Hostinger resets customer passwords following security breach

Network servers in data room Domestic Room
(Image credit: Shutterstock)

The web hosting company Hostinger has disclosed that it has experienced a security breach which impacted both its platform and users.

The company revealed in a blog post that a hacker was able to gain access to an internal server where he discovered an authorization token for an internal API. The hacker then used it to make “API calls affecting information about Clients”.

According to Hostinger, the hacker made API calls against a database which contained the personal information of around 14m customers that included their usernames, IP addresses, first and last names, and contact information such as their phone numbers, emails and home addresses. Information about user passwords was also stored on the database but thankfully it was in a hashed format.

Following the security incident, Hostinger decided to forcibly reset the passwords for all users whose accounts had been impacted as the company attempts to discover which of its customers were affected.

Security breach

The hacker did not obtain any financial data nor were they able to compromise customer sites according to Hostinger.

Following the security breach, the company set up a status page where customers can see up to the minute updates regarding the extent of the incident. Hostinger also said that the breached server and API have both been taken down.

The company provided further information on the steps it has taken following the security breach in a blog post, saying:

“Following the incident, we have identified the origin of unauthorized access and have taken necessary measures to protect data about our Clients, including mandatory password reset for our Clients and systems within all of our infrastructure. Furthermore, we have assembled a team of internal and external forensics experts and data scientists to investigate the origin of the incident and increase security measures of all Hostinger operations. As required by law, we are already in contact with the authorities.”

Via ZDNet

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring
NetSuite EVP Evan Goldberg at SuiteConnect London 2025
"It's our job to deliver constant innovation” - NetSuite head on why it wants to be the operating system for your whole business