Skip to main content
Back to overview
Medium

Hacker steals 1 million Cock.li user records in webmail data breach

Hacker steals 1 million Cock.li user records in webmail data breach Email hosting provider Cock.li has confirmed it suffered a data breach after threat actors exploited flaws in its now-retired Roundcube webmail…

Key points

  • Over 1 million user records exposed (1,023,800 user accounts).
  • Exposed data includes email addresses, login timestamps, failed login attempts, language, Roundcube settings, email signatures, and contact entries (for 93,000 users).
  • Breach attributed to an old Roundcube SQL injection vulnerability (CVE-2021-44026).

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Ransomware

Threat source not confirmed

03

Potential impact

Data Exposure

Confidentiality, Availability

Published
Jun 17, 2025
Updated
Jul 22, 2026
Confidence
Medium
Evidence
1 source

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch ransomware, endpoint compromise and business interruption exposure.

Business impact

Potential operational disruption
Impact area
Confidentiality, Availability
Likely asset
User or customer data

Mentioned entities

CockData DisclosureHackerEmailRoundcubeGermany-basedVincent CanfieldSMTPIMAPTLS. Cock.li

Quick context

Questions about this signal

What happened in this signal?

Hacker steals 1 million Cock.li user records in webmail data breach Email hosting provider Cock.li has confirmed it suffered a data breach after threat actors exploited flaws in its now-retired Roundcube webmail platform to steal over a million user records. The incident exposed all users who had logged in to the mail service since 2016, estimated at 1,023,800 people, along with contact entries for an additional 93,000 users. Cock.li is a Germany-based free email hosting provider with a privacy-focused ethos and lax moderation policies, run by a single operator known as 'Vincent Canfield' since 2013. It is promoted as an alternative to mainstream email providers, supporting standard security protocols like SMTP, IMAP, and TLS. Cock.li is used by people who distrust major providers and members of infosec and open-source communities. It is also popular among cybercriminals, such as affiliates from Dharma, Phobos, and other ransomware gangs. Late last week, the Cock.li service was disrupted without public explanation, leaving users wondering what might have happened. Soon after, a threat actor claimed to be selling two databases containing dumped from Cock.li that contained sensitive user information, offering them for sale for a minimum of one Bitcoin ($92.5k). Cock.li published a statement on its website yesterday, confirming the breach and the validity of the threat actor's claims. The email service confirmed that the following information has been exposed for 1,023,800 user accounts: A serialized blob of Roundcube settings and email signature Contact names (only for a subset of 10,400 accounts) Contact email addresses (only for a subset of 10,400 accounts) vCards (only for a subset of 10,400 accounts) Comments (only for a subset of 10,400 accounts) The service's announcement clarifies that user account passwords, email content, and IP addresses were not compromised, as these are not present in the stolen databases. Meanwhile, the 10,400 account holders who had third-party contact information exposed will be getting a separate notification. For everyone who used the service since 2016, it is recommended to reset their account passwords. The Cock.li data breach could be valuable to researchers and law enforcement, as the exposed information can be used to learn more about the threat actors who use the platform. Cock.li says they believe the data was stolen using an old RoundCube SQL injection vulnerability tracked as CVE-2021-44026. This breach comes just as Cock.li recently analyzed an RCE flaw in Roundcube, CVE-2025-49113, which is believed to be actively exploited in attacks . Their analysis led them to remove the software from their platform in June 2025. "Cock.li will no longer be offering Roundcube webmail," explained the service admins. "Regardless of whether our version was vulnerable to this, we've learned enough about Roundcube to pull it from the service for good." "Another webmail is definitely on the table, but it is not an immediate priority for us."

When was this signal reported?

Shadow Tier lists Jun 17, 2025 as the signal date.

Which organization is connected to this signal?

Cock is the organization connected to this public signal.

Explore Cock
Which attack pattern is relevant?

This signal is connected to current ransomware incidents based on its reported incident context.

Explore current ransomware incidents
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence