Ransomware Intrusion Erases User Data
When utilizing Virtual Private Server (VPS) infrastructure, performing routine data backups remains paramount. Previously, CloudCone suffered a catastrophic ransomware intrusion that completely erased all user data. Now, Indian hosting provider HostDzire has succumbed to a similarly devastating ransomware attack. Because these providers maintain no independent backups, their sole recourse involves formatting the compromised drives and reinstalling operating systems from scratch.
Complete Destruction of Customer Virtual Machines
In its initial public announcement regarding the incident, HostDzire revealed that a severe ransomware intrusion rendered numerous virtual machines and dedicated servers inaccessible. During that initial phase, the company suspended operations to conduct a comprehensive system audit. Ultimately, analysis confirmed that dedicated servers remained completely unaffected by the breach.
However, in a subsequent status update, HostDzire emphasized that attackers encrypted the virtual disks on affected host servers. As a direct consequence, users lost all data stored on those specific nodes. In an official announcement detailing the ransomware attack on its VMware infrastructure, the company confirmed that malicious actors compromised the underlying hypervisors and encrypted storage volumes.
Consequently, all virtual machines hosted on these nodes were rendered unrecoverable. HostDzire responded by adopting the exact strategy previously deployed by CloudCone. Specifically, engineers isolated the affected host servers, formatted the storage drives, and began rebuilding the nodes from the ground up.
Aside from severe reputational damage, this incident will cause minimal direct financial loss for HostDzire. Naturally, the provider refused to pay ransom demands in exchange for decryption keys. Furthermore, because HostDzire places full responsibility for data retention on its customers, the company will likely offer only complimentary service credits as compensation.
Detailed Analysis of the Incident
The security breach occurred at approximately 02:00 UTC on August 5, 2026. The attack specifically targeted HostDzire’s multi-regional VMware ESXi hypervisor hosts and their associated virtual machine instances.
The geographical scope of the intrusion proved extensive. The attack impacted all server nodes in India, alongside multiple facilities in the United States and the Netherlands. Conversely, HostDzire’s Leaseweb VPS infrastructure remained completely unaffected throughout the ordeal.
Regarding data recovery, the encryption of virtual disks left no functional backups on the provider’s side. Consequently, affected clients must rely entirely on their own off-site backups to restore their applications and data.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.