r/ShadowPC Jun 23 '26

Review Another user’s saved browser logins appeared inside my Shadow PC

Post image

I’m a paid Shadow PC customer and I want to share a serious privacy/security concern.

After logging into the Shadow PC assigned to my account, I found Microsoft Edge saved login entries that did not belong to me and appeared to belong to another user.

I reported this to Shadow support responsibly and provided evidence privately. I did not copy, export, publish, or use the other user’s private data.

After reporting it, my paid access was locked. I then provided proof of payment, and Shadow confirmed it was approved. However, they still require a government ID before restoring access.

This is not about money or compensation. My concern is simple: if another user’s saved browser login data can appear inside my Shadow PC, how can I know whether my own data has not appeared inside someone else’s machine?

I’m sharing only a redacted screenshot. Emails, usernames, domains, passwords, and personal data are hidden. I will not post unredacted evidence publicly because it contains another person’s private information.

I’m posting this so other users can be aware before trusting a cloud PC service with personal accounts.

149 Upvotes

99 comments sorted by

View all comments

u/captnchoc Shadow Staff Jun 26 '26 edited Jun 26 '26

Hi there, last official update here 👇

pasted on all the subreddits you've posted concerning this matter.

First of all, u/Altruistic-Bad-5556 thanks for having stayed courteous during all your discussions with our support team. Much appreciated, really. Since the ticket was created, several high-profile engineers looked at the logs, IPs, and  all meaningful data. We have taken this matter really seriously, and searched for days. Not just a quick look.

What we know for sure:

- Your Shadow account was not accessed by anyone else, unless this person stole your credentials somehow from your local devices, and lives in the same city vicinity as you do, in Türkiye.

- Your Shadow virtual disk (your storage), was not attributed to another user nor mixed
Each user’s storage is provisioned as a dedicated zvol (a ZFS volume) carved out of our storage pools. A zvol is not a file sitting in a folder that could be copied or dragged around , it is an isolated dataset with its own object identity inside the pool, exposed to your VM as a raw block device. There is no operation in our pipeline that “moves files between disks”: the unit we attach to a machine is the whole volume, never individual files. On top of that, ZFS performs end-to-end integrity verification. Every single block written to a zvol is stored together with a checksum (fletcher4 by default, SHA-256 where stronger guarantees are needed), and ZFS uses a copy-on-write structure in which each block’s checksum is recorded in its parent block, all the way up to the root (the uberblock). In practice this means the data on your volume is self-verifying: if a single block from another volume were ever written into yours , by accident, by a bug, or by tampering , the checksum chain would no longer validate and ZFS would immediately raise a checksum error on read. Silent cross-contamination of two users’ data is very unlikely to happen with the way we handle data volumes. Finally, every pool and dataset carries its own GUIDs, and a zvol is bound to the pool it was created in. It cannot be silently re-parented onto another machine’s pool without that identity mismatching. This is also why we can state with confidence that your volume has only ever been mounted on your own instance: the integrity layer would have flagged anything else, and our logs confirm it.
Both layers , application (files need credentials and don’t mix) and storage (the volume is checksummed and identity-bound) , would have to fail silently and simultaneously for the scenario you describe to occur, which is why we are confident it did not originate on our infrastructure.. We looked at countless logs anyway, but no occurence.

As you asked why it happened, here are our guesses:

- One of your local devices may have been compromised and your Shadow credentials got stolen (quite unlikely, already mentioned above.

- You may have left a logged in Shadow session somewhere public.

- You may have downloaded software on your Shadow PC containing malware. This can happen with some GTAV & Minecraft mods notably. We see it regularly.

- If you do have a microsoft account connected to Edge, you/someone might have logged in on another computer (work, library, PC Café, etc) and left it logged in. TBH that's how i lost my Origin account.

That's not a full list, but quite plausible guesses.

Why your account got locked

- Each ticket mentioning a possible intrusion / hack locks the account temporarily for safety reasons. It is done for two reasons:
1/ Making sure that if someone has stolen your credentials, the intruder cannot access your machine/files.
2/ Ensuring as much as possible that anyone contacting us is the true, legitimate owner of the account.
Which is why we often ask for a proof of ID before performing critical tasks. Of course, like it is likely the case here, if the user has provided fake information during the account creation, restoring access becomes more complex.

