! :#

    Of course people practice good basic OPSEC! This is the Internet...oh.

  • bikegremlinbikegremlin ModeratorOG
    edited December 2023

    @Abdullah said:
    Just got this email. WHMCSec security team (?) anyone knows who that is.
    I saw someone mention here about LetBox staff stating their system was compromised and all VMs need to be reinstalled. So this seems credible.

    Dear name

    Hello and Merry Christmas.

    We are the WHMCSec security team. Recently we broke into Cloudie and obtained complete data.

    We tried to communicate with him in a friendly manner and offered him $200 to help him improve security and avoid data leakage.

    But he replied to us that he doesn't care about the security of user data.

    And lied to you, claiming that the data was not leaked

    Therefore we decided to release its complete database SQL DUMP within 24 hours, please join our Telegram group to learn more

    [redacted]

    Our goal is to clean up all hosting providers who are not responsible for customer data

    In addition, we will also release data on SmartHost, LetBox, etc. in the near future.

    They claim their goal is noble, but I don't think that dumping user data is a noble deed.

    My long-winded drivel on security ethics is here, at 11 minutes (the link should start right there):

  • @Abdullah said: They released the whmcs SQL dump some minutes ago.

    I guess that means the emails I received could be from different people because the database is public now.

    Still hope everything goes okay for @Cloudie! Sending him best wishes!

  • Change your passwords, boys.

    Have you tried turning it off and on again?

  • @bikegremlin said:

    They claim their goal is noble, but I don't think that dumping user data is a noble deed.

    Taking a dump is a noble deed no matter the context

  • Please change your passwords, just checked the dump.

    My details, and my friend's details were present.

    Stay Safe, and Stay Strong @Cloudie!

    and Fuck WHMCSservices/WHMCS

  • crunchbitscrunchbits Provider
    edited December 2023

    We tried to communicate with him in a friendly manner and offered him $200 to help him improve security and avoid data leakage.

    Very honorable and trustworthy offer!

    But he replied to us that he doesn't care about the security of user data.

    Doubt.

    Therefore we decided to release its complete database SQL DUMP
    In addition, we will also release data on SmartHost, LetBox, etc. in the near future.

    Ah, so noble. They refused your untrustworthy blackmail, so you released data compromising hundreds of innocent third party customers. I hope not a single host ever gives into these skids. They'll have you bent over their knee forever, they'll never actually destroy the data, and anytime they need a little refill they'll come shaking their little cup for $200 as a you'll be a known pay pig.

    Our goal is to clean up all hosting providers who are not responsible for customer data

    I was already leaked by multiple multinational billion dollar companies (ala Equifax, with more damning personal data) 6+ years ago. Why don't you go clean them up instead of some low end hosts?

    I'll keep it as clean as I can, but I really hope antics of some lowlife like this doesn't have much material effect overall.

  • @FatGrizzly said:
    Please change your passwords, just checked the dump.

    My details, and my friend's details were present.

    Stay Safe, and Stay Strong @Cloudie!

    and Fuck WHMCSservices/WHMCS

    do you have the downloadlink to the dump?

  • Otus9051Otus9051 The Original Freeloader

    i would make a joke but its on cloudies network

    youtube.com/watch?v=k1BneeJTDcU

  • @lapua said:

    @FatGrizzly said:
    Please change your passwords, just checked the dump.

    My details, and my friend's details were present.

    Stay Safe, and Stay Strong @Cloudie!

    and Fuck WHMCSservices/WHMCS

    do you have the downloadlink to the dump?

    Check dm's :)

  • webmashwebmash Retired
    edited December 2023

    Not looking good is it

    @treesmokah said:

    @lapua said:ou have the downloadlink to the dump?

    Check dm's :)

  • THAT IS WHY I ALWAYS USE FAKE DATA AND RANDOMLY GENERATED PASSWORD!

    you guys should also do the same. ignore any host that mandatory require you to give them real personal data, they are just trying to feed you to crocodiles

  • =)

    Host-C | Storage by Design | AS211462

    “If it can’t guarantee behavior under load, it doesn’t belong in production.”

  • Good reminder to use unique passwords everywhere (use a password manager).

    With how frequent data breaches are these days (to the point where I almost feel desensitized), there's no reason not to.

  • @selalumenang said:
    THAT IS WHY I ALWAYS USE FAKE DATA AND RANDOMLY GENERATED PASSWORD!

    you guys should also do the same. ignore any host that mandatory require you to give them real personal data, they are just trying to feed you to crocodiles

    Most generalizations are wrong... is a generalization itself. LOL

  • Any response from Cloudie Networks yet?

  • edited December 2023

    I have not seen the dump file, but assuming that the passwords are hashed and salted, I think it won't be a trivial task for someone to derive the original password from the hash? (Not a security expert here, so I might be wrong)

    But yeah, one should still change the password.

