A major security breach at email hosting provider Cock[.]li has compromised personal data from over one million users, the company announced in an official statement. The incident specifically targeted the service’s Roundcube webmail platform, affecting approximately 1,023,800 users who had accessed webmail since 2016.
The hackers successfully extracted two critical database tables containing sensitive user information. The stolen data includes email addresses, webmail login timestamps, failed login attempts, language preferences, and serialized user settings, including signatures and personal configurations.
Additionally, contact information for around 93,000 entries from approximately 10,400 users was compromised, containing names, email addresses, vCards, and comments.
Despite the extensive nature of the breach, Cock[.]li officials emphasized that passwords, actual email content, and IP addresses were not compromised. The company explained that passwords were stored in a separate “sessions” table that was apparently not included in the leaked data.
Email Hosting Provider Cock.li Hacked
Following the discovery of the breach, Cock[.]li immediately discontinued its Roundcube webmail service. The company strongly advised all users who had accessed webmail since 2016 to change their passwords as a precautionary measure.
The stolen database is reportedly being offered for sale at a “hefty price” on underground markets. In an unusual move, the company offered to provide usernames directly to Have I Been Pwned (HIBP) to help users determine if their data was compromised.
Cock[.]li attributed the breach to CVE-2021-44026, a potential SQL injection vulnerability affecting Roundcube versions prior to 1.4.121.
The company acknowledged they had updated the software “long ago” but suggested attackers may have held the compromised data for an extended period.
Interestingly, the announcement revealed that a more recent critical vulnerability, CVE-2025-49113, which enables remote code execution, was not exploitable on Cock.li’s systems due to their use of an end-of-life branch of Roundcube.
The incident has prompted Cock[.]li to permanently remove Roundcube from their services. While the company indicated that alternative webmail solutions are “definitely on the table,” they stated it is not an immediate priority, suggesting users should adopt dedicated email clients instead.
The company issued a formal apology, describing the incident as “an exception to an otherwise cautious security philosophy and structure”. This breach serves as another reminder of the ongoing cybersecurity challenges facing email service providers and the importance of robust security measures in protecting user data.
Live Credential Theft Attack Unmask & Instant Defense – Free Webinar
