中文
HostDZireHosting provider · India

HostDZire: Unannounced VPS Suspension, Public Claims About Customers, and a Telegram Ban — Full Record

The full story, written by the customer involved. Official emails, tickets, Telegram messages and forum replies, all with the original wording and screenshots.

Happened to Published By sayyiku, the customer involved7 screenshotsOpen
The merchant replied on the forum and offered a refund, but has not explained or apologized for suspending without notice or for what it said in the group.
Timeline (7 entries)

Related discussion threads: NodeSeek #937638NodeSeek #938769

The purpose of this article is to give a complete account of my dealings with the hosting provider HostDZire over the past nearly two months.

No extra embellishment, and no exaggerated venting. I lay out the whole matter from beginning to end exactly as it happened: the timeline, the official email notices, the support ticket records, the statements made in the Telegram group, and their latest replies on the forum. Every unreasonable point is presented with facts and reasoning. Read it and judge for yourself.


Two Basic Premises and Definitions

Before going through the timeline, I must first make two core principles clear. They are the fundamental baseline of this entire matter:

Definition 1: My Demand — This Is a Matter of Principle, Not About Refunds or Arguing Over Data

My demand has never been any refund, and it is certainly not an unreasonable dispute over the data loss itself.
In the hosting industry, a provider’s Terms of Service (TOS) usually contain disclaimers about data integrity, and anyone who has used VPS for years understands that offsite backups are the customer’s own safety net. So from beginning to end, I have not argued about the lost data at all.
This is a question of principle:
My only demand, from start to finish, has been for the provider to respond to the issues directly, acknowledge its heavy-handed failures in operations and management, and apologize publicly!
Pulling the plug on a server without any warning or factual basis, fabricating claims about customers out of thin air in a large public group, bluntly pushing a refund to close the matter when confronted, and even using admin permissions to silence and kick people out — this kind of misconduct is not something that refunding a few dollars can settle.

Definition 2: Do Not Use TOS Disclaimers or “Cheap” as an Excuse

Do not use their so-called TOS — including but not limited to its various disclaimers — or “the price is cheap” and “you get what you pay for” as reasons why they may do as they please. Even cheap has its baseline!
When a server is sold cheaply, customers can accept older hardware, occasional network congestion, somewhat reduced performance, and slower ticket responses. That is the normal correspondence between pricing and product specification.
But “cheap” can never be an excuse for a provider to trample on a consumer’s basic right to be informed, suspend servers without cause, smear customers out of thin air in a public community, and kick people out to silence them when confronted!
Disclaimers protect the boundaries of law and force majeure. They are not a “get out of jail free card” that lets a provider abuse its administrative permissions and treat customers’ normal operations as worthless. A low price is not a pass for shamelessness, and no clause or price can whitewash heavy-handed conduct that crosses the line.


August 5, 2026: Underlying VMware Hit by Ransomware, All Data Permanently Lost

The story starts in early August.

HostDZire unexpectedly sent out an email announcing that their VMware ESXi virtualization infrastructure had suffered a ransomware attack.

HostDZire’s early-August notice about the VMware ransomware attackView full size
Exhibit 1HostDZire’s early-August notice about the VMware ransomware attackView full size

The official notice made three main points:

  1. Scope of impact: all VMware nodes in the India datacenter were hit, and some nodes in the Netherlands and the United States were compromised as well;
  2. Permanent data loss: the virtual disks (vmdk) on the host nodes were encrypted. Because the provider had no cold backups or offsite backups of any kind, all customer data was permanently lost and could not be recovered;
  3. Remediation: the provider physically powered off the host nodes via IPMI/iDRAC and reinstalled them from scratch, extending the service period of affected machines a little as compensation.

For users who had bought a VPS, availability was completely interrupted and data was wiped overnight. Although many people were unhappy at the time, ransomware is a risk the whole industry faces, so most people cooperated with the provider and redeployed their machines.


September 8, 2026: Self-Operated Machines Compromised Again, Proxies and SSH Backdoors Planted in Bulk

Only a month later, on September 8, customers with VPS on HostDZire’s self-operated India and Netherlands nodes again noticed anomalies:

  1. Proxy server software planted on machines: several users’ VPS had Xboard-related server software installed and were being used as free proxy nodes by illicit operators;
  2. A root backdoor written in: an unknown long-lived root SSH public key had been added to /root/.ssh/authorized_keys on the affected machines.

