New on LowEndTalk? Please Register and read our Community Rules.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Comments
The mjjs have arrived
Who care's about backups. the problem is OUR DATA WAS COMPROMISED. All passwords and everything else is in the hands of someone else and we have no idea for how long.
I mean, I for one really hope they completely stop what they're doing, quit restoring services, and drop everything to personally reply to your freakout. Clearly that will help everyone involved.
Weird.. didn't receive it (NL VPS).
Welcome, today we learn the definitions of words.
Ransomware
Ransomware is a malicious software that locks a user's device or encrypts their files, making them inaccessible. The attacker then demands a payment (a ransom) in exchange for the key needed to restore access
Next episode, data breach
It sounds like they're not doing anything anyways.
Why is everyone so casual of a massive data breach. Is this common on here?
I'm in CDT (UTC-5) if that helps correlate the time, but yeah, i don't know. Got it this morning.
what do you want then. make a scene here so it takes them even longer to reassign vps?
Hacked yes. vCenter vulnerability because they left the panel exposed to the internet and they didn't patch it fast enough.
Stolen? There's no proof of that.
Seems like a simple ransomware attack. But maybe they stole someone's hoarding of feet pics (was it yours?).
Same. Also nothing on their website or anything else. Although almost their entire site is down.
I have services with them in India, NL, Canada and US.
To be able to edit data and encrypt files they need read and write access.
Ransomware is worse than data breach as not only did they access files but they also encrypted them. Typically they ransomware them to hide their tracks and prevent forensics.
Better to assume it was stolen, since there's no proof it wasn't either.
Yes, surely, they downloaded terabytes of hundreds of vdisks in 1 minute and are now crawling through it on their quantum computer
It was great for the price. Backup was customer's responsibility. The same was stated on their ordering page since it didn't use RAID.
Regarding data breach, nothing to do except change all passwords, env values, etc.
Why are you saying 1 minute? It could have been years and once done they ransomware'd the system to hide their tracks.
We know their panel was hit since its still offline. So all our PII is compromised. That could be a few MBs in a database and take seconds.
how do you know this?
I'm mildly amused by the amount of people treating this as though they had their banking credentials and state secrets stored in a text file on the desktop of these boxes.
This sounds much more like opportunistic ransomware than exfilling terabytes of random virtual disks to look for some guys collection of feet pics, but... whatever floats your tinfoil hat boat.
No we don't, you're making assumptions. They actually posted asking people to stop mass-logging-in to check on the status of their boxes shortly before the panel went offline, and its been on and off a few times since. My guess (if i had to make one) is they have it offline on purpose.
Why would they take their panel offline on purpose?
I didn't get it either. I checked email history in the panel before it went down, and it wasn't there either. I'm guessing that it might not have gone out to all effected parties. Not a big deal for me, but a low priority item for the HD team to dig into once things are more stable. This isn't the first provider I've seen have email issues with WHCMS.
did you read the first half of the sentence?
Why would logging in to their portal cause issues if it wasn't affected?
They literally said they'll post updates in their announcements page and its offline...
They're blaming an ESXI CVE but that requires access to vcenter
Ok, lets all run around screaming and assume the absolute worst and that the provider is hiding things and not actually trying to do their best instead, im sure that will help.
@rpqu you got your popcorn ready?
Its a trash provider who just compromised everyone's data. Lets not act like its all ok and keep downplaying it.
They're lying constantly about this whole thing and ignoring that they were hacked and data was compromised.
Its required they notify everyone about it within 72 hours. A full notification of the severity and risks. Who has my PII and my credit card info and my data???
Selling pitchforks and torches!!!
Yeah, doesn't matter unless the VPS credentials are also being sent via email while the client page is disabled.
So, uhh, are they going to be working over the weekend? An update was expected around 12 hours after their last post, but it's close to 24 hours now?
Because the issue is posted on the first page. It's a RCE.
Funny sidenote iirc the second one this year. There where people that used some shitty ai script on cloudcone to destroy some sectors on the vdisks and write a ransom message for the customers at boot. I think one hopeless soul even paid, lmao.
Panel works for me at the moment - here's the latest from this morning, putting them about 5hrs past their 12 hour update, to @kevin99's point.