✦ Preferences saved
TRACE / SPECIAL CASE FILE 003

START HERE

A clear overview of the Hostinger case, the two documented incidents, Hostinger’s changing explanations, later corrections and the questions that remain unresolved.

CASE STATUS

Current case status

Case statusONGOING
Documented incidents02
Final internal reviewSEP 7, 2026
New recurrenceSEP 10, 2026
Preservation requestRECORDED
Hold applicationPENDING AT 17:40 CEST
Last updated

This case began with destructive malware-scanner action against working PHP files and developed into a dispute over what the scanner had detected, what technical work had actually occurred, what records existed, what had been sent to a third party and how the provider handled preservation. The documentary record now covers two separate destructive incidents, formal corrections by Hostinger and a new recurrence after Hostinger had already closed its internal review.

01

What happened

In August 2026, manager.php files associated with legitimate administrative software were classified by Hostinger’s malware system and subjected to cleanup that left the affected customer-facing files at 0 bytes. The dispute that followed was not limited to the classification itself. Hostinger’s technical account changed materially over time, several statements were later corrected or withdrawn, and the provider ultimately acknowledged shortcomings in the way the matter had been handled.

02

Why the record matters

The central issue for publication is the sequence of documented statements and records. Earlier explanations are preserved beside later corrections so that readers can see how the account evolved. A correction does not erase the earlier statement, and an unresolved question is not converted into a conclusion simply because the answer would be convenient.

03

Two documented destructive incidents

The August incident is documented through Hostinger communications, scanner-related records and preserved files. The September recurrence has an unusually clear boundary: a Hostinger-native pre-event backup preserves manager.php at 548,265 bytes, an independent same-day backup preserves exactly the same file, Hostinger’s malware interface records a new Malicious and Removed event, and a Hostinger-native post-event backup preserves the same path at 0 bytes.

04

What Hostinger later corrected

The later record includes formal correction of Monarx to Imunify, withdrawal of the alleged August 14 Engineering or manual scan, correction of the earlier hash-only description after Hostinger confirmed complete later/current file submissions to CloudLinux, confirmation that no allowlist was ever activated, and withdrawal of a specific size comparison that the retained event data did not support.

05

What Hostinger maintained

Hostinger’s final internal review continued to maintain that the August removal was correct and contractually permitted. Its final technical position described the detection as category and functionality based under an administrative-tools category, while stating that it had no file-specific record of authentication bypass, actual exploitation, account compromise, third-party access or a concealed malicious payload for the August files.

06

What remains unresolved

Important gaps remain because Hostinger’s preserved August event table did not contain several fields repeatedly requested during the dispute, including the original size and hash, exact rule version, scanner component and matched byte or region. The disappearance of a previously visible customer-facing escalation conversation remains unexplained. The complete downstream retention and chain of custody for CloudLinux submissions remains a separate question. For the September recurrence, actual application of the preservation hold was still unconfirmed at 17:40 CEST on September 11.

Established by the current record

Two destructive incidents are documented. Hostinger formally corrected or withdrew multiple earlier technical statements. Complete later/current files were submitted to CloudLinux. The September recurrence has a preserved pre-event and post-event boundary.

Still unresolved

The missing customer-facing conversation remains unexplained. Several original August forensic fields were not captured in Hostinger’s preserved event table. CloudLinux downstream custody questions remain open. Actual application of the September preservation hold was still unconfirmed at 17:40 CEST on September 11.