Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Warning: C-Servers (web.c-servers.co.uk) — VPS Deleted Without Any Notice, "Refund" Locked in Accoun

What Happened to Me
I had purchased VPS services from C-Servers (operated by the UK company Centerfield Ltd, based at the Docklands Business Centre in London). Then one day, I discovered my VPS had simply been deleted — no advance email, no ticket notification, no grace period whatsoever. The server and all the data on it were just gone.
When I paid, they took real money. But the so-called "refund" only went into my website account balance. That balance can't be withdrawn, and with the service already deleted and all trust broken, it's effectively useless. In other words, the money went into their pocket while you're left with nothing: no server, no data, and no refund you can actually use at your own discretion.
I'm Not the Only One
After sharing my experience, I found that this provider has a documented history of similar behavior. Between March and April 2025, multiple users reported nearly identical experiences on the LowEndTalk forum:
Their Houston, Texas node was shut down entirely after the upstream provider DartNode alleged "port scanning" activity, and C-Servers then announced the termination of all customer services on that node — with the upstream offering nothing more than a brief "we have 67 reports of port scanning" reply, no technical logs, no evidence. Multiple users stated they never received any notification email; one customer had paid for a three-year plan just three weeks earlier before losing everything, while the official network status page continued to display "all systems operational."
Even more alarming was their refund scheme at the time: refunds would only be issued as account credit, and only after passing a KYC identity verification through a third-party company. If a customer refused to comply or failed KYC, not only would there be no refund for the Houston VPS — all other services under their account would be terminated as well, with no refunds anywhere. The official email even stated outright that "KYC non-compliance" would be cited as a defense in any future disputes or chargeback attempts. This approach drew heavy criticism in the forum discussions at the time, with veteran members saying things like "I put this guy on my 'never' list."
Two further details deserve attention: first, the company has no real ticketing system — customers are left dealing with a chat bot that cannot escalate to a human. Second, they later publicly announced that all plans priced below 12 USD per year and/or with 896MB RAM or less would lose free human support entirely — including during global outages and network failures. To reach a human, you either need to spend at least 36 USD per year on their services, or pay an extra 6.79 USD for a package of "3 support tickets."
Summary: The Core Risks of This Provider
Based on my own experience and the public record, I believe C-Servers presents the following structural risks — think twice before buying:
First, services can be terminated without warning or evidence.​ A single unverified accusation from an upstream provider can get an entire node of customers purged en masse, with no chance to appeal or remedy anything. Finding out after the fact is the norm.
Second, the refund mechanism is effectively useless.​ Refunds don't go back to your original payment method — they only go into site credit, forcing you to keep spending at a provider you no longer trust. It's essentially a form of fund lock-in.
Third, communication channels are extremely limited.​ Notification emails may never arrive, the ticket system exists in name only, and budget plans have lost human support entirely. When something goes wrong, there's almost no one to reach.
Fourth, the company is young and small.​ Founded only in 2024, it depends heavily on third-party upstream resources — and any upstream change can translate directly into service termination for users.
Advice for Anyone Still Considering Small VPS Providers
If you still choose to buy from small VPS providers like this one, at minimum: don't store important data on them, avoid large annual or multi-year prepayments, pay by credit card or other chargeback-capable methods, back up regularly, and stay alert to terms like "refunds issued as account credit only."
The savings from a cheap VPS will never make up for the cost of losing your data and having your funds locked away.

Thanked by 1tzuli

Comments

  • Yeah, they are a well known scam. You could have said that without 10 paragraphs.

  • vpsricvpsric Member

    Welp, good luck with its user

  • rpqurpqu Member

    Thanked by 1forest
  • thanks, now i know they are scammers.

  • Please tell your AI to limit your whole story to 1 paragraph so others can read.

    Thanked by 1forest
  • HFSHFS Member

    c-servers should be permanently banned. I've had similar experiences too.

  • zedzed Veteran

    known shitbags, sorry for your loss

  • alfatarsosalfatarsos Member, Host Rep
    edited August 21

    Every time someone like you posts a review like this, it actually helps our business. I always get revenue increases on any given day whenever these posts for LET come up. In fact, it's even a compliment having these posts on LET, a forum closer to black hat activity than others and widely regarded at that.

