Skip to content
RansomwareContained

Ransomware wipes HostDZire VMware nodes, causing permanent data loss (2026)

Indian hosting provider HostDZire confirmed a 5 August 2026 ransomware attack that encrypted VMware ESXi nodes across three regions and left affected customer data unrecoverable.

Victim
HostDZire

On 5 August 2026, Indian web-hosting provider HostDZire confirmed a ransomware attack that compromised several of its VMware ESXi virtualization nodes and caused the permanent loss of customer data. The company said the intrusion began at approximately 02:00 UTC and targeted its multi-regional hypervisor hosts and the virtual machines running on them.

What happened

According to HostDZire, the attackers encrypted the virtual disks on the affected ESXi hosts beyond any possibility of recovery. The compromise spanned infrastructure in India, the Netherlands, and the United States, meaning customers across all three regions saw their virtual servers knocked offline and their data destroyed. The provider said the encrypted data could not be restored and that it was rebuilding the affected systems from scratch, urging customers to recover their services from external backups where available.

The company launched a forensic investigation but did not publicly name the group responsible, and as of its disclosure there was no indication that stolen data had been published โ€” the damage lay in the destruction rather than in extortion-style leaks.

Why it matters

VMware ESXi hypervisors have become a favoured target for ransomware crews because a single compromised host can encrypt every virtual machine it runs, multiplying the blast radius. For a hosting provider, that dynamic is especially severe: one intrusion can wipe out the data of many downstream customers at once. The HostDZire incident is a stark reminder that shared-hosting tenants cannot assume their provider's snapshots are a substitute for their own independent, off-platform backups.

Timeline

  1. At around 02:00 UTC, ransomware compromises HostDZire's VMware ESXi hypervisor hosts, encrypting virtual disks in India, the Netherlands, and the United States.

  2. HostDZire confirms the attack, reporting that data on the affected nodes is permanently lost and that impacted systems must be rebuilt from scratch.

Sources

  1. securityonline.infohttps://securityonline.info/hostdzire-ransomware-attack/
  2. ababnews.comhttps://www.ababnews.com/news/39db0d35-993d-4a72-adda-0927ed44426e
  3. lowendtalk.comhttps://lowendtalk.com/discussion/219823/hostdzire-hit-by-ransomware-attack

Related incidents

RansomwareContained

Foxconn Nitrogen ransomware breach (2026)

The Nitrogen ransomware group claimed on its dark-web leak site that it had stolen over 11 million files from Foxconn's North American facilities, including confidential information belonging to customers Apple, Dell, Google, Intel, Nvidia, and Sony. Foxconn said affected factories were resuming normal production.

Victim
Foxconn (Hon Hai Precision Industry)