Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Hetzner

Hetzner Vendor Cyber Rating & Cyber Score

hetzner.com

Hetzner is a professional web hosting provider and experienced data center operator. Since 1997 the company has provided private and business clients with high-performance hosting products as well as the necessary infrastructure for the efficient operation of websites. A combination of stable technology, attractive pricing and flexible support and services has enabled Hetzner to continuously strengthen its market position both nationally and internationally.


Hetzner A.I CyberSecurity Scoring

Hetzner
Company Information
Website:https://www.hetzner.com/links
Employees number:222
Number of followers:20,437
NAICS:513
Industry Type:Technology, Information and Internet
Homepage:hetzner.com
Hetzner Risk Score (AI oriented)
Between 650 and 699
logo
HetznerTechnology, Information and Internet
Updated:
02/09/2026
695/1000
Weak
B
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
✖ Insurance prefers TPRM score to calculate premium
Hetzner Global Score (TPRM)
xxxx
logo
HetznerTechnology, Information and Internet
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

HetznerWeak
Current Score
695B (WEAK)
01000
3 incidents
-31 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
OCTOBER 2026
696Before Incident
SEPTEMBER 2026
717Before Incident
Cyber Attack
02 Sep 2026 • Hetzner
Hetzner Online: Ransomware Hackers Built Their Own C2 Framework to Steal Passwords and Kill Security Tools

Newly Discovered TukTuk C2 Framework Linked to The Gentlemen Ransomware Group

695After Incident
LOW-22
HET1788337502
Newly Discovered TukTuk C2 Framework Linked to The Gentlemen Ransomware Group Threat intelligence researchers uncovered a command-and-control (C2) server tied to the ransomware group The Gentlemen, revealing a previously undocumented framework called TukTuk, tools to disable endpoint security, and stolen corporate data from two global companies. The server, hosted by Hetzner Online in Finland (IP: 65.109.70.162), contained the full TukTuk v2.0 project, including Windows and Linux agents, a backend server, and an operator control panel. The framework enables attackers to monitor compromised devices, execute commands, manage files, capture screenshots, and harvest credentials via a fake Windows Security prompt. Key findings include: - Cross-platform capabilities: The Windows agent (C#) and Linux agent demonstrate TukTuk’s versatility beyond Windows-only attacks. - DLL sideloading techniques: A malicious log4net.dll disguised as part of the legitimate Greenshot application was found, along with research on sideloading opportunities in ProcMon, Slack, and Postman. - EDR-killing tools: The server hosted materials on BYOVD (Bring Your Own Vulnerable Driver) techniques, including files like EDRKiller, WarsawKiller, and an unidentified driver still lacking a CVE. - Stolen data: 224 Jira tickets and eight attachments from a global tech company were recovered, containing infrastructure details, credentials, and sensitive information related to U.S. defense and aerospace customers. The server also contained an eb.sys file matching GentleKiller, a driver previously linked to The Gentlemen, reinforcing the connection. Evidence suggests the group used AI-assisted development for TukTuk, marking a growing trend in ransomware operations.
INCIDENT DETAILS -
TYPE
Ransomware
IMPACT
Data Compromised: 224 Jira tickets and eight attachments containing infrastructure details, credentials, and sensitive information related to U.S. defense and aerospace customersSystems Affected: Compromised devices (Windows and Linux)Identity Theft Risk: High (credentials and sensitive information harvested)
DATA BREACH
Jira ticketsAttachmentsCredentialsInfrastructure detailsNumber Of Records Exposed: 224 Jira tickets and eight attachmentsSensitivity Of Data: High (U.S. defense and aerospace-related)Data Exfiltration: YesPersonally Identifiable Information: Credentials and sensitive information
AUGUST 2026
716Before Incident
JULY 2026
715Before Incident
JUNE 2026
714Before Incident
MAY 2026
712Before Incident
APRIL 2026
752Before Incident
Cyber Attack
10 Apr 2026 • Hetzner
Hetzner and Twitter/X: Botnet Exposed: Hackers Leave Worker Access and Root Passwords Wide Open

Exposed Twitter/X Credential-Stuffing Botnet Reveals Full Infrastructure and Operations