    So thank you for the revenue increase. :)

    As for the allegations, yours are essentially full of big fat lies:

    • False that we don't have humans answering tickets, they are there and do answer;
    • False that we request KYC for refunds, we didn't in the end for the situation of the Houston node and it was thoroughly explained at the time what all of that was about (and well framed on an unavailability issue we had with our upstream on one server back in March), and generally don't;
    • False that a 6.79 USD for a package of 3 support tickets is needed, as it is available from 1 (one) single ticket since several weeks ago, at a much lower cost;
    • False that activity can't be appealed - if it is a reasonably gray area, we do ask, but there is strict monitoring to avoid abuse and things that are clearly forbidden get their treatment;
    • False that refunds don't get to card, they do on normal circumstances if it is requested and frameable to do that, according to the Terms and Conditions and Fair Usage Policy;
    • False that notification e-mails never arrive, our e-mails are operating normally.

    You are pure scum by posting this fake "review" full of blatant direct lies and, even more serious, easily verifiable that they are lies.

    The only thing remotely true is the dependence on upstreams to provide some services but I'm already on that one and working to remove it to the greatest possible extent, though the Internet is a network of networks and there's no such thing as "independence".

    Customers that try to abuse this company will get due treatment and I will continue to strengthen security mechanisms and escalate to make sure things get safe and sound. Every time someone sends a DoS attack to the WebStore and attempts to have us deadpool, tries a port scan, attempts spamming on 25, these customers, these external agents, are directly treated in line with the existing terms, whenever such activity is not allowed. Regardless of having a promotional campaign or not.

    Customers that don't abuse this company and are not buying things for the sake of pursuing their dark interests in full disregard for the company will always be welcomed and continually supported and addressed.

    Seems that you were on the first lot. And seeing per your "review", which implicitly leaves you did something not allowed, booting your service out was the exact right thing to do.

    At least try to do something credible. This is nothing.

  • LET should sticky a list of providers to avoid.

  • forestforest Member
    edited August 22

    @alfatarsos said: Customers that don't abuse this company and are not buying things for the sake of pursuing their dark interests in full disregard for the company will always be welcomed and continually supported and addressed.

    Except when you terminate everyone on a node because you were unable to figure out how to determine who is responsible for abuse behind NAT and, when pressed, just admitted that the software you use can't do that.

    Or when someone's service is down because of a problem on your end, but they can't open a ticket to contact you because they need to pay to do that.

    I've never seen a company stoop so low that genuine reports of downtime are ignored on even the cheapest plan. Refusing to answer tickets that aren't related to a problem on your side? Sure, that's fine. But when you're at fault and you don't allow people to report that to you without paying more, you're going about it wrong and negligently providing a faulty service.

    @alfatarsos said: Every time someone like you posts a review like this, it actually helps our business.

    Oof, you have bad business sense. For a small, inconsequential provider, sure any news is good for business. But if you ever want to expand, this kind of thing will keep coming up. You're celebrating the fact that you get a small short-term benefit at the expense of setting yourself a semi-permanent hard ceiling. That's kind of sad.

  • KuYeHQKuYeHQ Member

    You should be ashamed of your replies without any evidence. I am using a NAT VPS with IP 205.209.111.190 and port 49720. You can post evidence of traffic usage and violations of rules. My email has not received any warning messages. A service provider like you, who has no credibility, should have gone out of business long ago.

  • forestforest Member
    edited August 22

    @KuYeHQ said:

    You should be ashamed of your replies without any evidence. I am using a NAT VPS with IP 205.209.111.190 and port 49720. You can post evidence of traffic usage and violations of rules. My email has not received any warning messages. A service provider like you, who has no credibility, should have gone out of business long ago.

    He admitted in the past that he's simply unable to get the evidence and seemed to overestimate how hard it was. Maybe he's found a solution by now, but I tend to doubt it. The worst part is that he tried to use KYC thinking that "only the real abuser would refuse KYC" which is risible. He says he didn't end doing it, but he defended that idea for a long time.

    @HFS said:
    c-servers should be permanently banned. I've had similar experiences too.

