r/webhosting • u/muggylittlec • 4d ago
Rant Hosting.com scamming customers with "malicious content" emails.
Posting this as a warning to anyone who might Google or Reddit search this.
Yesterday hosting.com emailed me with an alarming email saying one of my websites (I host a lot of sites for clients) was infected with "malicious content" and had likely been hacked. It ruined my evening as I'm a bit of a work perfectionist and want to keep my clients happy.
The email said someone from the security team would call me soon. I started a live chat right away as I was just about to finish work for the day. They confirmed it wasn't a phishing email and there was "malicious content" but couldn't tell me anymore until the security team called me.
The call was not from anyone in security, but a sales person. They confirmed which website it was but couldn't tell me what the "malicious content" was. Good news though! They could fix the mystery issue for a fee of £39.
I said I would investigate the problem myself and fix it, I asked them to email me with a list of files or a report from their scanner with the details. The sales person agreed. They emailed me once again with the link to pay the fee to the fix the "malicious content" and no info on what or where the content was.
I replied saying I needed to see evidence as this is a serious issue for me considering this is my business.
They replied and told me there were over 600 injected links that were being used for Spam SEO purposes by a hacker. Again they refused to give me more details in order to find and resolve the issue.
I tried again and firmly told them these are my websites and I need to know where these links are so I can ensure my client sites are secure.
I received a final email saying there had been a mistake and there was actually no "malicious content" at all.
I can only conclude that hosting.com are selling services to people who do not need them and are behaving like scammers.
3
u/SerClopsALot 3d ago
I'm a former Hosting.com employee, but I was laid off so...
The email is probably real. They aren't in the business of scamming people. They don't owe you the report, and the lack of them providing the report does not mean the issue isn't real.
I replied saying I needed to see evidence as this is a serious issue for me considering this is my business.
That's just really dismissive and short-sighted of you imo. Their goal is to sell you a service, they're not going to put in the effort of marketing the service to you then just let you bypass the service and get it for free. Ultimately, they are not your friend doing you a favor, they are a business.
What they do not have, though, is a "security team". They're probably reselling an existing service, something like Bitninja or Sucuri, whatever. Another thing of important note, anybody you speak to as a live contact is useless and doesn't know anything. They're all hired with no experience required and given almost no real technical training, and their only actual job is to push customer interaction into tickets.
Like any business, Hosting.com would absolutely love to sell people services they don't need as long as they're willing to buy it.
I received a final email saying there had been a mistake and there was actually no "malicious content" at all.
Knowing the skill level of people there, I wouldn't even take this at face value. What likely happened for them to come to this conclusion is: - Live chat interaction of you complaining there's no proof was pushed into a ticket because the rep didn't know how to do anything - Ticket rep gets the ticket, logs into your cPanel account, starts an Imunify360 scan and snoozes the ticket for like 2-4 hours - New ticket rep gets the ticket, checks the Imunify360 scan result, sees nothing, tells you "oops all a mistake you're all clean!"
I can basically guarantee a combined 20 minutes between both reps was not spent on this ticket.
The problem with this methodology from them is this:
over 600 injected links
Statistically, you likely host a WordPress website. If you're technical and quick on your feet, you'd notice that WordPress doesn't actually serve static web pages... it uses database content and dynamically generates the pages that are served. This means any injected links are possibly saved not in a file, but in the database. Cool!
Imunify360 scans... files. Only files. Well, okay, what if they're just using an edit to something like functions.php or a plugin to dynamically throw the link all over the website? Then it'd be a file problem! Well... doing this is very simple, and probably would not flag a file-based antivirus anyways.
Imunify360 is a generalized antivirus product, it's not "for" WordPress. Adding links to website elements is really, really normal website behavior and is not at all suspicious. Imunify360 can fairly reliably catch the exec(b64_string) type of exploits, but that would be overkill if you wanted to spam your link all over someone's website...
If you're hosting a WordPress website, install WordFence and run their free scanner. Like I said, they are not in the business of scamming people. They probably reached out to you because some scanner they have did flag your website or hosting account. They are in the business of being really bad at support, and most likely this process of scanning accounts + marketing this service was entirely not communicated to anyone you could possibly have a chance of getting in touch with... Including the guy who responds on their Reddit account, who also was never told this service existed LOL
2
u/AlejandroMurrieta 4d ago
It is real and they aren’t making it up. How bad it is who knows. You could have claude or chatgpt on desktop app ssh in and check.