  • It's quite ridiculous that an extortion group calls themselves "Security Team".

  • MikeAMikeA ProviderOG

    @ZuckZwing said:
    It's quite ridiculous that an extortion group calls themselves "Security Team".

    Lots of them are called that. Many stresser/booters ran by groups of kids are called that too. Just a term used in that space.

  • @tmntwitw said:
    I have not seen the dump file, but assuming that the passwords are hashed and salted, I think it won't be a trivial task for someone to derive the original password from the hash? (Not a security expert here, so I might be wrong)

    But yeah, one should still change the password.

    Its all bcrypt so its pretty secure if you used a strong password. But some rules that @Decicus and @selalumenang talked about:
    1. Use unique passwords for every single thing
    2. Avoid KYC

  • Dammit, now I'll have to switch to hunter3 everywhere.

  • MannDudeMannDude Provider IncogNET - Speech and Privacy
    edited December 2023

    OGF says Cloudie's Discord mods are deleting mentions who bring it up in their chat, and nothing has been sent to their customers from Cloudie yet. :(

    I had someone ping me privately to inform me my details were in the DB. (Well, IncogNET company details). I can confirm it was. (My first/last, business name, business address, business phone number, and my VPN IP)

  • jarlandjarland ProviderOG
    edited December 2023

    @tmntwitw said:
    I have not seen the dump file, but assuming that the passwords are hashed and salted, I think it won't be a trivial task for someone to derive the original password from the hash? (Not a security expert here, so I might be wrong)

    But yeah, one should still change the password.

    From what I’ve seen they’ll have the code from configuration.php which is all that is needed to at least turn service passwords into plain text. So it’s not just billing passwords you need to change.

    Also email history in WHMCS may contain passwords generated for new services in plain text. For hosts who never changed it in email templates (not sure if WHMCS changed it themselves later), email history at least used to contain plain text passwords written by the user on registration.

    Do everything as though everyone you’ll ever know is watching.

  • AdvinAdvin Provider
    edited December 2023

    @MannDude said:
    OGF says Cloudie's Discord mods are deleting mentions who bring it up in their chat, and nothing has been sent to their customers from Cloudie yet. :(

    I had someone ping me privately to inform me my details were in the DB. (Well, IncogNET company details). I can confirm it was. (My first/last, business name, business address, business phone number, and my VPN IP)

    Cloudie sent out an email on Dec 16th when the breach happened. The email indicated that no personal or payment data had been breached, but I guess he thought that at the time. He's still probably not awake which is why an email hasn't probably been sent out, it doesn't make sense to not send out an email.

    I am a representative of Advin Servers

  • MannDudeMannDude Provider IncogNET - Speech and Privacy

    @Advin said:

    @MannDude said:
    OGF says Cloudie's Discord mods are deleting mentions who bring it up in their chat, and nothing has been sent to their customers from Cloudie yet. :(

    I had someone ping me privately to inform me my details were in the DB. (Well, IncogNET company details). I can confirm it was. (My first/last, business name, business address, business phone number, and my VPN IP)

    Cloudie sent out an email on Dec 16th when the breach happened. The email indicated that no personal or payment data had been breached, but I guess he thought that at the time.

    Yes, and in that email it says "To reiterate, we have no reason to believe that any personal or payment data has been breached..."

    Personal details have been breached.

  • MannDudeMannDude Provider IncogNET - Speech and Privacy
    edited December 2023

    @jarland said:

    @tmntwitw said:
    I have not seen the dump file, but assuming that the passwords are hashed and salted, I think it won't be a trivial task for someone to derive the original password from the hash? (Not a security expert here, so I might be wrong)

    But yeah, one should still change the password.

    From what I’ve seen they’ll have the code from configuration.php which is all that is needed to at least turn service passwords into plain text. So it’s not just billing passwords you need to change.

    Also email history in WHMCS may contain passwords generated for new services in plain text. For hosts who never changed it in email templates (not sure if WHMCS changed it themselves later), email history at least used to contain plain text passwords written by the user on registration.

    User on OGF that is going through the DB dump says they had ID's and other KYC verification in the dump, as well. So, that's makes this even worse for some.

  • @MannDude said: Personal details have been breached.

    And this was suspected and 99% confirmed by a lot of people already last week.

  • edited December 2023

    New email they allegedly sent out just now(from OGF)

    Immediate Action Required: Security Breach and Data Leak Update
    We are contacting you to address a critical security incident that has impacted our systems and potentially your data.
    Incident Timeline and Immediate Actions:
    
        December 16th, 2023 - Initial Breach Detected: Our team discovered unauthorized access in our WHMCS system and promptly notified all users.
        Proactive Security Measures: We initiated a fresh installation on a new server for enhanced security and to mitigate further risks.
    
