Dear Customer,
We are writing to inform you about a recent security concern reported by multiple VPS customers and to recommend immediate precautionary steps.
Several customers recently reported unauthorized access to their VPS instances. In some cases, customers found Xboard-related nodes/software installed without authorization, while others reported that an unknown long-term root SSH public key had been added to their VPS.
After speaking with affected customers and reviewing the information available to us, we identified several common factors among the reported cases:
- The VPS was still using the default password generated and displayed by our client-area panel.
- SSH was publicly accessible.
- Password-based SSH authentication was enabled.
- No SSH key authentication was configured.
- No brute-force protection such as Fail2Ban was installed.
- The VPS had received a large number of SSH brute-force/login attempts.
Because we received multiple reports with similar characteristics, we started a broader investigation to understand how these incidents may have occurred and whether any active vulnerability could be involved.
VPS Node and Infrastructure Review
We reviewed the physical and virtualization nodes hosting the affected VPS instances.
At this time, we have found no indication that the hosting nodes themselves were compromised.
Following our previous VMware incident, we moved the management interfaces of our nodes to a private network, meaning they are not directly accessible from the public internet.
Even with this isolation in place, we performed additional checks across the relevant nodes and, based on our current findings, they appear to be safe and secure.
WHMCS Security Review
We also performed a security review of our current WHMCS installation.
At this time, we have found no evidence of an active compromise within our WHMCS installation.
However, WHMCS recently released multiple updates addressing undisclosed security issues, including updates released around:
- 25 August 2026
- 3 September 2026
We applied these updates promptly after they were made available.
Because WHMCS has not publicly disclosed the full technical details of these security fixes, we cannot independently determine the exact nature, impact, or exploitation status of the vulnerabilities addressed by those updates.
It is also important to understand that the date a security patch is released does not necessarily mean that the underlying vulnerability was first discovered on that same date. A vulnerability may have been identified earlier, investigated privately, and patched later.
We noticed that several of the affected VPS instances were provisioned around the same general period as these WHMCS security updates, including around 25 August 2026.
Because of this timing, we are investigating whether there could be any connection. However, we cannot currently confirm that WHMCS was the cause of these VPS compromises, and we do not want to present an unconfirmed possibility as a confirmed security incident.
Common Pattern We Have Observed
So far, the reports we have reviewed have primarily involved VPS instances that were still using the default panel-generated password and standard password-based SSH access.
We have not observed the same pattern among customers who had already implemented stronger VPS security measures such as:
- Changing the default password after installation
- Using SSH key authentication
- Disabling password-based SSH authentication
- Using brute-force protection such as Fail2Ban
- Applying additional SSH hardening
Because multiple reports show similar characteristics, we strongly recommend that customers using our India and Netherlands infrastructure-based VPS services take preventive action, even if they have not noticed any suspicious activity.
Immediate Action Recommended
Before making changes, please take a backup of any important data you need to preserve.
We then strongly recommend the following:
Reinstall your VPS from the client-area panel.
Change the VPS password immediately after installation.
Do not continue using the password generated or displayed by the panel.
Automatically generated provisioning passwords should always be treated as temporary passwords. We strongly recommend replacing them with your own strong and unique password immediately after installation.
Change the default SSH port and enable brute-force protection such as Fail2Ban or another appropriate security solution.
Use SSH key authentication wherever possible.
After confirming that SSH key authentication is working correctly, we also recommend disabling plain password-based SSH login.
Our Investigation Is Continuing
We are continuing to review the reported cases, logs, VPS provisioning process, password-generation process, WHMCS environment, and other possible attack vectors.
At this stage:
- The reports are currently limited to our own infrastructure-based VPS services in India and the Netherlands.
- We have received no similar reports for Leaseweb VPS, dedicated servers, or other services.
- We have found no indication that our VPS hosting nodes were compromised.
- We have found no evidence of an active compromise in our current WHMCS installation.
- We have identified a common pattern involving VPS instances that continued using their original panel-generated password with publicly exposed password-based SSH access.
- We are still investigating whether any recently patched third-party vulnerability may have contributed to the incidents.
Until the investigation is fully concluded, we strongly recommend that affected VPS customers treat any previously generated VPS password as temporary and replace it with a new password of their own.
Please complete the recommended security steps as soon as possible.
We would like to also clarify the scope of these reports.
The reported incidents currently apply only to VPS services running on our own infrastructure in India and the Netherlands.
At this time, we have received no reports of similar issues affecting:
- Leaseweb VPS services
- Dedicated servers
- Any other HostDZire services
So far, the reports are limited to VPS instances hosted on our own infrastructure in India and the Netherlands.
Kind regards,
HostDZire Team