The provider sent out a security notice on September 8:

HostDZire’s September 8 security incident notice and emailView full size
Exhibit 2HostDZire’s September 8 security incident notice and emailView full size

Looking closely at the content of that email:

  • The provider insisted that the physical host nodes and WHMCS had not been directly breached, but mentioned that WHMCS had just released an undisclosed patch;
  • The provider attributed the cause to customers using the initial default password generated by the panel, allowing SSH password login, and not installing Fail2Ban, and thus being brute-forced;
  • The countermeasures the provider gave were worded, without exception, as Preventive Recommendation and Immediate Action Recommended, including reinstalling from the panel, changing the default password, changing the port, and using keys.

There is one crucial fact here:
The notice was advisory throughout. It contained no deadline of any kind, and not one sentence saying that “machines will be forcibly shut down if they are not reinstalled.”

Because I have always found HostDZire’s control panel crude and hard to use, with occasional errors, after receiving the September 8 notice I did not click “Reinstall” in the panel. Instead, from inside the server, I used a mature open-source community script (bin456789/reinstall) to reformat the whole system and install a clean Debian. After the reinstall the machine was clean, with no extra programs and no anomalous traffic whatsoever.


September 19, 2026: Server Suspended With No Warning at All

On the morning of September 19, with no prior notice and no email communication of any kind, my normally running machine suddenly became unreachable.

When I logged in to the client area, the machine had already been marked Suspended:

HostDZire suspends the VPS on September 19 on the grounds that it was not reinstalled from the panel
Exhibit 3HostDZire suspends the VPS on September 19 on the grounds that it was not reinstalled from the panelView full size

The reason the provider gave for the suspension was:

“This VPS has been suspended because the required OS reinstallation has not yet been completed. We previously sent a security notification on 8 September 2026 requesting that this VPS be reinstalled. Please open a support ticket to request temporary unsuspension of the VPS for data backup and OS reinstallation…”

This swaps one concept for another: the September 8 email clearly said Recommended, yet 11 days later, without any follow-up notice, the provider unilaterally recast it as required and used that as the reason to suspend the server outright.

I immediately opened a ticket in protest. The exchange went as follows:

Support ticket record of the HostDZire suspension disputeView full size
Exhibit 4Support ticket record of the HostDZire suspension disputeView full size
  1. 9:58, my ticket: protested the arbitrary suspension made without any warning or any concrete evidence of intrusion, and asked for restoration and an explanation;
  2. 10:27, support reply: rigidly insisted that “our records show your machine has not been reinstalled, hence the suspension. If you need a backup we can unsuspend temporarily, but after the backup you must reinstall from the panel”;
  3. 10:36, my reply: stated clearly that I had long since reinstalled the entire system with the open-source project reinstall.sh, and had simply not used their panel;
  4. 13:44, support reply: reversed course and unsuspended the machine, adding in passing: “If you re-install your VPS using script after 9 sep 2026 then it’s okay.”

This ticket exchange exposed two problems: First, the provider had not performed any actual security check on the machine at all. The sole basis for the suspension was whether their database held a record of the reinstall button being clicked; Second, one moment the provider said a panel reinstall was mandatory, and once told that I had reinstalled with a script, they changed their position and unsuspended on the spot, without verifying a single log line. The suspension was decided purely off the cuff.


September 20, 2026, Morning: The Provider’s Standard Ticket Template Reply

On the morning of the 20th, in response to a large number of users questioning the unexplained suspensions, the provider sent out a standardized ticket reply:

We previously sent a security notification on 8 September 2026 advising that this VPS needed to be reinstalled for security purposes. However, our records show that the VPS has still not been reinstalled.

As a result, we have suspended the VPS today as a security precaution.

To restore normal service, the VPS will need to be reinstalled with a fresh operating system. Once the reinstallation is completed, we can proceed with keeping the VPS active.

If you have important data on the VPS that has not yet been backed up, please let us know. We can temporarily unsuspend the VPS so you can take a backup of your required data. After the backup is completed, you will need to reinstall the VPS from the client area.

Please note that the temporary unsuspension is intended only for data backup before reinstallation.

You can review the original security notification sent on 8 September 2026 here:
https://tinyurl.com/468hsm75

Please let us know whether you need temporary access for backup, or if you are ready to proceed directly with the reinstallation.