    Being permanently banned is a little harsh. After all, a lot of crappy providers are allowed to advertise her and it would be unfair to ban them for simply making customers angry.

    The real issue is the fact that they knowingly (or rather, negligently) sell some services which are defective and demand extra money to people to get what they had already paid for, in the case of provider-side issues. That deserves a host rep tag suspension until it is rectified, at least, but not a permanent ban.

    Thanked by 2rpqu zed
  • rpqurpqu Member

    @alfatarsos said:
    Every time someone like you posts a review like this, it actually helps our business. I always get revenue increases on any given day whenever these posts for LET come up. In fact, it's even a compliment having these posts on LET, a forum closer to black hat activity than others and widely regarded at that.

    LOL, he consent.
    @jbiloh @angstrom If there's complaint, please refer to this message or make a canary whether it has been superceded

    Thanked by 3forest zed alfatarsos
  • alfatarsosalfatarsos Member, Host Rep
    edited August 22

    @forest said:

    @KuYeHQ said:

    You should be ashamed of your replies without any evidence. I am using a NAT VPS with IP 205.209.111.190 and port 49720. You can post evidence of traffic usage and violations of rules. My email has not received any warning messages. A service provider like you, who has no credibility, should have gone out of business long ago.

    He admitted in the past that he's simply unable to get the evidence and seemed to overestimate how hard it was. Maybe he's found a solution by now, but I tend to doubt it. The worst part is that he tried to use KYC thinking that "only the real abuser would refuse KYC" which is risible. He says he didn't end doing it, but he defended that idea for a long time.

    Again, incorrect (on the first sentence).

    Let's see if you understand nuance, I believe you do: the evidence was temporarily unable to be seen at the time while the server was down in late March and early April, but once it got up I got all that I needed and on short time windows.

    Since I could control when the server went up as my control was restored, there was a near zero chance I could miss something, since all activity was continuous and there were logs at AbuseIPDB to help and support for patterns. Networking was then up for the time I needed to collect it, and down again deliberately later on, to give myself time to act on the observed issue, which I did.

    So, no: no overestimating. No "can't do anything" or being "powerless". The KYC, as I repeated time and again, was seen, if needed, which it wasn't, as a last-resort measure if everything else failed to avoid abusers getting again to other servers in the fleet, which is a quite reasonable measure, though not without its perks - hence why it was abandoned. Since in the end it did not fail and I got a fair shot at solving things from the upstream, that's what I did and that's what it was done - end of story.

    Oh, and btw, answering to something you said to on another thread: NAT servers are very much possible to identify individually - the users still have internal IPs and still get routing to the main interface via bridging, and there's this little magical thing on Linux called conntrack. Especially from the point I got our new VPS platform working, I have all the bread and butter I need to stop abuse automatically on the right tracks. And sure I'm doing it and expanding on it.

    It's not only possible, it's already done.

    @rpqu said:
    LOL, he consent.
    @jbiloh @angstrom If there's complaint, please refer to this message or make a canary whether it has been superceded

    Yes, do refer to that message. :) I explicitly consent that. Not saying anything out of the ordinary there other than the truth.

    Why would you think providers would still pay 200 USD per year and still get shilling levels like those demonstrated to multiple providers? No one's in this business to lose money or reputation, right? So why pay and ensure both?

    The power of curiosity runs a long way, believe me. And it outpowers any potential power a user thinks it has by posting a "review" like the one written above or anything similar.

    It actually does a lot more for marketing than anything else with the high provider scattering at present on the market, because a negative review is a matter of opinion, not a matter of fact, regardless of attempting to being presented as a fact - and who reads them knows that.

  • zedzed Veteran

    definitely winning

    Thanked by 1thane
  • forestforest Member
    edited August 23

    @alfatarsos said: Oh, and btw, answering to something you said to on another thread: NAT servers are very much possible to identify individually - the users still have internal IPs and still get routing to the main interface via bridging, and there's this little magical thing on Linux called conntrack. Especially from the point I got our new VPS platform working, I have all the bread and butter I need to stop abuse automatically on the right tracks. And sure I'm doing it and expanding on it.

