Skip to content

Found my host in a ransomware leak site

General Discussion by LichunLars 2 replies 150 views
#1

Was doing my quarterly check on leak monitoring sites and found my provider's name on a ransomware gang's blog. Specifically their internal billing panel and some customer data. Reached out to support, they confirmed "an incident involving a third-party tool" but downplayed scope.

Ran traceroutes before and after their statement. Route via their edge in Frankfurt adds 12ms now versus 8ms two weeks ago. New AS path goes through a different upstream. Correlation unclear.

Before:  8.2ms  example.com → 10.0.0.1 → 192.168.x.x (Contabo edge)
After:  12.4ms  example.com → 10.0.0.3 → 203.0.113.x (Hetzner transit)

Migrating everything to OVHcloud this weekend. Will track their disclosure timeline here. So far:

  • Day 0 leak
  • Day 3 my notification
  • Day 5 public statement (vague)
  • Day 7 still no customer email

1ms or I don't want it
#2

Oh no... very sorry to hear this. Made VPS with Contabo last month, not receive any email about this. Thank you very much for sharing this information. Will check my server now 🙏

#3
LichunLars said:
Migrating everything to OVHcloud this weekend

Сервер on Contabo too. Network not stable since last week. Support say "maintenance" but now this... very bad. Migrating tonight. Data already backup. Origin server not matter if provider compromised.

swimming upstream since 2019 🐟

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft