Skip to content

CloudCone Budget VPS security incident

Summary

CloudCone logo

A security incident affecting CloudCone’s Budget VPS platform in Los Angeles executed an unauthorized management-layer script, displayed ransom messages and made affected virtual-server disks irrecoverable. CloudCone restored the affected platform Feb. 11, 2026; other regions and service platforms were not affected.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
  • Incident end:
    ? Confirmed or defensibly assessed end of material operational disruption or incident activity.

Primary victim organization

Impacted location

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

  • Malware

    Malicious software other than ransomware used to compromise or disrupt systems.

Data impacts

  • Data deletion or destruction

    Data was intentionally deleted, wiped, destroyed, or made permanently unrecoverable.

  • Data corruption

    Data became damaged, inconsistent, unreadable, or unreliable as a result of malicious activity or incident-related system effects.

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

  • Complete service outage

    A primary service, system, platform, or operational capability became entirely unavailable.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Cloud service disruption

    Cloud-hosted infrastructure, software, storage, identity, or platform services were unavailable or materially impaired.

  • Staff unable to work normally

    Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.

Extortion indicators

  • Ransom demand

    The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.

  • Direct victim contact

    The actor directly contacted the victim through a ransom note, email, chat portal, telephone call, messaging platform, or other communication channel.

  • Payment instructions provided

    The actor supplied cryptocurrency addresses, payment procedures, transaction requirements, or other instructions for satisfying the demand.

Incident narrative

Analyst assessment

We reported that CloudCone experienced a destructive cyber incident affecting its Budget VPS environment in Los Angeles. Ransom messages and destructive disk modification support a high-confidence ransomware assessment, but no stable named actor claim was located.

Operational significance

The incident made affected virtual servers unavailable and required customers to reinstall systems. CloudCone said the affected disks could not be recovered, while other regions and service platforms remained operational. Its incident status history said about 60% of affected virtual machines had been restored by Feb. 8 and marked all affected VPS management features and platform operations fully restored Feb. 11.

The impacted infrastructure was in Los Angeles, California. CloudCone explicitly excluded its other service regions from the incident scope.

Confidence and uncertainty

Confidence is high that unauthorized code caused destructive data loss and service outage because CloudCone described the management-layer script and damaged virtual-server disks. Ransomware is assessed with high confidence because ransom messages, direct contact and payment instructions were documented. Actor attribution and data theft remain unresolved.

Disclosure posture

CloudCone documented the security incident, operational effects and staged recovery, supporting organization-confirmed cyber and disruption transparency.

Current status

The incident is resolved. CloudCone marked the affected platform fully restored Feb. 11, although destroyed customer data could not be recovered. Later unrelated CloudCone incidents do not extend this incident’s operational period.

Analytic gaps

The public record does not establish initial access, threat actor, affected-customer count, whether data was exfiltrated or whether any payment produced recovery.

Organizations involved

Impacted location

Sources

CloudCone security incident destroys Budget VPS data

We reported CloudCone’s disclosure of an unauthorized management-layer script, ransom messages, damaged boot sectors and irrecoverable VPS disks.

Hypervisor Outage

CloudCone’s incident history documented recovery through Feb. 11. About 60% of affected virtual machines had been restored Feb. 8; CloudCone then marked all affected VPS management features and platform operations fully restored and applied compensation credits Feb. 11.

See something that needs correction?

Signed-in members can report an error, update, or missing source.