Warning! The ColoCrossing database appears to have been compromised.

2»

Comments

  • MasonMason OG
    edited May 2025

    Did CC admit they fucked up and properly notify the people affected on what was accessed yet?

    Nope. Looks like they're sticking with their Virtualizor bug story despite no other providers being affected that leverage Virtualizor and continue to say nothing important was accessed/breached. Can't say I'm surprised in the slightest.

    If anyone is/was wondering why LES exists, this is Exhibit #754.

    yabs daddy

  • @Mason said:

    Looks like they're sticking with their Virtualizor bug story

    Also known as Dog ate my homework, excuse # 420

  • @Mason said:
    Did CC admit they fucked up and properly notify the people affected on what was accessed yet?

    Nope. Looks like they're sticking with their Virtualizor bug story despite no other providers being affected that leverage Virtualizor and continue to say nothing important was accessed/breached. Can't say I'm surprised in the slightest.

    If anyone is/was wondering why LES exists, this is Exhibit #754.

    The most funny part is, providers that abused that dump to spam people, got insta banned.
    But CC is still fine.

  • @Neoon said:

    @Mason said:
    Did CC admit they fucked up and properly notify the people affected on what was accessed yet?

    Nope. Looks like they're sticking with their Virtualizor bug story despite no other providers being affected that leverage Virtualizor and continue to say nothing important was accessed/breached. Can't say I'm surprised in the slightest.

    If anyone is/was wondering why LES exists, this is Exhibit #754.

    The most funny part is, providers that abused that dump to spam people, got insta banned.
    But CC is still fine.

    Also there is already phishing emails sent to the leaked email addresses, despite CC still saying "no personal information" was leaked.

  • somiksomik OG Hostbusters

    @tetech said:

    @Neoon said:

    @Mason said:
    Did CC admit they fucked up and properly notify the people affected on what was accessed yet?

    Nope. Looks like they're sticking with their Virtualizor bug story despite no other providers being affected that leverage Virtualizor and continue to say nothing important was accessed/breached. Can't say I'm surprised in the slightest.

    If anyone is/was wondering why LES exists, this is Exhibit #754.

    The most funny part is, providers that abused that dump to spam people, got insta banned.
    But CC is still fine.

    Also there is already phishing emails sent to the leaked email addresses, despite CC still saying "no personal information" was leaked.

    They probably consider their customers to be companies, which means the email is no longer a "personal information". I am guessing same goes for their other customer details. This is why you should avoid using personal information online.

    I speak fluent sarcasm and broken logic. | I would agree with you, but thæn we’d both be wrong.

  • @somik said:

    @tetech said:

    @Neoon said:

    @Mason said:
    Did CC admit they fucked up and properly notify the people affected on what was accessed yet?

    Nope. Looks like they're sticking with their Virtualizor bug story despite no other providers being affected that leverage Virtualizor and continue to say nothing important was accessed/breached. Can't say I'm surprised in the slightest.

    If anyone is/was wondering why LES exists, this is Exhibit #754.

    The most funny part is, providers that abused that dump to spam people, got insta banned.
    But CC is still fine.

    Also there is already phishing emails sent to the leaked email addresses, despite CC still saying "no personal information" was leaked.

    They probably consider their customers to be companies, which means the email is no longer a "personal information". I am guessing same goes for their other customer details. This is why you should avoid using personal information online.

    I don't think the majority of privacy authorities would accept "we consider our customers to be companies" as a reason for misleading individuals about the disclosure of their personal information. Especially if the "Company" field is left blank in the profile.

  • somiksomik OG Hostbusters

    @tetech said:

    @somik said:
    They probably consider their customers to be companies, which means the email is no longer a "personal information". I am guessing same goes for their other customer details. This is why you should avoid using personal information online.

    I don't think the majority of privacy authorities would accept "we consider our customers to be companies" as a reason for misleading individuals about the disclosure of their personal information. Especially if the "Company" field is left blank in the profile.

    So what you are saying is to make the company field compulsory to circumvent the law... :lol:

    I speak fluent sarcasm and broken logic. | I would agree with you, but thæn we’d both be wrong.

  • I was a past unhappy customer of Colocrossing. If anyone wants to learn how not to run a hosting business, this is a good example. Not surprised about this breach.

  • it's really impressive with how spineless LET is

    https://haveibeenpwned.com/Breach/ColoCrossing

    Fuck this 24/7 internet spew of trivia and celebrity bullshit.

  • @Encoders said: it's really impressive with how spineless LET is

    In what sense? Do you really think that John would bite hand which feeds him? Get a grip. LET is in business to make money, that's it. There is no real ethics, morale or inclination to "be right". Everything is to forget. As soon as CC launch 7$/year - all crap will be wiped out of memory. It always was like this, always is and always be. Low end cares only for $7.

  • It does not matter how good of a deal CC launches; I will never sign up for their service again. In fact, I will never go back to past providers that sucked. The providers that suck will either survive (by selling services to large enterprises) or just disappear.