    Data Leak Confirmation:
    
        December 28th, 2023 - Data Compromise Identified: Despite our actions, we have ascertained that certain data from the initial breach has been exposed online.
    
    Detailed Overview of the Leaked Data:
    
        Client Information: Names, addresses, phone numbers, and email addresses.
        Financial Data: Billing addresses, payment histories, and partial credit card details.
        Service and Purchase Records: Details of hosting plans, ASN registrations, and other services.
        Support and Communication Logs: Information from support tickets and email communications.
        Login Credentials and Security Data: Usernames, hashed passwords, security questions, and API keys.
        Custom Fields and Administrative Data: Additional client-specific information and administrative user data.
        Audit Logs and System Settings: Records of user actions and configurations within the system.
    
    Impact Beyond Cloudie Networks:
    
        Wider Industry Effect: The breach has repercussions for several providers, especially those using modules like WHMCSServices and WHMCSGlobalServices.
        Lack of Complete Provider List: Unfortunately, a comprehensive list of all affected providers is not available.
    
    Our Commitment to Enhanced Security:
    
        Selective Module Usage: To safeguard your information, we have discontinued the use of all third-party modules, with the exception of the Lagom theme.
        Infrastructure Security: We have migrated to a new server with upgraded security protocols to fortify our defenses against such incidents.
    
    Urgent Recommendations for Your Safety:
    
        Immediate Password Reset: Change your Cloudie Networks password using [Password Reset Link] and consider updating passwords on other platforms if they are similar.
        Account Monitoring: Stay vigilant for unusual activities in your accounts and report any anomalies.
        Beware of Phishing: Cloudie Networks will never ask for sensitive information via email. Use [Official Contact Link] for any verification.
    
    Additional Safety Measures Taken:
    
        Payment Information Security: We have cancelled all PayPal subscriptions and revoked/reissued Stripe card API tokens to prevent unauthorized charges.
        Resetting of Compromised Credentials: We've reset all leaked VM and Proxmox credentials as a preventive action.
    
    Staying Updated and Supported:
    
        Ongoing Updates: We will keep you informed about any new developments.
        Support Availability: We is ready to assist at Cloudie.sh Support. But please be aware that delays may occur due to the level of large volume of requests at the current time.
    
    Our Assurance:
    
    We are deeply committed to the security of your data and are taking all necessary steps to prevent such incidents in the future. We sincerely apologize for any inconvenience caused and appreciate your cooperation during this critical time.
    
    
    
    Best Regards,
    
    Cloudie Networks, LLC.
    
  • @treesmokah said:
    New email they allegedly sent out just now(from OGF)

    I received this email, so can confirm that it is more than alleged to have been sent.

  • @tetech said:

    @treesmokah said:
    New email they allegedly sent out just now(from OGF)

    I received this email, so can confirm that it is more than alleged to have been sent.

    Although I didn't compare the quoted version word-for-word :p

  • @MannDude said: OGF says Cloudie's Discord mods are deleting mentions who bring it up in their chat, and nothing has been sent to their customers from Cloudie yet. :(

    Can confirm they do some crazy damage control, I was banned before I even managed to join, for some reason.

  • MannDudeMannDude Provider IncogNET - Speech and Privacy
    edited December 2023

    Wider Industry Effect: The breach has repercussions for several providers, especially those using modules like WHMCSServices and WHMCSGlobalServices.

    Email suggests that the original breach may have occurred from module(s) provided by https://www.whmcsservices.com/ or https://whmcsglobalservices.com/ ?

    WHMCSServices was mentioned previously, since it appeared to be a supply chain attack where they were hacked, and the hackers then sent an email with a file link to 'update' a module used which was what allowed access to other user's WHMCS. Is that correct?

    This is the first I'm hearing of WHMCSGlobalServices being in the mix of blame, can anyone confirm?

  • Otus9051Otus9051 The Original Freeloader

    @treesmokah are you still giving the download link to people

    youtube.com/watch?v=k1BneeJTDcU

  • FrankZFrankZ ModeratorOG

    @Otus9051 said:
    @treesmokah are you still giving the download link to people

    I would hope that was just a one time deal and he is not handing out the link to everyone who asks.

  • edited December 2023

    @Otus9051 said:
    @treesmokah are you still giving the download link to people

    Yes.

    @FrankZ said:

    @Otus9051 said:
    @treesmokah are you still giving the download link to people

    I would hope that was just a one time deal and he is not handing out the link to everyone who asks.

    I do, everyone who reached out was a long time member that was most likely affected and wanted to check for himself. Everyone with malicious intents already have it, its public, I'm not doing anyone any harm by providing it to affected people.

  • @treesmokah said:

    @treesmokah are you still giving the download link to people

    Yes.

