All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
HostDzire Hit by Ransomware Attack
All my India VPS at @HostDZire are down. I got this reply.
We regret to inform you that our infrastructure has been impacted by a ransomware attack affecting multiple virtualization nodes. As a result, some VPS and dedicated services are currently unavailable. Our team has isolated the affected systems and is actively investigating the incident while working on service recovery. We are also engaging with security specialists to determine the full extent of the attack and restore services as safely and quickly as possible. We sincerely apologize for the disruption and appreciate your patience during this time. We will continue to share updates as recovery progresses.


Comments
UPDATE:
Mine is down.
Only India's VPS?
I have no idea how extensive the attack is. Even the HostDzire client area seems to be running very slowly.
It appears that all ESXi nodes have been hit by a ransomware attack. What I'm curious about now is whether the data stored inside has been leaked? @HostDZire
Terribly stressful situation for him to be in. Wish him luck handling it.
in 6 Am i hope this is fucking Ai, going to sleep noting more
Reminder
Zero backup == Zero worth
It seems some NL VPS instances are also affected.
Yeah both mine are down too
Hope they can recover from this soon.
Damn that sucks. India VPS has been down for 2 hours.
frankfurt vps also down 2 hours
Hello Everyone,
We regret to inform you that our infrastructure has been impacted by a ransomware attack affecting multiple VMware ESXi virtualization nodes.
At approximately 02:00 UTC, we began receiving reports from customers that multiple VPS services were inaccessible. Our engineering team immediately initiated an investigation and discovered that several VMware ESXi hosts had been compromised. As our investigation progressed, we confirmed that the majority of our VMware-based infrastructure has been affected, including all VMware nodes in India and a number of nodes in the Netherlands and United States.
As an immediate containment measure, we have powered down all affected nodes via IPMI/iDRAC to prevent any further spread or damage while our investigation continues.
Services hosted on our KVM virtualization platform and all Leaseweb VPS services remain unaffected by this incident and continue to operate normally.
During the attack, the virtual disks of the affected servers were encrypted, resulting in the complete loss of data on the affected nodes. Unfortunately, all data stored on these nodes has been permanently lost and cannot be recovered.
At this time, we have no option but to rebuild all affected virtualization nodes from scratch. Once the new infrastructure is ready, we will begin provisioning replacement services. Customers with external backups will be able to restore their services once their replacement servers become available.
We understand the seriousness of this incident and sincerely apologize for the impact it has caused. Our team is working around the clock to investigate the incident, restore operations, and implement additional security measures to help prevent similar incidents in the future.
We will continue to provide updates as recovery progresses.
We sincerely apologize for this devastating incident and appreciate your patience and understanding.
Thanks & Regards,
HostDZire Team
my 2 VPS(SG) on HostDzire(Leaseweb) are still working rn, and i'm not sure if they're affected.
mine is also down
just kill me man....
My 2 VPSes out of India are down too.
Please suggest backup options from LET itself - should these be storage servers from another provider, and rsync or any other end-to-end options to do this efficiently?
I wonder if the latest CVE was to blame for this.
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017
Yes looks like it
Yeah saw it being mentioned a day or two ago. RIP.
https://hostdzire.com/billing/index.php?rp=/announcements/48/Critical-Service-Incident--Ransomware-Attack-on-VMware-Infrastructure.html
We will post updates here.
Might as well configure the disks in RAID in AMS if it has been affected while you’re rebuilding the hypervisor.
Ideally > @balaji_pitchumani said:
I would advise getting multiple box from different providers for high availability. Then another box whose sole purpose is to ingest backup/WAL and/or offline backup (and the token should be scoped to upload only).
Rsync suffice, but the optimal solution is to design the system propagate the data to other warm node immediately.
Ideally, it should be on different provider, different upstream, different region/continent.
The end is nigh.
RAID has nothing to do with this incident. Around 80% of our affected nodes, including all VMware nodes in India, were already running on RAID. RAID protects against physical disk failures, it does not protect against ransomware or data encryption.
The only effective protection in a situation like this would have been independent backups. If we had full VM backups, even on a weekly schedule, we could have restored those backups and significantly reduced the impact of this incident.
Oh man, I used to host my important services and data there (with backups, of course, but still...) until about two months ago. I moved everything away while trimming down the number of services I was running.
Anyway, best of luck to both the users and the provider. Hope you all recover from this as soon as possible.
Mines also down, in EU area. Did just make ticket to them and after that did see this info here. I hope they can reset system fast. Didn't have anything important in their no raid VPs anyways.
@HostDZire, how long can it take to rebuild VPS at India location.
I need things online asap.