It isn’t a scam because they are selling a service. It might be shady ethics wise but not a scam
6
u/AaronBonBarron 4d ago
If the "service" is sold using fake issues that they've "identified", it is a scam.
Exactly the same as those Indian scam call centers that run netstat in the command prompt and call it a list of "hackers" to sell you fake security products.-1
u/AlejandroMurrieta 4d ago
They aren’t fake issues. They are genuine issues, the severity can range but they are not fake issues at all. That is a fact
If it was “exactly” like the Indian scam call centers they’d get sued and be in big trouble legally.
2
u/AaronBonBarron 4d ago
Folding under the lightest of pressure tells me there were no legitimate issues.
0
u/AlejandroMurrieta 4d ago
Folding under pressure? Are you drunk? I’m just correcting your incorrect stance based on knowledge of what they are doing and using. I have no horse in this race. I already recommended claude as a better solution to check. You’re simply objectively wrong
4
u/AaronBonBarron 4d ago
Are you retarded?
"There's been a mistake, there's no actual issues" after repeatedly being asked to provide details is folding under pressure.
3
u/FarmboyJustice 3d ago
Dude why are you calling the OP a liar?
'I received a final email saying there had been a mistake and there was actually no "malicious content" at all.'
0
u/AlejandroMurrieta 3d ago
Because I have firsthand knowledge of what they use and you clearly do not.
1
u/FarmboyJustice 3d ago
Then explain why the customer received an email from hosting.com saying that they were mistaken and there was no malicious content. Since you work for hosting.com and are familiar with this specific case, why did they send that final email?
1
u/TinyNiceWolf 3d ago
Are you claiming that some websites somewhere have security issues? Or by "it is real", do you mean that OP's website (which we do not know) has security issues?
OP's own host admitted that OP's website did not have security issues. They admitted that their claim of security issues was false. Why do you believe their claim of security issues, but not their claim of no security issues?
At best, you could imagine that OP's host is merely bad at their job, and sees security issues when there are none. But the simpler explanation is that OP's host lies, same as any scammer, and pretends their sites have security issues.
2
u/AlejandroMurrieta 3d ago
The software they use flags real security and malicious concerns. It can find false positives, any service can. But it’s real in that it really is designed to do that.
It isn’t the best software and I don’t recommend it. Just saying it is a real scan not made up
1
u/TinyNiceWolf 3d ago
The issue is not whether they really ran a scan, or whether their mediocre software really guessed there could be a problem. The issue is that the host claimed one of OP's sites was really infected with malicious content, when they did not know any such thing.
If they had said "We ran a scan on your site and it claimed there was malicious content, but it's wrong sometimes, and we couldn't be bothered to actually investigate, so we decided to contact you and ask if you'd like to pay us to check if there's an actual problem," then OP wouldn't have had much of a complaint. (Other than that the company didn't simply send him the result of the scan, instead of trying to hit him up for payment.)
Instead, they lied and said the site was really infected, and OP had to repeatedly question them before they actually looked at the site, and admitted it never was.
1
u/MarkGossageUK 3d ago
I’d be asking for the scanner report, affected file paths and timestamps before paying for anything.
If a host tells you there’s malicious content but can’t identify what it found, you can’t independently verify the problem or know whether anything has actually been cleaned.
I’d also take a backup before making changes and scan the site independently. Even if their warning turns out to be genuine, you should still know exactly what was detected and what they intend to change.
1
-1
-5
4d ago edited 4d ago
[removed] — view removed comment
12
u/muggylittlec 4d ago
Yes you do offer this service.
https://hosting.com/en-gb/malware-cleanup/
I wish you spent less time covering your arse on social media and provided an honest service.
2
u/Bigfoot444 4d ago
What on earth?
This is unbelievable. The rant flag doesn't cover this. Need a fraud flag.
6
u/biosc1 4d ago
Be aware that there has been a huge uptick in ai-generated spam where they are crawling domains, figuring out where they are hosted, and then sending branded phishing emails that will attempt to steal your logins, money, and/or both.
This smells super phishy: "They confirmed which website it was but couldn't tell me what the "malicious content" was. Good news though! They could fix the mystery issue for a fee of £39."