    I do, everyone who reached out was a long time member that was most likely affected and wanted to check for himself. Everyone with malicious intents already have it, its public, I'm not doing anyone any harm by providing it to affected people.

    I just sent a dm. Thnx

  • FrankZFrankZ ModeratorOG
    edited December 2023

    @treesmokah said:

    @Otus9051 said:
    @treesmokah are you still giving the download link to people

    Yes.

    @FrankZ said:

    @Otus9051 said:
    @treesmokah are you still giving the download link to people

    I would hope that was just a one time deal and he is not handing out the link to everyone who asks.

    I do, everyone who reached out was a long time member that was most likely affected and wanted to check for himself.

    I would consider passing around links to a hacked data base of customer information a black hat activity.
    I would like to hear other members thoughts on this.

  • edited December 2023

    @FrankZ said:

    @treesmokah said:

    @Otus9051 said:
    @treesmokah are you still giving the download link to people

    Yes.

    @FrankZ said:

    @Otus9051 said:
    @treesmokah are you still giving the download link to people

    I would hope that was just a one time deal and he is not handing out the link to everyone who asks.

    I do, everyone who reached out was a long time member that was most likely affected and wanted to check for himself.

    I would consider passing around links to a hacked data base of customer information a black hat activity.
    I would like to hear other members thoughts on this.

    I can stop If you want, but I find gatekeeping already public leak to be pointless. Nobody with malicious intents will come here and request it from me.
    I personally do not find anything what I did wrong, I did due diligence on people requesting it and decided to pass it to them.

    Cloudie presented misleading information stating no personal information was leaked, so I'd rather want affected people to not take his words on the leak and check for themselves.
    It can also be used for research and documenting his incompetence and negligence.

  • FrankZFrankZ ModeratorOG
    edited December 2023

    In my mind it is not that the information is known to be out in the wild, it's a question of if passing that data around is the right thing to do for a white hat forum. In my mind you should stop as people already know if they are affected because the hackers have probably already notified them directly.

  • webmashwebmash Retired
    edited December 2023

    It's out in the wild, with more leaks being dumped of other providers. Don't see an issue with treesmokah, they haven't posted any links publicly or looking to gain from it. Sad for anyone that's been breached... quite awful

  • mikhomikho AdministratorOG Bash Me Gently

    @treesmokah said:

    @FrankZ said:

    @treesmokah said:

    @Otus9051 said:
    @treesmokah are you still giving the download link to people

    Yes.

    @FrankZ said:

    @Otus9051 said:
    @treesmokah are you still giving the download link to people

    I would hope that was just a one time deal and he is not handing out the link to everyone who asks.

    I do, everyone who reached out was a long time member that was most likely affected and wanted to check for himself.

    I would consider passing around links to a hacked data base of customer information a black hat activity.
    I would like to hear other members thoughts on this.

    I can stop If you want, but I find gatekeeping already public leak to be pointless. Nobody with malicious intents will come here and request it from me.
    I personally do not find anything what I did wrong, I did due diligence on people requesting it and decided to pass it to them.

    Cloudie presented misleading information stating no personal information was leaked, so I'd rather want affected people to not take his words on the leak and check for themselves.
    It can also be used for research and documenting his incompetence and negligence.

    I would prefer if you stopped doing it, at least on LES.

    the DB is stolen from Cloudie and handing out stolen property/goods is a felony in my book.

    If people are interested in the DB for ”research” or to ”check ” if their data is in it.
    Since its in the public, let them search for it.

    And they should already know if they are, or have been, a customer. In that case they should assume that their data has been sold/given away to other people and change their password (if they haven’t already).

    I’m not saying that I’m an expert in GDPR, but spreading other peoples personal information (as you do by gicing out links to the DB), even you could face charges in the EU.

    In short, let interested people search for it.

    “Technology is best when it brings people together.” – Matt Mullenweg

  • In general I don't see a problem with passing around the link because it's widely available. However, I doubt this forum is the right place for it and thus it shouldn't be distributed here. Making aware that there's a public link is ok but we shouldn't be a place where things like this are exchanged, it's a different scope.

  • @mikho said: I would prefer if you stopped doing it, at least on LES.

    All right, I will.
    Thanks for presenting your points, I'm sure I wouldn't be prosecuted for it, but I respect you.

  • mikhomikho AdministratorOG Bash Me Gently

    To clarify, we can still discuss the breach but do not spread the material.

    “Technology is best when it brings people together.” – Matt Mullenweg

  • JabJab TOP Member 2027

    Yeah - name who else got hacked and why the fuck I did spam on my phonenumber (-:

    Haven't bought a single service in VirMach Great Ryzen 2022 - 2023 Flash Sale.

Sign In or Register to comment.