
Open-Xchange says an attacker exploited a vulnerability in its community forum software and extracted account records from the forum database on July 28, 2026. The company has taken the forum offline and plans to permanently decommission it.
Open-Xchange has notified members of its community forum about a security breach involving personal information and account data.
According to the notification sent to affected users, an attacker exploited a vulnerability in the software operating forum.open-xchange.com and gained access to its database on July 28, 2026.
Forensic investigators determined that the attacker extracted the forum’s user table, including records associated with registered community members.
Open-Xchange took the forum offline after discovering the incident. The forum has remained unavailable, and the company says it will now be permanently decommissioned rather than restored.
What information was exposed?
The compromised records may include:
- Usernames and display names
- Email addresses
- IP addresses
- Registration dates
- Last login, visit and activity dates
- User ranks or titles
- Post and topic counts
- Profile visit counters
- Language and time-zone settings
- Thread display preferences
- Notification preferences
- Website links
- Private-message counters
- Technical account-profile information
- Session identifiers used to keep users signed in
Open-Xchange says any exposed session identifiers have been invalidated.
The company has not disclosed how many forum accounts were affected.
Password hashes were also taken
The extracted database included forum password hashes.
Open-Xchange says passwords were not stored in readable text. Instead, they were protected using Argon2id with an individual salt for each account.
Argon2id is a modern, memory-intensive password-hashing method designed to make large-scale password guessing significantly more expensive. Individual salts also prevent an attacker from testing one calculated hash against every account simultaneously.
However, hashing does not make passwords impossible to recover. An attacker who possesses the database can potentially perform offline guesses against individual hashes, particularly when users selected short, common or previously exposed passwords.
Users should therefore change the password anywhere else it was reused, even though Open-Xchange says it has no evidence that passwords have been recovered from the hashes.
No payment or customer-system data affected
Open-Xchange says the community forum operated separately from its product and customer infrastructure.
The company reports that:
- No payment information was affected.
- No readable passwords were stored in the forum database.
- There is no indication that Open-Xchange product systems were accessed.
- There is no indication that customer email accounts or hosted data were affected.
Based on the information currently available, the incident appears limited to the standalone community forum.
Phishing is the most immediate risk
Exposed usernames and email addresses could be used to create convincing phishing messages.
Attackers may send emails pretending to come from Open-Xchange, the former community forum or an associated service. These messages could mention the breach and ask recipients to reset a password, verify an account or download a security update.
Affected users should be especially suspicious of messages that:
- Create urgency around the forum breach
- Ask for an existing password
- Include unexpected login or password-reset links
- Request payment or personal information
- Contain attachments described as security reports or account records
- Claim that additional Open-Xchange services have been compromised
Open-Xchange says it will not ask users to provide their passwords by email.
What affected users should do
Anyone who had an account at forum.open-xchange.com should take the following precautions:
Change reused passwords
The forum itself is being decommissioned, but users should immediately change the password on any other account where the same or a similar password was used.
Every important account should have its own unique password.
Enable multi-factor authentication
Enable multi-factor authentication wherever it is available, particularly for email, domain-management, hosting and administrative accounts.
An authenticator application or hardware security key generally provides stronger protection than relying only on a password.
Be alert for targeted phishing
Do not sign in through links contained in unexpected breach-related emails. Open the relevant service by typing its known address directly into the browser or using an existing bookmark.
Review important accounts
Check email, hosting, domain and other sensitive accounts for unfamiliar login activity, forwarding rules, password changes or recovery-address changes.
Use a password manager
A password manager can create and store a different, randomly generated password for each service. This limits the damage when one website’s password database is compromised.
Open-Xchange’s response
Open-Xchange says it has taken the following actions:
- Took the community forum offline
- Preserved and secured the system for forensic investigation
- Changed database credentials
- Invalidated active forum sessions
- Decided to permanently decommission the forum
- Reported the incident to the appropriate data-protection supervisory authority
The notification does not identify the vulnerability that was exploited, the forum-software product involved, the attacker or the total number of affected accounts.
It also does not state whether the extracted database has been published, sold or offered on a criminal forum.
Questions remain
Further disclosure from Open-Xchange would help clarify the full scale and technical circumstances of the incident.
Important unanswered questions include:
- How many community members were affected?
- Which forum software and version were compromised?
- How long was the vulnerability present?
- Was the flaw previously known or assigned a CVE?
- Were private-message contents exposed, or only message counters?
- What Argon2id cost parameters were used?
- Has the stolen database appeared online?
- Was the attacker able to access administrative accounts or forum files?
Open-Xchange has directed privacy-related questions to its Data Protection Officer at security-notice@open-xchange.com.
This incident does not indicate an Open-Xchange email breach
It is important to distinguish the compromised community forum from Open-Xchange’s email and collaboration platforms.
Based on the company’s notification, the attacker accessed the database associated with forum.open-xchange.com. Open-Xchange says it has found no evidence that its product, customer or payment systems were affected.
Users should still remain cautious about phishing messages that falsely claim their Open-Xchange email account was compromised.
Conclusion
The Open-Xchange forum breach exposed enough account information to create meaningful phishing and password-reuse risks, even though payment information and readable passwords were not present.
Argon2id provides stronger protection than outdated or fast password-hashing methods, but it cannot fully protect weak or reused passwords after a database has been stolen.
Affected community members should change reused passwords immediately, enable multi-factor authentication and carefully scrutinize messages referring to the incident.
This report is based on a security notification sent by Open-Xchange to affected community-forum members. Security-Breaches.com has not independently verified the number of records extracted or the vulnerability used in the attack.
0 Comments