Skip to content

Scam watch: the 'we'll migrate you free' that wasn't

General Discussion by SingaporeRep 7 replies 679 views
#1

Contabo → Hetzner migration "service" exfiltrated customer DBs. Timeline:

2026-01-15: Hetzner registers domain
2026-01-20: Spam campaign: "we'll migrate you free from Contabo"
2026-02-03: 17 victims report data leaks
2026-02-10: Hetzner site down
2026-02-28: WHOIS privacy expires, nameserver history matches RackNerd ex-employee

Decent disk IO on their scam VPS, meh network. One victim's YABS — https://github.com/masonr/yet-another-bench-script:

fio: 285 MB/s read, 190 MB/s write
iperf3: 89 Mbps RX, 112 Mbps TX

Compared to legitimate Contabo:

fio: 412 MB/s read, 398 MB/s write
iperf3: 890 Mbps symmetric

Pattern: insider knowledge of Contabo's API endpoints, customer communication style, even ticket response templates.

fio, iperf, geekbench. results or gtfo.
#2

In server they left little script in cron, yes? To backup data to outside szerwer every hour. No? I found same in my friend's migration, he use "free service" from Hostinger clone. Very professional, little script was obfuscated python calling home to KnownHost IP. Not random scammer work.

airgapped, encrypted, faraday'd, still worried
#3

YMMV, but IMO the template matching is the smoking gun. Anyone can phish passwords. Mimicking internal ticket formatting and API behavior suggests access to documentation or code. Take it with a grain of salt, but this feels targeted, not opportunistic.

...
#4

I never trust "free" migration, I am going to do it myself forever, going to use rsync and that is it, going to sleep fine at night

4 #5

The Hetzner used « the Contabo » branding colors exactly. How to say... not public information? I work in design, yes, but even I could not replicate so precise without insider file. Someone gave them asset pack.

And the WHOIS, it points to former employee of RackNerd, not Contabo. But RackNerd and Contabo share datacenter in same city. Maybe he move between companies? Small world.

prix fixe infrastructure: €5/mo
#6

Today I learned never trust free migration forever also check your cron jobs people I found 3 backdoors in my little vps last month from some "installer script" I got from random discord going to selfhost everything now no more middlemen

...
#7

Template matching proves insider access? Or just good osint and patience

#8

I found the same cron trick on a "free cpanel transfer" last year

...

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft