Ransomware wipes HostDZire VMware nodes, causing permanent data loss (2026)
Indian hosting provider HostDZire confirmed a 5 August 2026 ransomware attack that encrypted VMware ESXi nodes across three regions and left affected customer data unrecoverable.
- Victim
- HostDZire
On 5 August 2026, Indian web-hosting provider HostDZire confirmed a ransomware attack that compromised several of its VMware ESXi virtualization nodes and caused the permanent loss of customer data. The company said the intrusion began at approximately 02:00 UTC and targeted its multi-regional hypervisor hosts and the virtual machines running on them.
What happened
According to HostDZire, the attackers encrypted the virtual disks on the affected ESXi hosts beyond any possibility of recovery. The compromise spanned infrastructure in India, the Netherlands, and the United States, meaning customers across all three regions saw their virtual servers knocked offline and their data destroyed. The provider said the encrypted data could not be restored and that it was rebuilding the affected systems from scratch, urging customers to recover their services from external backups where available.
The company launched a forensic investigation but did not publicly name the group responsible, and as of its disclosure there was no indication that stolen data had been published โ the damage lay in the destruction rather than in extortion-style leaks.
Why it matters
VMware ESXi hypervisors have become a favoured target for ransomware crews because a single compromised host can encrypt every virtual machine it runs, multiplying the blast radius. For a hosting provider, that dynamic is especially severe: one intrusion can wipe out the data of many downstream customers at once. The HostDZire incident is a stark reminder that shared-hosting tenants cannot assume their provider's snapshots are a substitute for their own independent, off-platform backups.
Timeline
At around 02:00 UTC, ransomware compromises HostDZire's VMware ESXi hypervisor hosts, encrypting virtual disks in India, the Netherlands, and the United States.
HostDZire confirms the attack, reporting that data on the affected nodes is permanently lost and that impacted systems must be rebuilt from scratch.
Sources
- securityonline.infohttps://securityonline.info/hostdzire-ransomware-attack/
- ababnews.comhttps://www.ababnews.com/news/39db0d35-993d-4a72-adda-0927ed44426e
- lowendtalk.comhttps://lowendtalk.com/discussion/219823/hostdzire-hit-by-ransomware-attack