Note: 
We suspended this VPS only because, according to our logs, it appears that the VPS was not reinstalled through the client panel after our security notification sent on 9 September 2026.
However, if you have already reinstalled the VPS using an external script, custom ISO, or any other method outside the client panel, please let us know.

In that case, no further reinstallation will be required from our side.

The Note the provider itself wrote at the end confirms the absurdity of the whole matter in their own words:

“We suspended this VPS only because, according to our logs, it appears that the VPS was not reinstalled through the client panel after our security notification sent on 9 September 2026. However, if you have already reinstalled the VPS using an external script, custom ISO, or any other method outside the client panel, please let us know. In that case, no further reinstallation will be required from our side.”

If the panel button had not been clicked, the machine was suspended across the board, even if it had already been wiped clean; yet if a user merely said in a ticket that they had reinstalled with a script, the provider let it through at once, without checking logs or verifying anything. This operational logic, which takes no account of whether customers’ services stay online, is hard to understand.


September 20, 2026, Afternoon: Groundless Claims About Customers in the Telegram Group, Then a Swift Kick After Being Confronted

After the matter spread in the community, the owner of HostDZire publicly posted an explanation in the official Telegram group:

HostDZire Official claims in the Telegram group that users did not check email because they use unique email addresses
Exhibit 5HostDZire Official claims in the Telegram group that users did not check email because they use unique email addressesView full size

HostDZire Official:
“Here is the message of explanation..”
“We can see since users are using unique email, they didnt even check their email, so didnt reinstall the vps. SO we have to not take force measures to prevent further damage.”

This inference is fabricated out of thin air:

  1. Users use unique or alias email addresses for their own privacy and security. How does that become an accusation of “not checking email”?
  2. I not only read the email, I had long since reinstalled the system with an open-source script, and I opened a ticket as soon as the machine was suspended. Unable to explain its own heavy-handed suspension, the provider simply made up a story about customers in a large public group.

I joined the group and pointed out, directly, their arbitrary suspension and shifting of responsibility. The owner’s response was blunt:

First, a one-line reply telling me to open a ticket for a refund:

HostDZire Official replies by asking for a refund ticket
Exhibit 6HostDZire Official replies by asking for a refund ticketView full size

HostDZire Official:
“Okay, open ticket for refund please,”

Then a longer message claiming not to mind criticism:

HostDZire Official states that people are free to criticize them on NodeSeek
Exhibit 7HostDZire Official states that people are free to criticize them on NodeSeekView full size

HostDZire Official:
“Again, i am not in mood for argument here.
If you guys are really that unhappy, i have offered refund options as well.
And all the possible explanation has been given already, if you have any more question, open ticket.
Do not argue here in telegram, you are free to criticize about us in nodeseek, i dont have any issue with that.”

In words, it was “i am not in mood for argument” and “you are free to criticize about us in nodeseek, i dont have any issue with that.”
Yet right after saying this, the group’s official administrators pressed the delete and ban buttons and kicked me out of the official Telegram group!

Beyond that, my Telegram account subsequently appears to have been hit by malicious mass reports, leaving me unable to post normally in public groups for a short time. You spread false claims about customers in a public group; the person concerned joins the group to confront you face to face; you do not dare answer a single substantive question, and then turn around, kick the person out of the group and resort to reports.


September 20, 2026, Evening: Playing the “Race Card” on the Forum

On the NodeSeek thread, at floor #27, HostDZire’s official account appeared and replied:

HostDZire (Floor #27):
@sayyiku #5 posted on 9/20/2026, 2:28:15 PM
@XXXX #3
对我来说就不是退款的事情 [For me, this is not about a refund]
Exactly, then what do you want?
Creating a thread here on NodeSeek and making fun of an Indian company, right? Is that your goal?
Let’s say you think the company sucks. I already offered you an exit option. You can take the refund and buy from another company that fits your expectations better.
Regarding whatever happened, we have already provided the information we could. But things can’t always happen exactly as per your expectations, right?
I understand that you wanted more details, but there will always be some things we are unable to do exactly as you expect.
So yes, if you feel our service is not meeting your expectations, then why not simply change providers?

The most notable thing about this reply is that he began trying to redirect the conflict by playing the “race card” and the “victim card”:
“making fun of an Indian company, right? Is that your goal?” — while still trying to sidestep the issue with “I already offered you an exit option.”

