START HERE
A clear overview of the Hostinger case, the two documented incidents, Hostinger’s changing explanations, later corrections and the questions that remain unresolved.
Current case status
This case began with destructive malware-scanner action against working PHP files and developed into a dispute over what the scanner had detected, what technical work had actually occurred, what records existed, what had been sent to a third party and how the provider handled preservation. The documentary record now covers two separate destructive incidents, formal corrections by Hostinger and a new recurrence after Hostinger had already closed its internal review.
What happened
In August 2026, manager.php files associated with legitimate administrative software were classified by Hostinger’s malware system and subjected to cleanup that left the affected customer-facing files at 0 bytes. The dispute that followed was not limited to the classification itself. Hostinger’s technical account changed materially over time, several statements were later corrected or withdrawn, and the provider ultimately acknowledged shortcomings in the way the matter had been handled.
Why the record matters
The central issue for publication is the sequence of documented statements and records. Earlier explanations are preserved beside later corrections so that readers can see how the account evolved. A correction does not erase the earlier statement, and an unresolved question is not converted into a conclusion simply because the answer would be convenient.
Two documented destructive incidents
The August incident is documented through Hostinger communications, scanner-related records and preserved files. The September recurrence has an unusually clear boundary: a Hostinger-native pre-event backup preserves manager.php at 548,265 bytes, an independent same-day backup preserves exactly the same file, Hostinger’s malware interface records a new Malicious and Removed event, and a Hostinger-native post-event backup preserves the same path at 0 bytes.
What Hostinger later corrected
The later record includes formal correction of Monarx to Imunify, withdrawal of the alleged August 14 Engineering or manual scan, correction of the earlier hash-only description after Hostinger confirmed complete later/current file submissions to CloudLinux, confirmation that no allowlist was ever activated, and withdrawal of a specific size comparison that the retained event data did not support.
What Hostinger maintained
Hostinger’s final internal review continued to maintain that the August removal was correct and contractually permitted. Its final technical position described the detection as category and functionality based under an administrative-tools category, while stating that it had no file-specific record of authentication bypass, actual exploitation, account compromise, third-party access or a concealed malicious payload for the August files.
What remains unresolved
Important gaps remain because Hostinger’s preserved August event table did not contain several fields repeatedly requested during the dispute, including the original size and hash, exact rule version, scanner component and matched byte or region. The disappearance of a previously visible customer-facing escalation conversation remains unexplained. The complete downstream retention and chain of custody for CloudLinux submissions remains a separate question. For the September recurrence, actual application of the preservation hold was still unconfirmed at 17:40 CEST on September 11.
Two destructive incidents are documented. Hostinger formally corrected or withdrew multiple earlier technical statements. Complete later/current files were submitted to CloudLinux. The September recurrence has a preserved pre-event and post-event boundary.
The missing customer-facing conversation remains unexplained. Several original August forensic fields were not captured in Hostinger’s preserved event table. CloudLinux downstream custody questions remain open. Actual application of the September preservation hold was still unconfirmed at 17:40 CEST on September 11.