Des pirates revendiquent le piratage d’un miroir de Coco
A mirror site for the defunct Coco discussion forum, presented as a successor to the original site shut down due to illegal activities, has been compromised by the threat actor CuteSec. The attackers gained extensive control, exfiltrated a database containing over 14,500 user accounts, including credentials, email addresses, IP addresses, connection dates, and hashed passwords, along with server-related data and internal communications. This incident highlights a significant data breach and a broader loss of technical control.
A mirror site for the Coco discussion forum, known for its controversial and unregulated environment, has been compromised. The original Coco site was shut down on June 25, 2024, following investigations into illegal activities, including child exploitation and cybercrime. Following the original site’s closure, several successor platforms emerged online, including Chat Coco, which presented itself as a mirror site.
CuteSec, a threat actor previously unknown, claimed responsibility for the attack, which occurred on August 3, 2026. The attackers gained full control of the server, replacing the page with a black background message and a link to an archive containing over 14,500 user accounts.
The data exfiltrated included user credentials, email addresses, IP addresses, connection dates, and hashed passwords stored with a salt. The presence of a salt doesn’t automatically indicate strong password protection, as the robustness depends on the hashing algorithm and its parameters, which require further confirmation.
Beyond the user database, the attackers also obtained SSH private keys, server-related SMTP elements, automated backups, administrative webmail access, and internal and external email communications. This combination represents a critical intelligence concern, as a user database provides a mapping of registered individuals, while connection logs can potentially link accounts to specific IP addresses and time periods. The internal communications reveal technical organization, contacts, and internal procedures.
CuteSec offered a free SQL archive, weighing 7.34 MB after compression, containing a 36.7 MB database. SHA-256 hashes were also provided to identify the files disseminated. Furthermore, other individuals have been disseminating personal information related to the presumed administrator, including a photo and postal address.
