{"id":6927,"date":"2026-08-31T14:43:59","date_gmt":"2026-08-31T14:43:59","guid":{"rendered":"https:\/\/www.softaculous.com\/blog\/?p=6927"},"modified":"2026-08-31T14:43:59","modified_gmt":"2026-08-31T14:43:59","slug":"security-incident-bgp-hijacking-update","status":"publish","type":"post","link":"https:\/\/www.softaculous.com\/blog\/security-incident-bgp-hijacking-update\/","title":{"rendered":"Security Incident \u2013 BGP Hijacking \u2013 Update"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>August 31, 2026<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We are writing to provide an update regarding a recent security incident involving a portion of the infrastructure used by Softaculous.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Between August 28 and August 30, 2026, an unauthorized <strong>BGP route hijacking<\/strong> temporarily redirected traffic destined for one of our IP ranges to an attacker-controlled server.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">During this incident, the <strong>Virtualizor update system was affected<\/strong>, and a malicious update was delivered to a small number of Virtualizor installations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At this time, <strong>we have no reports or evidence of any compromise involving Softaculous or any of our other products<\/strong>. Our investigation is ongoing, and we are continuing to review our infrastructure and update systems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Normal routing has been restored, and we have taken additional measures to secure the affected infrastructure.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For customers who use Virtualizor, we strongly recommend following the remediation guidance provided in the detailed Virtualizor security advisory.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For complete technical details, including the incident timeline and details regarding the Virtualizor update system, please see:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.virtualizor.com\/blog\/security-incident-bgp-hijacking\/\"><strong>Virtualizor Security Incident: BGP Hijacking<\/strong><\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What Happened<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Traffic between networks on the Internet is routed using <strong>BGP (Border Gateway Protocol)<\/strong>. In a BGP hijack, an unauthorized network announces IP address ranges it does not control, causing traffic for those addresses to be redirected.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At approximately <strong>20:57 UTC on August 28, 2026<\/strong>, <strong>AS62390 (NexonHost)<\/strong> began announcing <code>162.55.80.0\/24<\/code>, a portion of Hetzner&#8217;s address space containing IP addresses for a number of Softaculous systems. The announcement was made through transit provider <strong>AS6204 (Zet.net)<\/strong> and was more specific than Hetzner&#8217;s normal announcement, causing it to take precedence on networks that accepted it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The incorrect routing was active during these two periods:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>August 28, 2026 ~20:57 UTC \u2192 August 29, 2026 ~08:50 UTC<\/strong><\/li>\n\n\n\n<li><strong>August 29, 2026 ~20:57 UTC \u2192 August 30, 2026 ~06:10 UTC<\/strong><\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">There was <strong>no incorrect routing between the two periods<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">During the hijack, the attacker-controlled server was also able to obtain new TLS certificates for affected domains because certificate validation traffic was routed through the hijacked network path.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">For Transparency<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Hetzner did not proactively notify us of the BGP hijacking. Their effective mitigation \u2014 announcing the affected <code>\/24<\/code> directly \u2014 took effect at approximately <strong>08:50 UTC on August 29<\/strong>, around 12 hours after the incident began.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We contacted Hetzner on <strong>August 31<\/strong>, after which they acknowledged the incident.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Billing and Client Area<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If you logged into <strong>softaculous.com\/clients<\/strong> or entered payment details during either of the following affected routing periods, your session may have been diverted to the attacker&#8217;s server:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>August 28, 2026 ~20:57 UTC \u2192 August 29, 2026 ~08:50 UTC<\/strong><\/li>\n\n\n\n<li><strong>August 29, 2026 ~20:57 UTC \u2192 August 30, 2026 ~06:10 UTC<\/strong><\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">There was <strong>no incorrect routing between these two periods<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As a precaution:<\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li><strong>Reset your Client Area password now.