File sharing platform ownCloud has issued an urgent warning to its users, urging them to immediately enable multi-factor authentication (MFA) to prevent eavesdropping and malicious access to sensitive data. The recommendation comes at a time of increased activity by cybercriminals who are exploiting compromised credentials rather than technical attacks on the platforms themselves.

A platform with a huge footprint
With more than 200 million users worldwide, ownCloud is a key collaboration and file sharing for businesses and public sector organizations. Its list of users includes leading institutions such as the European Organization for Nuclear Research (CERN), the European Commission, the European Investment Bank, as well as large companies such as ZF Group and Swiss Life. The size and importance of the ecosystem make the platform an attractive target for cybercriminals.
See also: United Kingdom: Strengthening cyber defense in the public sector
What really happened?
According to an official statement from ownCloud, there was no breach of the platform itself or exploitation of zero-day vulnerabilities. The company clarifies that the recently disclosed incidents are related to a different attack chain: the theft of user credentials via infostealer malware .
The warning was based on a report by Israeli cybersecurity firm Hudson Rock, which revealed that attackers gained access to self-hosted file sharing platforms (including ownCloud Community Edition instances) using stolen usernames and passwords.

The role of infostealers in the attack chain
RedLine, Lumma and Vidar malware are at the heart of these attacks. These infostealers infect employee devices and steal stored credentials, cookies and login tokens. The attackers then test this data on corporate platforms, taking advantage of the fact that many accounts are still password-protected.
As ownCloud points out, the attacks were only successful on accounts without MFA enabled, which highlights the importance of multi-layered security.
See also: Chinese hackers actively attack Taiwan's critical infrastructure
What does ownCloud recommend to organizations?
In addition to immediately enabling MFA, the company recommends a number of additional defense measures. These include resetting all passwords, canceling active sessions to enforce reauthentication, and thoroughly checking logs for suspicious login attempts.
This approach reflects a modern security philosophy, where credential breach is considered inevitable and protection is based on limiting the consequences.
The underground market for stolen corporate data
The warning from ownCloud comes after a threat actor named Zestixoffered to sell corporate data allegedly stolen from dozens of organizations. The data was reportedly obtained through unauthorized access to platforms such as ShareFile, Nextcloud, and ownCloud.

Hudson Rock, in a report on January 5, said it had identified thousands of infected computers on corporate networks, including well-known organizations such as Deloitte, KPMG, Samsung, Honeywell, Walmart and the US CDC. The scope of the infections shows how widespread the infostealers problem is.
See also: Chrome extensions have stolen conversations from ChatGPT and DeepSeek
MFA as a basic line of defense
The ownCloud case confirms a harsh reality: passwords alone are no longer enough. In an environment where credentials are sold en masse on underground marketplaces, multi-factor authentication acts as a critical filter that can prevent disaster, even when the first factor is already lost.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
For organizations and businesses, the message is clear. Security is not just about technology, but also about strategic preparedness against ever-evolving threats. And in this battle, MFA is no longer an option, but a necessity.
Source: www.bleepingcomputer.com
