New on LowEndTalk? Please Register and read our Community Rules.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Comments
Unlikely? Sure. But we have no idea of the scope of the attack, duration, ...
Better to assume the worst when it comes to security issues.
One of my India ones is back up and running again - thanks @HostDZire
No IPv6 but I guess that might have to wait until another day
Got my recreated server details now.
Update – VPS Provisioning & IP Assignment
Hello Everyone,
Another 12 hours have passed, and our team has continued assigning replacement VPS services in the background.
Initially, our goal was to provide every customer with the exact same IP address they had before the incident. However, because this requires a completely manual process involving multiple steps, it has taken significantly more time than expected. As a result, many VPS services are still pending.
Since we are now approaching 72 hours since the incident, we have decided to change our approach so that we can complete the recovery process much faster.
New Provisioning Plan
We will now proceed with assigning replacement VPS services without requiring the exact same IP address as before.
We understand that some customers may not be satisfied with the IP pool or range assigned to their replacement VPS. Therefore, we will provide a 72-hour window from the time your new VPS is assigned during which you can request a change to another available IP pool.
For example, if your replacement VPS is assigned an IP from the
192.168.x.xpool and you are not satisfied with that pool, you can contact us and request another available IP pool.Please note:
Expected Timeline
With this change, we expect to significantly speed up the provisioning process.
Our current target is to send the remaining VPS details within the next 12 hours.
We understand that this has already taken much longer than anyone expected. We made the decision to initially preserve the exact original IPs because we understood how important they could be for your applications, DNS, firewall rules, allowlists, and other configurations. However, at this stage, completing the restoration as quickly as possible has become the priority.
Thank you for your continued patience and understanding.
Kind Regards,
HostDZire Team
If I'm bored later, I'm going to make some popcorn and go through this thread comment by comment as it seems like it will be entertaining from my random page clicks and quick glances.
how do we get a refund? is our PII compromised???? or just our vps?
dedicry
We have already explained what happened and the immediate actions we took after detecting the incident. As soon as the compromise was identified, we powered down the affected servers to contain the incident and prevent further activity.
Based on our investigation so far, we have no indication that customer data was stolen or exfiltrated from the affected servers. Copying or transferring large VMDK files containing customer data would require significant network bandwidth and generate substantial data transfer activity. We did not observe any significant or unusual outbound network traffic indicating that large amounts of customer data were transferred from the affected infrastructure.
The behavior we observed is also consistent with how this type of ransomware typically operates: the attacker gains access to the system, encrypts or locks the files, leaves a ransom note, and demands payment for potential recovery. Our current evidence indicates that the objective was to encrypt the data rather than copy or steal it.
While we cannot completely rule out data access without completing the full forensic investigation, at this stage we have found no evidence of significant data exfiltration or customer data being transferred outside the affected infrastructure.
Regarding refunds or compensation, we understand that many customers may have questions about this. At this stage, our entire focus is on containing the incident and restoring affected services as quickly as possible. Once the immediate recovery work is completed and we have the necessary time to properly assess the situation, we will review the matter of refunds and compensation and make a decision accordingly. We will communicate our decision to affected customers once that review is complete.
We are not ignoring these questions; we simply need to prioritize service recovery at this moment.
Well, good thing you encrypted all the disks containing sensitive information with FDE. You did do that, right?
Surely no one could be stupid enough to host critically-confidential information unencrypted on a low-end host and just assume that they can never get breached.
Now, if you literally mean PII and not confidential information as a whole, then my question to you is: Why did you sign up using real information? If you're not causing troubles or abuse, most providers won't care if you sign up with a fictional name.
I think he believes that since the panel was briefly down much later on that they must have gotten his PII and credit card details…
was your control panel affected? you said everything was encrypted so what specific tools do you have to indicate the scope of this hack? What specific proof do you have that this wasn't compromised months ago?
You mentioned you believe this was from vmware cve but thar would require you exposing vcenter or esxi to public which is a known vulnerability. did you expose this to WAN?
what remediation team did you hire to investigate?
where should we send legal complaints too?
does Hostdzire support encrypted disks? also do they support using false information?
we have tickets saying they dont support disk encryption. where are you saying they allow it?
dedigod is shitting in his pants
Andrew from legal is gonna show up soon, just wait
SO how long for NL replacemnets? @HostDZire
Some APT/ransomware group known to do data exfil very secretly. They throttle hard to evade detection. You need to be very sure about this. There's a small chance that the breach could actually already happen for quite some time.
I believe you already take this into account though. Hopefully all will be good again for you.
Am I missing something here? Is this type of thing common with providers on here?
Not common but expected
..
You clearly don't understand how VPSes work. Every provider supports disk encryption because that's a feature of the guest, not the host.
And unless they KYC you, yes you can use false information (just don't make it obvious or give them a reason to check).
Or that they scanned for valuable information locally and only exported what they wanted. E.g. mount all VM images, copy a few valuable directories that likely contain credentials, then compress and transfer it all. Could fit in a few MB. No need for them to exfiltrate a bitwise-exact copy of each VPS image.
What do you mean unless they KYC you? They either support anonymous users or they don't.
They said they use VMware, you don't need to mount vdmks, you can search right into all vdmk files at once if you have root access, which obviously they did to encrypt them. So a simple command to search through everyone's files for specific keywords would give them simple info. They then can combine it all in a simple file and export millions of records for a few MB. This is VERY common. They pull important information then encrypt everything to hide their tracks.
Only way Hostdzire will know is if they have the logs which should be in a SIEM tool, but apparently they don't have any proper tooling.
Its obvious that Hostdzire.com have no proper security and zero concern about our data being compromised. They can't even give us our IPs back... which sounds a lot like their control panel was also hacked.
All they care about is getting fresh VMs back up and not offering refunds.
That doesn’t look too promising. I’ve created a support ticket. could you please take a look at it?
Ticket ID: 887925
whats not promising about this?
Security breaches and data loss are all understandable.
However, in order to restore progress, IP addresses are now being assigned at random, which is extremely, extremely, extremely troublesome for me. I need to amend the firewall restrictions for SSH, HTTP, HTTPS, FTP and other ports on hundreds of servers; in some cases, I even need to change domain name resolution and a whole host of other details.
This is a very poor and failed remedial measure. They did not give any prior notice of this situation, but instead only published the details on LET after they had already begun implementing it. Just a few minutes ago, I confirmed that my original IP address had already been reallocated and can no longer be used.
Anyone with Netherland (EU) vps got their service back already? Im still waiting that email.
Nope, still waiting..
In your email, you mentioned: "Along with rebuilding the affected infrastructure, we have implemented significant security improvements designed to greatly reduce the likelihood of similar incidents in the future." Could you specify what security measures have been taken to prevent such incidents from happening again? Merely stating that security measures have been implemented without specifics will not alleviate concerns. Greater transparency is essential to rebuilding trust between you and your clients.
I can assure you, we have no way of knowing if your real name is Harvey Specter and you live on 11 Wall Street, New York, NY 10005, USA without KYC...
How we can differentiate if you are maybe actually Jane Doe living on 1950 North Stemmons Freeway, Dallas, TX 75207, USA
If the address make sense (even if provider care about it), you won't have problems...
Why don't you automate that? I've got 54 servers and whenever I need to change an IP in the firewall, I run a one-liner over SSH in a for loop for all of them. Old-fashioned method, but works.
https://fakepersongenerator.com
I bet there has been a person opening a ticket somewhere asking where to put their weight.