Was doing my quarterly check on leak monitoring sites and found my provider's name on a ransomware gang's blog. Specifically their internal billing panel and some customer data. Reached out to support, they confirmed "an incident involving a third-party tool" but downplayed scope.
Ran traceroutes before and after their statement. Route via their edge in Frankfurt adds 12ms now versus 8ms two weeks ago. New AS path goes through a different upstream. Correlation unclear.
Before: 8.2ms example.com → 10.0.0.1 → 192.168.x.x (Contabo edge)
After: 12.4ms example.com → 10.0.0.3 → 203.0.113.x (Hetzner transit)Migrating everything to OVHcloud this weekend. Will track their disclosure timeline here. So far:
- Day 0 leak
- Day 3 my notification
- Day 5 public statement (vague)
- Day 7 still no customer email