    Ultimately, it all comes down to good service and good will. Tech savvy customers, as opposed to average Joes, do not repeat their mistakes in the market.

  • host_chost_c Provider

    In my opinion, a data breach is one of the worst things that can happen in the IT world. ( the worst period :) )

    That said, I don’t think Virtualizor is the only one at fault here. Software today is often built in “fast-forward” mode—features rushed out, deadlines tight, and security sometimes seen as a lower priority ( or none in some cases ). They're not the first to get breached, and sadly, they won’t be the last.

    If we were to stop using every provider that had a security incident, even well-known enterprise vendors would be out of the picture. The real issue lies in the overall quality and security practices of the software—not just whether they've had a breach.

    What’s ironic is that when a provider does try to take security seriously—by enforcing things like KYC (Know Your Customer)—they often get bashed for it. People complain: “that nerd is doing KYC, he sucks,” even though it's part of a serious effort to improve trust and prevent abuse.

    So in the end, we can’t have it both ways. We either accept stronger security—even if it's inconvenient—or we keep playing whack-a-mole with breaches and blaming whoever happens to get hit next.

    Whatever worked 5 years ago will not take us further.

    Host-C | Storage by Design | AS211462

    “If it can’t guarantee behavior under load, it doesn’t belong in production.”

  • A data breach is annoying, but it can happen to anyone.

    What defines a company is how they respond to it. ColonCrossing have pretty much lied from the start, still haven't actually bothered notifying everyone whose personal data was lost, and the few they have talked to seem to have got the message "ahh well it's working again, what you complaining about?"

    I mean I always knew they were pretty bad, and only have stuff running with them because I won some free credits but if I'd ever actually paid them a cent, I'd be fuming.

  • AuroraZeroAuroraZero Retired
    edited June 2025

    @ahnlak said:
    A data breach is annoying, but it can happen to anyone.

    What defines a company is how they respond to it. ColonCrossing have pretty much lied from the start, still haven't actually bothered notifying everyone whose personal data was lost, and the few they have talked to seem to have got the message "ahh well it's working again, what you complaining about?"

    I mean I always knew they were pretty bad, and only have stuff running with them because I won some free credits but if I'd ever actually paid them a cent, I'd be fuming.

    ColonCleansing has never told the truth since its inception

    The Yeti has left the building.

  • tentortentor Provider
    edited June 2025

    @host_c said:
    In my opinion, a data breach is one of the worst things that can happen in the IT world. ( the worst period :) )

    That said, I don’t think Virtualizor is the only one at fault here. Software today is often built in “fast-forward” mode—features rushed out, deadlines tight, and security sometimes seen as a lower priority ( or none in some cases ). They're not the first to get breached, and sadly, they won’t be the last.

    If we were to stop using every provider that had a security incident, even well-known enterprise vendors would be out of the picture. The real issue lies in the overall quality and security practices of the software—not just whether they've had a breach.

    I partially disagree here. It is not only "lower priority" in software development world, it is lower priority for any business. There are for sure some exclusions but they are rare. What drives the business? Profit, and in the end it is features features features (if we are talking about any IT product). You can't "sell" proper security policies to the C-level. And security is what usually has the lowest budget.

    What’s ironic is that when a provider does try to take security seriously—by enforcing things like KYC (Know Your Customer)—they often get bashed for it. People complain: “that nerd is doing KYC, he sucks,” even though it's part of a serious effort to improve trust and prevent abuse.

    Enforcing KYC is often done for compliance reasons (which is not a real security) and it is additional risks business must handle. Leaked emails and leaked IDs/SSNs are of very different severity.

    So in the end, we can’t have it both ways. We either accept stronger security—even if it's inconvenient—or we keep playing whack-a-mole with breaches and blaming whoever happens to get hit next.

    Having KYC and caring abour customer data are different topics, so I am disagreeing completely here.

    Whatever worked 5 years ago will not take us further.

    Check our KVM VPS plans in 🇵🇱 Warsaw, Poland and 🇸🇪 Stockholm, Sweden

  • is there a list somewhere of which hosts at LET are allowed to be hacked due to their own laziness, lose customer PII, lie about it, continue to lie once it's in the media, then keep their vendor account?

    is it just:

    • RackNerd
    • *Crossing

    ?

  • @grasple said:
    is there a list somewhere of which hosts at LET are allowed to be hacked due to their own laziness, lose customer PII, lie about it, continue to lie once it's in the media, then keep their vendor account?

    is it just:

    • RackNerd
    • *Crossing

    ?

    maybe torchbyte

  • WSSWSS OG Guru Meditation Error

    Imagine using CC in 2025. LoL. LMAO, even.

    "It's a hard life- to be a stick insect." - Karl Pilkington

  • @WSS said:
    Imagine using CC in 2025. LoL. LMAO, even.

    You need a ColonCleansing?

    The Yeti has left the building.

Sign In or Register to comment.