    Last time you complained that your software simply didn't support it and said something vaguely along the lines of "let's see you figure out how to do that because it's not as easy as it looks" (meanwhile I've been doing that for ~10 years). I recall I did mention connection tracking in that thread and was surprised you weren't using that to identify abuse. I'm glad you figured it out. Hopefully it'll prevent other customers from being punished for what their neighbors do.

    If I sound more than slightly harsh, it's not because I want to pick a consumer-vs-provider fight but because your repeated claims that only the abuser would refuse KYC stuck with me. Even if you didn't end up going that route, the fact that that was your plan and that you defended it even when called out was remarkable and a huge slap in the face to anyone who cares about their own privacy.

    Thanked by 1alfatarsos
  • alfatarsosalfatarsos Member, Host Rep
    edited August 23

    @forest said:

    Last time you complained that your software simply didn't support it and said something vaguely along the lines of "let's see you figure out how to do that because it's not as easy as it looks" (meanwhile I've been doing that for ~10 years).

    Doing it with a server offline at the time sure is hard, isn't it?

    You can be doing that even for 20 years - you still couldn't do that if either the original server, or the server where you keep these logs (if they differ), are inaccessible. That's a universal truth - no one escapes these.

    I recall I did mention connection tracking in that thread and was surprised you weren't using that to identify abuse. I'm glad you figured it out. Hopefully it'll prevent other customers from being punished for what their neighbors do.

    You keep insisting that other customers were punished for what neighbors did, however, that did not happen - because patterns were checked and direct logs were analyzed. Direct, in-place, no room for ambiguity. Malware and abuse have patterns, signatures, even when the pattern seems more erratic there's always a pattern, a path, a process.

    But if you do that analysis for 10+ years you surely know that as well.

    Conntracking analysis is not included in VirtFusion as a software (used in March and up to late June 2026), but it is used on our own in-house EagleKey VPS Portal since late June, among other things.

    On VF it was more CLI-based, more manual and casuistic, because creating a separate front/back-end for that info to be reported when that wasn't happenning every day or week seemed both riskier (from a data security perspective) and less necessary.

    That's the advantage of having our VPS portal done in-house: we can mold it much better into what we need, and desirably give a better experience for everyone.

    If I sound more than slightly harsh, it's not because I want to pick a consumer-vs-provider fight but because your repeated claims that only the abuser would refuse KYC stuck with me. Even if you didn't end up going that route, the fact that that was your plan and that you defended it even when called out was remarkable and a huge slap in the face to anyone who cares about their own privacy.

    With a whole server offline, I had an entire fleet to defend, well more than a thousand users and 1300 VMs included, and not many tools left at the time since it was offline. I absolutely wasn't going to compromise them, I had to protect them and let bygones be bygones - if they were to be bygones.

    Now it would be an entirely different game as there are more tools to cover for any rainy day (as they say).

    I could have theoretically implemented KYC but ultimately chose not to, because I wanted to be entirely sure that it would be effective enough, and because what was seen at the end in practice actually comes in-line with your privacy-first stance in the sense that all plans had abusers (from the 384MB to the 3GB one), and all user types had shown these, from the less identified account to the entirely identified account, as I've duly recognized at the time.

    I'm a data guy by nature - I analyze, probe, and understand existing data, and decide on it. Sometimes the reason is there, sometimes it isn't. I have no problem on going back on a claim or a statement if my idea is cleanly and technically proven wrong, and also have zero problems on improving potential or existing procedures, whichever they may.

    Otherwise, C-Servers continues not to request KYC, unless seen as necessary, and so far, until now, the number of requests done this year were... 1. So yeah, we don't use it. That alone tells everything.

  • forestforest Member

    @alfatarsos said: Doing it with a server offline at the time sure is hard, isn't it?

    In such a case, you would want to wait for it to be online before even suggesting punitive action.

    @alfatarsos said: Conntracking analysis is not included in VirtFusion as a software (used in March and up to late June 2026)

    Surely you had command-line access to the node, right? It shouldn't matter what the panel supports.

  • a brit domain with c- innit, the owner also properly doing the needful to behave like one.
    i am laffin.

    Thanked by 1rpqu
  • openidopenid Member

    lol

Sign In or Register to comment.