OVHcloud A.I CyberSecurity Scoring
OVHcloud
Company Information
Website:https://www.ovhcloud.com/en/
Employees number:3,163
Number of followers:282,711
NAICS:5112
Industry Type:Software Development
Homepage:ovhcloud.com
OVHcloud Risk Score (AI oriented)
Between 600 and 649
OVHcloudSoftware Development
Updated:
10/06/2026
10/06/2026
621/1000
Poor
Caa
OVHcloud Global Score (TPRM)
xxxx
OVHcloudSoftware Development
Score locked

OVHcloudPoor
Current Score
621Caa (POOR)
01000
3 incidents
-53 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
622
JUNE 2026
641
Cyber Attack
04 Jun 2026 • OVHcloud
Google, velia.net, OVH SAS, HostPapa and Leaseweb: How Spammers Are Hiding Behind Google and the New York Times
Large-Scale Phishing Infrastructure Uncovered: 12,704 Servers Exploit Google Cloud and Scraped NYT Content
621
HIGH-20
LEAGOOVELOVHHOS1781109328
Large-Scale Phishing Infrastructure Uncovered: 12,704 Servers Exploit Google Cloud and Scraped NYT Content
A recent investigation has exposed a sophisticated, globally distributed phishing operation leveraging 12,704 internet-facing servers across 55 countries to facilitate spam and credential-harvesting campaigns. The infrastructure, designed for deliverability, evasion, and resilience, abuses Google Cloud Storage as an initial redirect layer before funneling targets to attacker-controlled landing pages many of which mimic The New York Times to deceive security scanners and non-targeted visitors.
### Key Findings
- Scale & Distribution: The network spans 412 hosting providers, with the highest concentrations at HostPapa (630 servers), velia.net (453), OVH SAS (438), and Leaseweb (423). Geographic diversification including heavy use of low-cost VPS markets in Turkey and Romania complicates takedown efforts.
- Google Cloud Abuse: Attackers exploit Google Cloud Storage to host benign-looking HTML/JS files, using trusted Google domains (e.g., `storage.googleapis.com`) to bypass initial suspicion. JavaScript redirects then obscure the final phishing destination, allowing operators to rotate infrastructure without updating embedded email links.
- Deceptive Landing Pages: Servers serve near-identical pages scraped from The New York Times, likely to evade detection by security tools. Only targeted visitors identified via factors like location, browser type, or referral source are redirected to malicious payloads.
- Outdated & Vulnerable Software: 99.8% of servers run end-of-life (EOL) software, including:
- Apache/2.4.52 (Ubuntu): 69%
- Apache/2.4.6 (CentOS) with OpenSSL/1.0.2k-fips: 21%
- Apache/2.4.41 (Ubuntu): 6%
- Apache/2.4.58 (Ubuntu): 4%
The uniformity suggests automated deployment from a small set of server images.
- Low Abuse History: 89% of IP addresses had no prior reports in AbuseIPDB, indicating either rapid rotation or use as intermediate redirectors to avoid reputation-based blocking.
- Selective Targeting: The infrastructure appears to filter visitors, serving benign content to scanners while delivering phishing pages to intended victims. The exact filtering logic remains unclear.
### Operational Tactics
1. Initial Contact: Victims receive spam emails with links to Google Cloud Storage URLs, which appear legitimate.
2. First Redirect: JavaScript on the Google-hosted page redirects to an attacker-controlled server.
3. Landing Page: Non-targets see NYT-scraped content; targets are sent to phishing pages.
4. Credential Harvesting: Victims who enter personal or financial data have their information compromised.
### Impact & Unknowns
While the investigation confirms the existence and scale of the infrastructure, critical details remain unknown:
- Total email volume sent via this network.
- Number of victims who clicked links or submitted data.
- Identity of the operators, though the coordinated deployment and shared tooling suggest a centralized operation rather than isolated actors.
The campaign’s design distributed hosting, EOL software, and Google Cloud abuse prioritizes persistence and evasion, making disruption difficult. Victims who entered credentials on any linked page should assume their data is compromised. Even clicking a link may confirm an email address as active, increasing future spam exposure.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MAY 2026
634
APRIL 2026
632
MARCH 2026
623
FEBRUARY 2026
686
Breach
01 Feb 2026 • OVHcloud
OVHcloud: OVHcloud breach claimed by hacker, millions of users potentially affected
OVHcloud Alleged Cyberattack with Potential Data Breach
620
CRITICAL-66
OVH1774513748
OVHcloud Faces Alleged Cyberattack with Potential Data Breach Affecting Millions
A threat actor known as contactbreachforums has claimed responsibility for breaching OVHcloud, one of Europe’s largest web hosting providers, allegedly compromising a primary account and associated servers. The group asserts that the attack resulted in the exfiltration of sensitive data, though OVHcloud has not yet confirmed the breach’s authenticity.
