If your website, online store, or a client’s site runs on shared hosting or a VPS, there’s a good chance it depends on software you’ve never heard of: Softaculous, an app installer used by hosting control panels, and Virtualizor, a platform many hosting providers use to manage virtual servers behind the scenes. Late last month, attackers hijacked internet routing to redirect traffic meant for these systems, for 33 hours, to a server they controlled, and used the opportunity to push out a malicious software update.
The attack used a technique called BGP hijacking. In simple terms, the internet’s routing system relies on providers announcing which networks they’re responsible for, and normally that trust holds. Starting around 21:00 on 28 August, an unfamiliar network began announcing ownership of IP addresses actually belonging to Hetzner, Softaculous’s infrastructure provider, and used that false claim to intercept traffic heading to Softaculous’s client, billing, and software update systems. Because the attacker could also obtain a valid security certificate for the hijacked domain, victims had no obvious way to tell anything was wrong.
Why this matters even if you’ve never heard of these tools
You don’t choose Softaculous or Virtualizor directly, your hosting provider does, often as part of the control panel or reseller platform sitting behind your website. That’s exactly what makes this kind of attack dangerous for small businesses: the compromise happens one layer removed from anything you’d normally check, in software your provider chose on your behalf. One hosting provider reported that 5 of 34 Virtualizor servers it checked had been compromised with full root-level access, meaning attackers had complete control of those machines.
This is a supply-chain attack in the truest sense: nobody targeted your business specifically, but if your provider’s infrastructure was one of the affected ones, your site, data, and customer information were exposed as collateral. It’s the same pattern behind several incidents this year where attackers went after the tools businesses trust rather than businesses themselves.
What to actually check this week
Ask your hosting provider directly whether they use Softaculous or Virtualizor, and whether they were affected. Most SMEs have never had a reason to ask this question, but it takes one email. A provider that can’t answer clearly is itself worth noting.
If you or anyone with access logged into a hosting control panel or entered payment details between 28 August and 1 September, reset those credentials now. Anyone who authenticated during the hijack window should treat their password as potentially exposed, along with any payment card details entered during that period.
Check for unfamiliar admin accounts or unexpected server activity. A root-level compromise can mean new user accounts, altered file permissions, or software you didn’t install. If your provider confirms they were affected, ask specifically what remediation they’ve done, not just whether the immediate issue is patched.
Build “who is my provider’s provider” into how you think about hosting risk. KeepSafe monitors for exactly this kind of downstream exposure, where the vulnerability sits with a supplier’s supplier rather than anywhere you can directly see. For a small business, knowing which infrastructure your website actually depends on, beyond just “who do I pay the hosting bill to”, is worth having documented before the next incident, not during it.
The takeaway
This wasn’t a phishing email or a weak password, it was an attack on the internet’s routing infrastructure itself, and it briefly turned a legitimate software update channel into a malware delivery system. Most SMEs can’t do anything about BGP hijacking directly, but you can find out fast whether your provider was in the blast radius, and that’s the one action worth taking today.