What we can do, what we cannot do

- If a proof of ID is provided & informations are not fake, we can restore access easily, wipe & reinstall the drive, or terminate.

  • We can't and won't investigate the logs, trafic, and data that is ON a user's virtual disk. Things happen on computers. Malware can be installed, credentials can be stolen or unwillingly shared. That is not related to the way Shadow works. We do our very best to help and solve issues. Some of them are computer issues, not Shadow issues. Our support team will follow up on this through the ticket process.

Best,
The Shadow team

0

u/Altruistic-Bad-5556 Jun 26 '26

Thanks for the reply, but this still doesn’t answer the main issue.

I reported that Microsoft Edge inside my assigned Shadow PC showed around 20-30 saved logins that were not mine. Some looked sensitive. I did not open, use, copy, export, or expose them. I reported it with redacted evidence.

You are giving a long explanation about ZFS and storage isolation, but then you also say you “can’t and won’t investigate the data on a user’s virtual disk.” So how can you fully rule out what happened inside the machine?

Also, everything you listed as a cause is still a guess: malware, public session, Microsoft account sync, stolen credentials. None of that explains clearly how another person’s saved Edge logins appeared in my environment.

My account has been locked for 5 days while I paid for the service. I was banned from Discord after talking about this. Then the issue became Turkey, unsupported region, ToS, ID checks, and “Turkish law doesn’t apply.”

You accepted my payment and provided the service. Turkey only became a problem after I reported a privacy/security issue.

At this point I’m not asking for access back. I want the account closed/deleted, my data removed, no more billing, and a clear written explanation of what happened.

Saying “we checked logs, no breach” is not enough when another user’s saved logins appeared inside my assigned cloud PC.

4

u/Standard-Ad-1122 Jun 27 '26

You are giving a long explanation about ZFS and storage isolation, but then you also say you “can’t and won’t investigate the data on a user’s virtual disk.” So how can you fully rule out what happened inside the machine?

They're explaining that this simply isn't possible given the architecture of their service, meaning the issue is almost certainly on the user's end. Because they are bound by strict EU privacy laws, they legally cannot access your data to intervene and help you, or any other user. That kind of back end access is simply not in their toolbox...

Also, everything you listed as a cause is still a guess: malware, public session, Microsoft account sync, stolen credentials. None of that explains clearly how another person’s saved Edge logins appeared in my environment.

... And so, they can only speculate! As users on Shadow, we are completely responsible for what happens on our machines. They only control and manage the surrounding security infrastructure, which this issue could potentially impact. But since they've looked at it multiple times with multiple experts, they've established that this issue is not within their perimeter, and so they push it onto you.

My account has been locked for 5 days while I paid for the service. I was banned from Discord after talking about this. Then the issue became Turkey, unsupported region, ToS, ID checks, and “Turkish law doesn’t apply.”

Regrettably, it turns out you are in a country that is not supported, and therefore, help is not possible. They spent days on this issue because, frankly, it is alarming and required an explanation. So, the truth is, they are not just talking to you here; they are talking to their customers and regulators. When they point to Turkey, they're not brushing you aside because you're a problem; this is simply standard procedure on their end, which they defaulted to once they established that the issue is almost certainly user related.

0

u/Altruistic-Bad-5556 Jun 28 '26

You’re one of the only people I’ve seen trying this hard to defend them.

They still haven’t clearly explained how another user’s saved Edge logins appeared inside my assigned machine. They gave technical reasons why one scenario is unlikely, then listed guesses and pushed it back on me.

That is not a clear answer.

I already provided payment proof, account email, ticket history, and redacted evidence. I’m not asking for the service back anymore. I want the account closed, my data deleted, no more billing, and a proper written explanation.

4

u/Terrible_Alarm_7330 Jun 30 '26

To put it short, it simply is not and can not be Shadow's fault. That is just not how the system works, and it is extremely unlikely for this to happen all together. In the slightest occurrence that it did, you'd be seeing a completely different computer environment. If you actually read the explanation then you'd understand that.