<\/strong> If you reused the same password anywhere else, change it there as well.<\/li>\n\n\n\n<li>If you entered card details during either affected period, <strong>review your card statements<\/strong> and contact your payment provider if you notice anything unusual.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Softaculous does <strong>not process or store card payments on our servers<\/strong>. Payments are processed through our payment gateways.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On our side, we are invalidating Client Area sessions from the affected periods.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">License and API Keys<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">As a precaution, we recommend regenerating your NOC API keys from the Client Area and updating them on your servers (if you use them):<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.softaculous.com\/clients\">https:\/\/www.softaculous.com\/clients<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Questions<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If you have any questions or concerns regarding this incident, please contact our <a href=\"https:\/\/softaculous.deskuss.com\/\">support team<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We will continue to provide updates if our investigation identifies any additional information that materially affects our customers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>\u2014 The Softaculous Team<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Appendix A \u2014 Affected Domains<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The BGP hijack affected infrastructure within the <code>162.55.80.0\/24<\/code> IP range. Domains associated with systems in the affected range included:<br><code>a.softaculous.com<\/code>, <code>ampps.com<\/code>, <code>api.sitepad.com<\/code>, <code>api.softaculous.com<\/code>,<br><code>api.virtualizor.com<\/code>, <code>api.webuzo.com<\/code>, <code>backuply.com<\/code>, <code>files.ampps.com<\/code>, <code>files.sitepad.com<\/code>,<br><code>files.softaculous.com<\/code>, <code>files.virtualizor.com<\/code>, <code>files.webuzo.com<\/code>, <code>pagelayer.com<\/code>,<br><code>popularfx.com<\/code>, <code>server.softaculous.com<\/code>, <code>sitepad.com<\/code>, <code>softaculous.com<\/code>, <code>virtualizor.com<\/code>,<br><code>webuzo.com<\/code>, <code>www.ampps.com<\/code>, <code>www.backuply.com<\/code>, <code>www.popularfx.com<\/code>, <code>www.sitepad.com<\/code>,<br><code>www.softaculous.com<\/code>, <code>www.virtualizor.com<\/code>, <code>www.webuzo.com<\/code>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The presence of a domain in this list indicates that its traffic <strong>could have been affected by the routing incident<\/strong>. It does <strong>not<\/strong> indicate that the corresponding product or service was compromised.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For the complete technical details, including detailed timestamps, routing information, and details regarding the Virtualizor update system, please refer to the <a href=\"https:\/\/www.virtualizor.com\/blog\/security-incident-bgp-hijacking\/\"><strong>Virtualizor Security Incident: BGP Hijacking<\/strong><\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>August 31, 2026 We are writing to provide an update regarding a recent security incident involving a portion of the infrastructure used by Softaculous. Between August 28 and August 30, 2026, an unauthorized BGP route hijacking temporarily redirected traffic destined for one of our IP ranges to an attacker-controlled server. During this incident, the Virtualizor&hellip; <a class=\"more-link\" href=\"https:\/\/www.softaculous.com\/blog\/security-incident-bgp-hijacking-update\/\">Continue reading <span class=\"screen-reader-text\">Security Incident \u2013 BGP Hijacking \u2013 Update<\/span><\/a><\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-6927","post","type-post","status-publish","format-standard","hentry","category-uncategorized","entry"],"_links":{"self":[{"href":"https:\/\/www.softaculous.com\/blog\/wp-json\/wp\/v2\/posts\/6927","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.softaculous.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.softaculous.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.softaculous.com\/blog\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.softaculous.com\/blog\/wp-json\/wp\/v2\/comments?post=6927"}],"version-history":[{"count":2,"href":"https:\/\/www.softaculous.com\/blog\/wp-json\/wp\/v2\/posts\/6927\/revisions"}],"predecessor-version":[{"id":6929,"href":"https:\/\/www.softaculous.com\/blog\/wp-json\/wp\/v2\/posts\/6927\/revisions\/6929"}],"wp:attachment":[{"href":"https:\/\/www.softaculous.com\/blog\/wp-json\/wp\/v2\/media?parent=6927"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.softaculous.com\/blog\/wp-json\/wp\/v2\/categories?post=6927"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.softaculous.com\/blog\/wp-json\/wp\/v2\/tags?post=6927"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}