Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
OVHcloud

OVHcloud Vendor Cyber Rating & Cyber Score

ovhcloud.com

OVHcloud is a global player and the leading European cloud provider operating over 450,000 servers within 43 data centers across 4 continents to reach 1,6 million customers in over 140 countries. Spearheading a trusted cloud and pioneering a sustainable cloud with the best price-performance ratio, the Group has been leveraging for over 20 years an integrated model that guarantees total control of its value chain: from the design of its servers to the construction and management of its data centers, including the orchestration of its fiber-optic network. This unique approach enables OVHcloud to independently cover all the uses of its customers so they can seize the benefits of an environmentally conscious model with a frugal use of


OVHcloud A.I CyberSecurity Scoring

OVHcloud
Company Information
Website:https://www.ovhcloud.com/en/
Employees number:3,163
Number of followers:282,711
NAICS:5112
Industry Type:Software Development
Homepage:ovhcloud.com
OVHcloud Risk Score (AI oriented)
Between 600 and 649
logo
OVHcloudSoftware Development
Updated:
10/06/2026
621/1000
Poor
Caa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
OVHcloud Global Score (TPRM)
xxxx
logo
OVHcloudSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

OVHcloud
OVHcloudPoor
Current Score
621Caa (POOR)
01000
3 incidents
-53 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
622Before Incident
JUNE 2026
641Before Incident
Cyber Attack
04 Jun 2026OVHcloud
Google, velia.net, OVH SAS, HostPapa and Leaseweb: How Spammers Are Hiding Behind Google and the New York Times

Large-Scale Phishing Infrastructure Uncovered: 12,704 Servers Exploit Google Cloud and Scraped NYT Content

621After Incident
HIGH-20
LEAGOOVELOVHHOS1781109328
Large-Scale Phishing Infrastructure Uncovered: 12,704 Servers Exploit Google Cloud and Scraped NYT Content A recent investigation has exposed a sophisticated, globally distributed phishing operation leveraging 12,704 internet-facing servers across 55 countries to facilitate spam and credential-harvesting campaigns. The infrastructure, designed for deliverability, evasion, and resilience, abuses Google Cloud Storage as an initial redirect layer before funneling targets to attacker-controlled landing pages many of which mimic The New York Times to deceive security scanners and non-targeted visitors. ### Key Findings - Scale & Distribution: The network spans 412 hosting providers, with the highest concentrations at HostPapa (630 servers), velia.net (453), OVH SAS (438), and Leaseweb (423). Geographic diversification including heavy use of low-cost VPS markets in Turkey and Romania complicates takedown efforts. - Google Cloud Abuse: Attackers exploit Google Cloud Storage to host benign-looking HTML/JS files, using trusted Google domains (e.g., `storage.googleapis.com`) to bypass initial suspicion. JavaScript redirects then obscure the final phishing destination, allowing operators to rotate infrastructure without updating embedded email links. - Deceptive Landing Pages: Servers serve near-identical pages scraped from The New York Times, likely to evade detection by security tools. Only targeted visitors identified via factors like location, browser type, or referral source are redirected to malicious payloads. - Outdated & Vulnerable Software: 99.8% of servers run end-of-life (EOL) software, including: - Apache/2.4.52 (Ubuntu): 69% - Apache/2.4.6 (CentOS) with OpenSSL/1.0.2k-fips: 21% - Apache/2.4.41 (Ubuntu): 6% - Apache/2.4.58 (Ubuntu): 4% The uniformity suggests automated deployment from a small set of server images. - Low Abuse History: 89% of IP addresses had no prior reports in AbuseIPDB, indicating either rapid rotation or use as intermediate redirectors to avoid reputation-based blocking. - Selective Targeting: The infrastructure appears to filter visitors, serving benign content to scanners while delivering phishing pages to intended victims. The exact filtering logic remains unclear. ### Operational Tactics 1. Initial Contact: Victims receive spam emails with links to Google Cloud Storage URLs, which appear legitimate. 2. First Redirect: JavaScript on the Google-hosted page redirects to an attacker-controlled server. 3. Landing Page: Non-targets see NYT-scraped content; targets are sent to phishing pages. 4. Credential Harvesting: Victims who enter personal or financial data have their information compromised. ### Impact & Unknowns While the investigation confirms the existence and scale of the infrastructure, critical details remain unknown: - Total email volume sent via this network. - Number of victims who clicked links or submitted data. - Identity of the operators, though the coordinated deployment and shared tooling suggest a centralized operation rather than isolated actors. The campaign’s design distributed hosting, EOL software, and Google Cloud abuse prioritizes persistence and evasion, making disruption difficult. Victims who entered credentials on any linked page should assume their data is compromised. Even clicking a link may confirm an email address as active, increasing future spam exposure.
INCIDENT DETAILS -
TYPE
Phishing
MOTIVATION
Credential harvesting, financial gain
IMPACT
Data Compromised: Credentials, personally identifiable information (PII)Systems Affected: 12,704 internet-facing servers across 55 countriesOperational Impact: Potential compromise of user accounts, increased spam exposure for victimsIdentity Theft Risk: High
DATA BREACH
Type Of Data Compromised: Credentials, personally identifiable information (PII)Sensitivity Of Data: High (credentials, PII)Data Exfiltration: Likely (credentials harvested)Personally Identifiable Information: Yes
MAY 2026
634Before Incident
APRIL 2026
632Before Incident
MARCH 2026
623Before Incident
FEBRUARY 2026
686Before Incident
Breach
01 Feb 2026OVHcloud
OVHcloud: OVHcloud breach claimed by hacker, millions of users potentially affected