According to the cybercriminals, the incident may have impacted 1.6 million customers and 5.9 million active websites hosted on the platform. The purportedly stolen data includes personal customer information such as names, phone numbers, email addresses, and physical addresses as well as website-related details, including source code, databases, and server configurations. The threat actor shared samples of usernames and provided a Telegram contact (@doxeur) for negotiations, suggesting a ransom demand.
The claims emerge amid a series of technical outages OVHcloud experienced in February, which disrupted services for numerous websites and applications. The most severe incident occurred at its Gravelines, France, data center, where an electrical failure caused prolonged downtime. While OVHcloud attributed these disruptions to operational failures, the timing has raised questions about potential vulnerabilities.
If verified, the breach could undermine confidence in European cloud providers, particularly as they compete with global giants like AWS, Microsoft Azure, and Google Cloud. The incident also underscores challenges in Europe’s push for digital autonomy, where local providers must demonstrate resilience comparable to their international counterparts. OVHcloud has yet to issue an official statement confirming the attack.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
759
Breach
30 Jan 2026 • OVHcloud
DigitalOcean, OVH and AWS: Moltbot Operators Leak Control Panels via Exposed mDNS Traffic
Moltbot Framework Exposes 1,400+ Instances via mDNS Misconfigurations
686
CRITICAL-73
AWSDIGOVH1769784401
Moltbot Framework Exposes 1,400+ Instances via mDNS Misconfigurations
Security researchers have uncovered a widespread exposure of 1,487 Moltbot instances globally, leaking sensitive operational metadata and messaging platform credentials through misconfigured multicast DNS (mDNS) broadcasts. The open-source framework, designed for autonomous agent orchestration, inadvertently disclosed system-level details including hostnames, filesystem paths, service ports, and identity artifacts to any device on the same network segment.
### Key Findings
- Exposed Data: Full machine hostnames, Clawdbot Control panel ports (18789), SSH ports, internal IPs, and messaging platform credentials (Signal, Telegram, WhatsApp) containing registration secrets and identity keys.
- Geographic Spread: Instances were found across 53 countries, with the highest concentration in the U.S. Major hosting providers included DigitalOcean, AWS, and OVH.
- Accessible Control Panels: 88 instances had publicly exposed web interfaces, with 66 leaking both mDNS and web access simultaneously.
- Credential Leakage: Open directory listings revealed operational logs, cryptographic material, and runtime caches, enabling full agent impersonation without exploiting vulnerabilities.
- Network Reconnaissance: mDNS broadcasts, intended for local service discovery, acted as pre-authentication metadata leaks, exposing systems in workplace Wi-Fi, co-working spaces, and university networks.
### Deployment Failures & Attack Surface
The exposure stems from poor deployment hygiene rather than software flaws. Many instances self-announced internal structures via mDNS, providing attackers with reconnaissance data without active probing. A dedicated honeypot with 25 open ports suggested early attacker interest, while 635 accessible web control interfaces further expanded the attack surface.
The combination of service advertisements, open directories, and credential leaks creates pre-authentication compromise risks, allowing adversaries to bypass authentication, hijack agent identities, or conduct phishing and lateral movement attacks. The findings highlight systemic misconfigurations in Moltbot deployments, where operators often overlook mDNS implications and basic access controls.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2025
759
NOVEMBER 2025
759
OCTOBER 2025
759
SEPTEMBER 2025
759
AUGUST 2025
759
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for OVHcloud ??
What was OVHcloud's A.I Rankiteo Cyber Score in June 2026 ??
What was OVHcloud's A.I Rankiteo Cyber Score in May 2026 ??
What was OVHcloud's A.I Rankiteo Cyber Score in April 2026 ??
What was OVHcloud's A.I Rankiteo Cyber Score in March 2026 ??
What was OVHcloud's A.I Rankiteo Cyber Score in February 2026 ??
What was OVHcloud's A.I Rankiteo Cyber Score in January 2026 ??
What was OVHcloud's A.I Rankiteo Cyber Score in December 2025 ??
What was OVHcloud's A.I Rankiteo Cyber Score in November 2025 ??
What was OVHcloud's A.I Rankiteo Cyber Score in October 2025 ??
What was OVHcloud's A.I Rankiteo Cyber Score in September 2025 ??
What was OVHcloud's A.I Rankiteo Cyber Score in August 2025 ??
What is the average per-incident point impact on OVHcloud's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with OVHcloud ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view OVHcloud's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?