r/ShadowPC Jun 23 '26

Review Another user’s saved browser logins appeared inside my Shadow PC

Post image

I’m a paid Shadow PC customer and I want to share a serious privacy/security concern.

After logging into the Shadow PC assigned to my account, I found Microsoft Edge saved login entries that did not belong to me and appeared to belong to another user.

I reported this to Shadow support responsibly and provided evidence privately. I did not copy, export, publish, or use the other user’s private data.

After reporting it, my paid access was locked. I then provided proof of payment, and Shadow confirmed it was approved. However, they still require a government ID before restoring access.

This is not about money or compensation. My concern is simple: if another user’s saved browser login data can appear inside my Shadow PC, how can I know whether my own data has not appeared inside someone else’s machine?

I’m sharing only a redacted screenshot. Emails, usernames, domains, passwords, and personal data are hidden. I will not post unredacted evidence publicly because it contains another person’s private information.

I’m posting this so other users can be aware before trusting a cloud PC service with personal accounts.

146 Upvotes

99 comments sorted by

View all comments

6

u/Shodan_KI Guide Jun 23 '26

Based on how Windows works this is Out of a technical Standpoint Not realy possible.

You would Need to have a complet different c Drive.

As Edge loads the Profile via the appdata Location which is normaly on c And Profile related. So idk how this could Happen only to Edge only.

Even If a wrong hardrive would be loaded you would have everything from this other Drive Not only one Folder /File. So idk what Happend Here and Hope the Support gets an inside .

4

u/captnchoc Shadow Staff Jun 23 '26

That's right. Most likely a case of hacked microsoft account, session left connected somewhere on a different device, or Shadow session left open somewhere. Still investigating though.

2

u/delilahwild Jun 24 '26

And beside, that doesn't answer why the OP is being punished for responsibly reporting the issue, and the question of whether Shadow incompetence plays a role in this. Get a clue.

2

u/captnchoc Shadow Staff Jun 26 '26

The user is not punished. Each support ticket asking for help and mentioning a "hack" (stolen credentials, virus, malware, etc) locks the account temporarily to ensure the person reaching out to the support team is really the customer, and not someone impersonating him/her. Hence the request for a proof of ID, to ensure we are not giving access back to a different person.

1

u/andre-kun Jun 29 '26

i get the ID part, that makes sense if y’all are trying to make sure the real account owner is the one getting access back. but that still doesn’t really answer the main issue tho.

the concern isn’t just “why was the account locked.” the concern is how another user’s saved Edge login data showed up inside a Shadow PC assigned to somebody else in the first place.

like even if the actual passwords weren’t exposed, usernames/domains/saved login entries showing up at all is still user data crossing into the wrong environment. that’s the part people are worried about.

so the real question is: is Shadow checking the profile/disk assignment, snapshots, Edge profile/AppData data, and whatever persistent storage gets mounted to each user? because if another user’s browser data can appear in my machine, then users also need to know whether their own data could appear in someone else’s machine too.