I rebutted this directly on the spot at floor #34 of the thread:

First: Please publicly acknowledge that this suspension was entirely a matter of poor judgment on your part. You suspended servers directly without the slightest prior communication. This is a serious man-made incident, and I need an apology!
Second: This is entirely my real experience as a buyer, not mockery at all. My article did not even compare your country with European or American providers in any way; I only mentioned your company name and the specific service nodes. And yet you say I am publicly mocking an Indian company? Why are you the one emphasizing that you are Indian?
Third: Please explain and apologize for this statement you made in the Telegram group:
“We can see since users are using unique email, they didnt even check their email, so didnt reinstall the vps. SO we have to not take force measures to prevent further damage.”
On what basis do you believe customers did not check their email? Is this your subjective assumption? As an official representative, passing judgment on users and forcibly suspending them with no factual basis whatsoever — please apologize for this!

Trying to divert attention with the “discrimination against an Indian company” line does not work in the Chinese-speaking hosting community, or in any technical community.
People pay for servers. What they care about is the SLA, data security, and whether the provider fundamentally solves problems when they arise. A machine suspended for no reason, false claims about customers in a group, a person kicked out when confronting them face to face — these are facts in black and white. Turning one’s own technical incompetence and heavy-handed operations into a question of nationality and identity is nothing more than an extremely clumsy way of shifting blame.


The Refund Dispute That Followed: Shifting Terms and Using the TOS as a Shield

Beyond the handling of my own machine, feedback from other community members on the forum (NodeSeek #938769, floors 51–58) further shows this provider’s record on keeping its word:

  1. Refund promises changed at will:
    The provider initially stated in the group that any dissatisfied user of the India datacenter could request a refund; once people actually opened tickets, the provider went back on this and added a Note in the group saying that “only users affected by this forced suspension can be refunded; all others will be refused” (floor 55);
  2. Using the TOS as a shield for a hostile attitude:
    A community member (floor 58) posted the provider’s original words from a refund request to support:

    “how many things we have to write ? as i said i cant write things as per your imagination, Do not argue. i denied your request, as per TOS i can do that. i have also updated the post just after some time with clear note, old post had confusion.”

As can be seen, from arbitrary shutdowns and shifting responsibility to bluntly refusing refunds, their constant refrain is “as per TOS i can do that.”


Summary of Facts

Going through the whole incident, every unreasonable point is clear:

  1. Security responsibility inverted:
    In August the host nodes were hit by ransomware and everything was lost, with zero cold backups on the provider’s side; in September self-operated machines were loaded with Xboard nodes and root backdoors, and the entire notice pushed the blame onto customers’ weak passwords;
  2. Formalism in operational decisions:
    Servers were forcibly suspended without notice, and the basis for the decision was not a security scan but the panel’s button-click log. Machines cleanly reinstalled with an external script were suspended outright, while a verbal statement was enough to restore them with no verification;
  3. Publicly fabricating customer behavior:
    In the official group, responsibility for the suspensions was publicly placed on customers “using unique email and not checking email” — purely a subjective invention with no factual basis;
  4. Refusing to communicate and silencing by force:
    Faced with a customer’s well-founded questions, the provider first brushed them off with a refund, and then, right after claiming “criticize freely, I don’t mind,” swiftly kicked the customer out of the group;
  5. Redirecting the conflict by playing the race card:
    In the public exchange on the forum, the provider stayed silent on the core responsibility and instead tried to distort a customer’s objective defense of their rights into “making fun of an Indian company”;
  6. Using disclaimers as a fig leaf:
    The refund policy changed from one day to the next, ticket communication was emotional, and the TOS was brandished at will to refuse communication.

As in the two definitions I set out at the beginning: First, my demand has never been that bit of refund, nor an unreasonable dispute over data. It is purely a question of principle — that the provider face its technical and management failures squarely and apologize publicly;
Second, do not use TOS disclaimers or “cheap” as an excuse for whitewashing. Even cheap has its baseline, and a low price is never a pass for trampling on customers’ right to be informed, suspending servers at will, spreading smears, and silencing and kicking people out.

The above is the full factual record of the incident from beginning to end. For users who are still using HostDZire or considering a purchase, I suggest checking against the evidence above and assessing for yourself their security defenses, operational standards and after-sales credibility.

Sources and screenshots

Links

Archived screenshots7 screenshots

Merchant response

The merchant has not responded yet.

If you are the merchant, or you found a mistake, email sa@catcat.blog. Responses are added here in full.