August 31, 2026
We are writing to provide an update regarding a recent security incident involving a portion of the infrastructure used by Softaculous.
Between August 28 and August 30, 2026, an unauthorized BGP route hijacking temporarily redirected traffic destined for one of our IP ranges to an attacker-controlled server.
During this incident, the Virtualizor update system was affected, and a malicious update was delivered to a small number of Virtualizor installations.
At this time, we have no reports or evidence of any compromise involving Softaculous or any of our other products. Our investigation is ongoing, and we are continuing to review our infrastructure and update systems.
Normal routing has been restored, and we have taken additional measures to secure the affected infrastructure.
For customers who use Virtualizor, we strongly recommend following the remediation guidance provided in the detailed Virtualizor security advisory.
For complete technical details, including the incident timeline and details regarding the Virtualizor update system, please see:
Virtualizor Security Incident: BGP Hijacking
What Happened
Traffic between networks on the Internet is routed using BGP (Border Gateway Protocol). In a BGP hijack, an unauthorized network announces IP address ranges it does not control, causing traffic for those addresses to be redirected.
At approximately 20:57 UTC on August 28, 2026, AS62390 (NexonHost) began announcing 162.55.80.0/24, a portion of Hetzner’s address space containing IP addresses for a number of Softaculous systems. The announcement was made through transit provider AS6204 (Zet.net) and was more specific than Hetzner’s normal announcement, causing it to take precedence on networks that accepted it.
The incorrect routing was active during these two periods:
- August 28, 2026 ~20:57 UTC → August 29, 2026 ~08:50 UTC
- August 29, 2026 ~20:57 UTC → August 30, 2026 ~06:10 UTC
There was no incorrect routing between the two periods.
During the hijack, the attacker-controlled server was also able to obtain new TLS certificates for affected domains because certificate validation traffic was routed through the hijacked network path.
For Transparency
Hetzner did not proactively notify us of the BGP hijacking. Their effective mitigation — announcing the affected /24 directly — took effect at approximately 08:50 UTC on August 29, around 12 hours after the incident began.
We contacted Hetzner on August 31, after which they acknowledged the incident.
Billing and Client Area
If you logged into softaculous.com/clients or entered payment details during either of the following affected routing periods, your session may have been diverted to the attacker’s server:
- August 28, 2026 ~20:57 UTC → August 29, 2026 ~08:50 UTC
- August 29, 2026 ~20:57 UTC → August 30, 2026 ~06:10 UTC
There was no incorrect routing between these two periods.
As a precaution:
- Reset your Client Area password now. If you reused the same password anywhere else, change it there as well.
- If you entered card details during either affected period, review your card statements and contact your payment provider if you notice anything unusual.
Softaculous does not process or store card payments on our servers. Payments are processed through our payment gateways.
On our side, we are invalidating Client Area sessions from the affected periods.
License and API Keys
As a precaution, we recommend regenerating your NOC API keys from the Client Area and updating them on your servers (if you use them):
https://www.softaculous.com/clients
Questions
If you have any questions or concerns regarding this incident, please contact our support team.
We will continue to provide updates if our investigation identifies any additional information that materially affects our customers.
— The Softaculous Team
Appendix A — Affected Domains
The BGP hijack affected infrastructure within the 162.55.80.0/24 IP range. Domains associated with systems in the affected range included:a.softaculous.com, ampps.com, api.sitepad.com, api.softaculous.com,api.virtualizor.com, api.webuzo.com, backuply.com, files.ampps.com, files.sitepad.com,files.softaculous.com, files.virtualizor.com, files.webuzo.com, pagelayer.com,popularfx.com, server.softaculous.com, sitepad.com, softaculous.com, virtualizor.com,webuzo.com, www.ampps.com, www.backuply.com, www.popularfx.com, www.sitepad.com,www.softaculous.com, www.virtualizor.com, www.webuzo.com.
The presence of a domain in this list indicates that its traffic could have been affected by the routing incident. It does not indicate that the corresponding product or service was compromised.
For the complete technical details, including detailed timestamps, routing information, and details regarding the Virtualizor update system, please refer to the Virtualizor Security Incident: BGP Hijacking.