712After Incident
LOW-40
HETTWI1776176874
Exposed Twitter/X Credential-Stuffing Botnet Reveals Full Infrastructure and Operations Security researchers at GHOST uncovered an unsecured credential-stuffing botnet targeting Twitter/X, exposing its entire command-and-control (C2) infrastructure, worker fleet, and operational details. The botnet’s control panel a Python Flask-based dashboard branded "Twitter Checker Master Panel – FULL FIX v2.3" was left completely unauthenticated, allowing unrestricted access to its management functions. The C2 server, hosted on a Windows Server 2019 instance by Hetzner in Falkenstein, Germany, had multiple services (RDP, SMB, WinRM) exposed alongside the Flask panel. No authentication mechanisms were in place, enabling direct access to all endpoints via HTTP on port 5000. Researchers obtained the full 98 KB source code, confirming the absence of security controls and revealing hardcoded API routes for server management, campaign execution, and data exfiltration. The botnet’s worker fleet consisted of 18 Linux servers in the 31.58.245.0/24 range, owned by Turkish provider Komuta Savunma Yuksek Teknoloji in Ankara. All workers were accessible via root SSH on port 22, with credentials following a predictable pattern: a 12-character lowercase hexadecimal string followed by "kmt.!" likely referencing the hosting provider. The servers were labeled in Turkish (e.g., "Sunucu 8"), suggesting a previous generation of at least seven decommissioned nodes. During a 12-minute observation on April 10, 2026, the botnet tested 722,763 Twitter/X credential pairs, adding 18 newly compromised accounts to its hit list. Lifetime statistics revealed 4.86 million accounts checked, with 138 successful takeovers a 0.0028% success rate. Notably, 85.6% of tested accounts triggered two-factor authentication (2FA) and were discarded, demonstrating 2FA’s effectiveness in blocking such attacks. Only 211,662 accounts had valid passwords without 2FA, with just 138 fully compromised. Attribution indicators point to a Turkish-speaking operator, given the UI’s Turkish language labels (e.g., "Sunucu Ekle" for "Add Server") and the use of Komuta Savunma’s infrastructure. The botnet’s deployment occurred in waves between December 25, 2025, and January 31, 2026, with a tool rollout in late February. Despite its scale, the operation remained undetected on major threat feeds, including VirusTotal, ThreatFox, and AbuseIPDB, highlighting how credential-stuffing campaigns can persist on general-purpose cloud hosts. The exposed infrastructure including plaintext root passwords, bulk control endpoints, and real-time telemetry provided a rare, unfiltered view into the mechanics of a large-scale automated attack.
INCIDENT DETAILS -
TYPE
Credential Stuffing
MOTIVATION
Account takeover for unknown purposes (likely financial or data exploitation)
IMPACT
Data Compromised: Twitter/X account credentials (722,763 tested, 138 compromised)Systems Affected: Twitter/X accounts, botnet infrastructure (C2 server, 18 worker nodes)Operational Impact: Potential unauthorized access to compromised Twitter/X accountsBrand Reputation Impact: Potential reputational damage to Twitter/X due to credential-stuffing attacksIdentity Theft Risk: High (compromised accounts may contain PII or linked services)
DATA BREACH
Type Of Data Compromised: Twitter/X account credentials, account metadataNumber Of Records Exposed: 722,763 (tested), 138 (compromised)Sensitivity Of Data: High (account credentials, potential PII in accounts)Personally Identifiable Information: Potential (depends on account contents)
MARCH 2026
751Before Incident
FEBRUARY 2026
751Before Incident
JANUARY 2026
751Before Incident
DECEMBER 2025
750Before Incident
NOVEMBER 2025
750Before Incident
JANUARY 2016
768Before Incident
Breach
01 Jan 2016 • Hetzner
Hetzner: UpGaurd Discovers Misconfigured Cloud Including 2.7 Billion SSNs

Massive Exposed Database Leaks Billions of SSNs and Passwords

582After Incident
CRITICAL-186
HET1772159936
Massive Exposed Database Leaks Billions of SSNs and Passwords Researchers at UpGuard recently uncovered a misconfigured cloud database containing billions of sensitive records, including 2.7 billion Social Security numbers (SSNs) and 3 billion plaintext email-password combinations. The unsecured data was accessible without authentication, making it easily discoverable during routine internet scans. After notifying the FBI’s Internet Crime Complaint Center (IC3) and the German hosting provider Hetzner, the database was taken offline. Cybersecurity analysts suggest the dataset likely originated from aggregated and refined data from previous large-scale breaches, with estimates indicating over 1 billion unique SSNs and 2.2 billion unique passwords in the collection. To verify the data’s authenticity, researchers cross-checked records with known individuals, confirming that the SSNs were valid. One person in the dataset had previously been a victim of identity theft, reinforcing concerns about the data’s legitimacy. Most of the exposed information appears to have been harvested before 2016, highlighting how old breaches continue to fuel modern cybercrime. The incident underscores the persistent risk of identity theft and fraud, as SSNs remain a critical authentication tool for financial accounts and credit applications. The scale of the leak demonstrates how threat actors compile and exploit stolen data long after initial breaches occur.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Data Aggregation for Cybercrime
IMPACT
Data Compromised: 2.7 billion SSNs, 3 billion email-password combinationsSystems Affected: Cloud DatabaseIdentity Theft Risk: High
DATA BREACH
Social Security Numbers (SSNs)Email-Password CombinationsNumber Of Records Exposed: 5.7 billion (2.7B SSNs + 3B email-passwords)Sensitivity Of Data: HighData Encryption: Plaintext (passwords)Personally Identifiable Information: SSNs, Email Addresses, Passwords

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Hetzner ?
?
What was Hetzner's A.I Rankiteo Cyber Score in September 2026 ?
?
What was Hetzner's A.I Rankiteo Cyber Score in August 2026 ?
?
What was Hetzner's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Hetzner's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Hetzner's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Hetzner's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Hetzner's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Hetzner's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Hetzner's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Hetzner's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Hetzner's A.I Rankiteo Cyber Score in November 2025 ?
?
What is the average per-incident point impact on Hetzner's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Hetzner ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Hetzner's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?