Dear Customer,
We are writing to inform you about a security incident involving a BGP hijacking that affected a block of IP addresses used by Softaculous services, including infrastructure serving Virtualizor.
Incident Summary
Between 28 August 2026 ~20:57 UTC and 30 August 2026 ~06:10 UTC, an unauthorized network announcement diverted traffic destined for 162.55.80.0/24 to an attacker-controlled server. The affected infrastructure included our software update endpoint and client-area services.
What Happened
Traffic was redirected through a BGP hijack
An unrelated network began announcing our IP range using a more-specific BGP route. This caused traffic from some networks to be redirected to an attacker-controlled server. The attacker also obtained a technically valid TLS certificate for our domains, so affected connections did not display a certificate warning.
Virtualizor
Malicious Update Package
A malicious Virtualizor update package was delivered to a small number of installations whose update requests completed while traffic was diverted.
Routing Status
Fully Restored
The unauthorized route was withdrawn and normal routing was restored globally on 30 August at approximately 06:10 UTC.
Action Required
If you run Virtualizor, please check your server 1. Check for the indicator of compromise: look for /etc/systemd/system/java-jre-update.service. If it is present, do not simply delete it; contact us.
2. Rotate Virtualizor API credentials: reset all API keys, restrict API access to trusted IP addresses, and remove any key you do not recognize.
3. Audit access: review SSH keys, user accounts, scheduled tasks, cron jobs, and unexpected outbound connections. Restrict SSH access to trusted IP addresses.
4. Run our security scan: Virtualizor Security Scan https://files.virtualizor[.]com/security/virtualizor_security_scan.sh
5. If you find signs of compromise, contact support before remediation so we can help preserve evidence.
Other Softaculous Products
No malicious package identified
We have not identified a malicious package for Webuzo, Softaculous, Backuply, SitePad, or our other products. As a precaution, if one of these servers performed an update check during the incident window, please verify the server for anything suspicious and contact us if you find anything unusual.
Client Area & API Keys
If you logged into the Softaculous client area or entered payment details during the incident window, your session may have been diverted. We recommend resetting your client-area password. As a precaution, regenerate the client area NOC API keys and update them on your servers.
Full Incident Report
Detailed timeline, measurements and findings
We have reconstructed the incident using public routing data, including the timeline, impact measurements, indicators of compromise, and the actions we recommend. Please read the full report for complete details.
Read the Full Security Report https://www.virtualizor.com/blog/security-incident-bgp-hijacking/
We are writing to inform you about a security incident involving a BGP hijacking that affected a block of IP addresses used by Softaculous services, including infrastructure serving Virtualizor.
Incident Summary
Between 28 August 2026 ~20:57 UTC and 30 August 2026 ~06:10 UTC, an unauthorized network announcement diverted traffic destined for 162.55.80.0/24 to an attacker-controlled server. The affected infrastructure included our software update endpoint and client-area services.
What Happened
Traffic was redirected through a BGP hijack
An unrelated network began announcing our IP range using a more-specific BGP route. This caused traffic from some networks to be redirected to an attacker-controlled server. The attacker also obtained a technically valid TLS certificate for our domains, so affected connections did not display a certificate warning.
Virtualizor
Malicious Update Package
A malicious Virtualizor update package was delivered to a small number of installations whose update requests completed while traffic was diverted.
Routing Status
Fully Restored
The unauthorized route was withdrawn and normal routing was restored globally on 30 August at approximately 06:10 UTC.
Action Required
If you run Virtualizor, please check your server 1. Check for the indicator of compromise: look for /etc/systemd/system/java-jre-update.service. If it is present, do not simply delete it; contact us.
2. Rotate Virtualizor API credentials: reset all API keys, restrict API access to trusted IP addresses, and remove any key you do not recognize.
3. Audit access: review SSH keys, user accounts, scheduled tasks, cron jobs, and unexpected outbound connections. Restrict SSH access to trusted IP addresses.
4. Run our security scan: Virtualizor Security Scan https://files.virtualizor[.]com/security/virtualizor_security_scan.sh
5. If you find signs of compromise, contact support before remediation so we can help preserve evidence.
Other Softaculous Products
No malicious package identified
We have not identified a malicious package for Webuzo, Softaculous, Backuply, SitePad, or our other products. As a precaution, if one of these servers performed an update check during the incident window, please verify the server for anything suspicious and contact us if you find anything unusual.
Client Area & API Keys
If you logged into the Softaculous client area or entered payment details during the incident window, your session may have been diverted. We recommend resetting your client-area password. As a precaution, regenerate the client area NOC API keys and update them on your servers.
Full Incident Report
Detailed timeline, measurements and findings
We have reconstructed the incident using public routing data, including the timeline, impact measurements, indicators of compromise, and the actions we recommend. Please read the full report for complete details.
Read the Full Security Report https://www.virtualizor.com/blog/security-incident-bgp-hijacking/