OVHcloud Alleged Cyberattack with Potential Data Breach

620After Incident
CRITICAL-66
OVH1774513748
OVHcloud Faces Alleged Cyberattack with Potential Data Breach Affecting Millions A threat actor known as contactbreachforums has claimed responsibility for breaching OVHcloud, one of Europe’s largest web hosting providers, allegedly compromising a primary account and associated servers. The group asserts that the attack resulted in the exfiltration of sensitive data, though OVHcloud has not yet confirmed the breach’s authenticity. According to the cybercriminals, the incident may have impacted 1.6 million customers and 5.9 million active websites hosted on the platform. The purportedly stolen data includes personal customer information such as names, phone numbers, email addresses, and physical addresses as well as website-related details, including source code, databases, and server configurations. The threat actor shared samples of usernames and provided a Telegram contact (@doxeur) for negotiations, suggesting a ransom demand. The claims emerge amid a series of technical outages OVHcloud experienced in February, which disrupted services for numerous websites and applications. The most severe incident occurred at its Gravelines, France, data center, where an electrical failure caused prolonged downtime. While OVHcloud attributed these disruptions to operational failures, the timing has raised questions about potential vulnerabilities. If verified, the breach could undermine confidence in European cloud providers, particularly as they compete with global giants like AWS, Microsoft Azure, and Google Cloud. The incident also underscores challenges in Europe’s push for digital autonomy, where local providers must demonstrate resilience comparable to their international counterparts. OVHcloud has yet to issue an official statement confirming the attack.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Ransom
IMPACT
Data Compromised: Personal customer information (names, phone numbers, email addresses, physical addresses), website-related details (source code, databases, server configurations)Systems Affected: Primary account and associated serversDowntime: Prolonged downtime due to electrical failure (Gravelines, France data center)Operational Impact: Disrupted services for numerous websites and applicationsBrand Reputation Impact: Potential undermining of confidence in European cloud providersIdentity Theft Risk: High (personal customer information exposed)
DATA BREACH
Personal customer informationWebsite-related details (source code, databases, server configurations)Sensitivity Of Data: High (personally identifiable information, proprietary website data)Data Exfiltration: YesPersonally Identifiable Information: Names, phone numbers, email addresses, physical addresses
JANUARY 2026
759Before Incident
Breach
30 Jan 2026OVHcloud
DigitalOcean, OVH and AWS: Moltbot Operators Leak Control Panels via Exposed mDNS Traffic

