CloudCone

A security incident affecting CloudCone’s Budget VPS platform in Los Angeles executed an unauthorized management-layer script, displayed ransom messages and made affected virtual-server disks irrecoverable. CloudCone restored the affected platform Feb. 11, 2026; other regions and service platforms were not affected.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Malware that encrypts systems or data, typically accompanied by a ransom demand.
Malicious software other than ransomware used to compromise or disrupt systems.
Data was intentionally deleted, wiped, destroyed, or made permanently unrecoverable.
Data became damaged, inconsistent, unreadable, or unreliable as a result of malicious activity or incident-related system effects.
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
A primary service, system, platform, or operational capability became entirely unavailable.
Internal business, administrative, operational, or staff-facing systems were unavailable.
Cloud-hosted infrastructure, software, storage, identity, or platform services were unavailable or materially impaired.
Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.
The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.
The actor directly contacted the victim through a ransom note, email, chat portal, telephone call, messaging platform, or other communication channel.
The actor supplied cryptocurrency addresses, payment procedures, transaction requirements, or other instructions for satisfying the demand.
We reported that CloudCone experienced a destructive cyber incident affecting its Budget VPS environment in Los Angeles. Ransom messages and destructive disk modification support a high-confidence ransomware assessment, but no stable named actor claim was located.
The incident made affected virtual servers unavailable and required customers to reinstall systems. CloudCone said the affected disks could not be recovered, while other regions and service platforms remained operational. Its incident status history said about 60% of affected virtual machines had been restored by Feb. 8 and marked all affected VPS management features and platform operations fully restored Feb. 11.
The impacted infrastructure was in Los Angeles, California. CloudCone explicitly excluded its other service regions from the incident scope.
Confidence is high that unauthorized code caused destructive data loss and service outage because CloudCone described the management-layer script and damaged virtual-server disks. Ransomware is assessed with high confidence because ransom messages, direct contact and payment instructions were documented. Actor attribution and data theft remain unresolved.
CloudCone documented the security incident, operational effects and staged recovery, supporting organization-confirmed cyber and disruption transparency.
The incident is resolved. CloudCone marked the affected platform fully restored Feb. 11, although destroyed customer data could not be recovered. Later unrelated CloudCone incidents do not extend this incident’s operational period.
The public record does not establish initial access, threat actor, affected-customer count, whether data was exfiltrated or whether any payment produced recovery.

We reported CloudCone’s disclosure of an unauthorized management-layer script, ransom messages, damaged boot sectors and irrecoverable VPS disks.
CloudCone’s incident history documented recovery through Feb. 11. About 60% of affected virtual machines had been restored Feb. 8; CloudCone then marked all affected VPS management features and platform operations fully restored and applied compensation credits Feb. 11.
Signed-in members can report an error, update, or missing source.