Nextcloud site hacked and redirected to phishing | official framing hides likely WP2Shell root cause
TL;DR
Nextcloud's official site was hacked and redirected to a phishing site on the afternoon of July 19. Officially framed as an "infrastructure problem," but the community saw through it — Nextcloud's site runs on WordPress, and the incident falls within 48 hours of WP2Shell (CVE-2026-63030) hitting in-the-wild exploitation.
Open-source private-cloud software Nextcloud's official site was hacked on the afternoon of July 19 — the main domain was redirected to a phishing site. After anomaly reports, admins took the main site offline; Nextcloud IT publicly framed it as an "infrastructure problem" being restored from data — without mentioning the hack.
The community saw through it immediately. Nextcloud's own site runs on WordPress — and the timing lands within 48 hours of WordPress WP2Shell unauthenticated RCE (CVE-2026-63030) being confirmed in-the-wild. The cleanest hypothesis: Nextcloud's WordPress instance failed to update to 7.0.2 in time and got popped by WP2Shell — but the official chose the "infrastructure" euphemism.
Nextcloud is a German open-source private-cloud platform, positioned as the "replace Google Drive / Dropbox" privacy-and-self-host play, with hundreds of thousands of deployments estimated worldwide. As the flag-bearer of "don't let public cloud own your data," getting popped through its own WordPress plus obfuscating the cause is a double image hit — users hand over their privacy expecting the first layer of trust to hold on the official site.
The proper response would be "transparent disclosure + rapid patch." Nextcloud's fog-of-narrative choice instead amplifies the community's suspicion — the probability that WordPress got popped goes from 60% to 90% precisely because "refusing to admit it" is usually confirmation.
Emergency restoration is done, but "main site redirected to phishing" is going to live in SEO snapshots and internet history for a long time — the kind of brand incident a privacy project cannot afford.
via landiannews / Nextcloud on Mastodon
The community saw through it immediately. Nextcloud's own site runs on WordPress — and the timing lands within 48 hours of WordPress WP2Shell unauthenticated RCE (CVE-2026-63030) being confirmed in-the-wild. The cleanest hypothesis: Nextcloud's WordPress instance failed to update to 7.0.2 in time and got popped by WP2Shell — but the official chose the "infrastructure" euphemism.
Nextcloud is a German open-source private-cloud platform, positioned as the "replace Google Drive / Dropbox" privacy-and-self-host play, with hundreds of thousands of deployments estimated worldwide. As the flag-bearer of "don't let public cloud own your data," getting popped through its own WordPress plus obfuscating the cause is a double image hit — users hand over their privacy expecting the first layer of trust to hold on the official site.
The proper response would be "transparent disclosure + rapid patch." Nextcloud's fog-of-narrative choice instead amplifies the community's suspicion — the probability that WordPress got popped goes from 60% to 90% precisely because "refusing to admit it" is usually confirmation.
Emergency restoration is done, but "main site redirected to phishing" is going to live in SEO snapshots and internet history for a long time — the kind of brand incident a privacy project cannot afford.
via landiannews / Nextcloud on Mastodon