Moltbot Framework Exposes 1,400+ Instances via mDNS Misconfigurations

686After Incident
CRITICAL-73
AWSDIGOVH1769784401
Moltbot Framework Exposes 1,400+ Instances via mDNS Misconfigurations Security researchers have uncovered a widespread exposure of 1,487 Moltbot instances globally, leaking sensitive operational metadata and messaging platform credentials through misconfigured multicast DNS (mDNS) broadcasts. The open-source framework, designed for autonomous agent orchestration, inadvertently disclosed system-level details including hostnames, filesystem paths, service ports, and identity artifacts to any device on the same network segment. ### Key Findings - Exposed Data: Full machine hostnames, Clawdbot Control panel ports (18789), SSH ports, internal IPs, and messaging platform credentials (Signal, Telegram, WhatsApp) containing registration secrets and identity keys. - Geographic Spread: Instances were found across 53 countries, with the highest concentration in the U.S. Major hosting providers included DigitalOcean, AWS, and OVH. - Accessible Control Panels: 88 instances had publicly exposed web interfaces, with 66 leaking both mDNS and web access simultaneously. - Credential Leakage: Open directory listings revealed operational logs, cryptographic material, and runtime caches, enabling full agent impersonation without exploiting vulnerabilities. - Network Reconnaissance: mDNS broadcasts, intended for local service discovery, acted as pre-authentication metadata leaks, exposing systems in workplace Wi-Fi, co-working spaces, and university networks. ### Deployment Failures & Attack Surface The exposure stems from poor deployment hygiene rather than software flaws. Many instances self-announced internal structures via mDNS, providing attackers with reconnaissance data without active probing. A dedicated honeypot with 25 open ports suggested early attacker interest, while 635 accessible web control interfaces further expanded the attack surface. The combination of service advertisements, open directories, and credential leaks creates pre-authentication compromise risks, allowing adversaries to bypass authentication, hijack agent identities, or conduct phishing and lateral movement attacks. The findings highlight systemic misconfigurations in Moltbot deployments, where operators often overlook mDNS implications and basic access controls.
INCIDENT DETAILS -
TYPE
Misconfiguration
IMPACT
Data Compromised: Hostnames, filesystem paths, service ports, messaging platform credentials (Signal, Telegram, WhatsApp), operational logs, cryptographic material, runtime cachesSystems Affected: 1,487 Moltbot instancesOperational Impact: Pre-authentication compromise risks, agent identity hijacking, phishing, lateral movement attacksIdentity Theft Risk: High (identity artifacts and credentials exposed)
DATA BREACH
Type Of Data Compromised: Operational metadata, messaging platform credentials, cryptographic material, runtime cachesNumber Of Records Exposed: 1,487 instancesSensitivity Of Data: High (identity artifacts, credentials, internal IPs, service ports)File Types Exposed: Logs, cryptographic material, runtime cachesPersonally Identifiable Information: Hostnames, identity artifacts, messaging platform credentials
DECEMBER 2025
759Before Incident
NOVEMBER 2025
759Before Incident
OCTOBER 2025
759Before Incident
SEPTEMBER 2025
759Before Incident
AUGUST 2025
759Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for OVHcloud ?
?
What was OVHcloud's A.I Rankiteo Cyber Score in June 2026 ?
?
What was OVHcloud's A.I Rankiteo Cyber Score in May 2026 ?
?
What was OVHcloud's A.I Rankiteo Cyber Score in April 2026 ?
?
What was OVHcloud's A.I Rankiteo Cyber Score in March 2026 ?
?
What was OVHcloud's A.I Rankiteo Cyber Score in February 2026 ?
?
What was OVHcloud's A.I Rankiteo Cyber Score in January 2026 ?
?
What was OVHcloud's A.I Rankiteo Cyber Score in December 2025 ?
?
What was OVHcloud's A.I Rankiteo Cyber Score in November 2025 ?
?
What was OVHcloud's A.I Rankiteo Cyber Score in October 2025 ?
?
What was OVHcloud's A.I Rankiteo Cyber Score in September 2025 ?
?
What was OVHcloud's A.I Rankiteo Cyber Score in August 2025 ?
?
What is the average per-incident point impact on OVHcloud's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with OVHcloud ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view OVHcloud's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?