Back to overview
Resolved

Important Security Notice

Aug 30, 2026 at 10:00pm UTC
Affected services
VPS Servers (Perth)
VPS Servers (Auckland)
VPS Servers (Sydney)
VPS Servers (Melbourne)

Resolved
Sep 7, 2026 at 6:25am UTC

Our investigation into this incident is now complete.

Our findings have not changed since our previous update. We found no evidence that customer VPS instances were accessed or compromised, including the websites, files, databases and mailboxes stored within them.

The unauthorised SSH keys deployed during the incident were not used successfully, and those keys and the associated malicious software packages have been removed.

We have confirmed that customer names and email addresses stored in our VPS management platform were accessed and used to send the phishing emails referenced in our earlier updates.

We are contacting affected customers directly. If your details were involved, you will hear from us individually, and that message will set out what information was involved and what we recommend you do.

Please continue to be cautious with any email claiming to be from DreamIT Host.

As a precaution, we continue to recommend that VPS customers reset their control-panel and root passwords, and review /root/.ssh/authorized_keys for any entries they do not recognise.

The remediation work described in our earlier updates remains in place, and our team will continue to monitor closely.

We understand an incident like this causes concern, and we appreciate the patience and support our customers have shown throughout. If you have any questions, our Melbourne-based support team is available to help.

Updated
Aug 31, 2026 at 11:04am UTC

Our team has now completed the immediate remediation work on our VPS management platform.

We have removed the unauthorised SSH keys and the malicious software packages deployed during this incident, restricted and reviewed administrative access, and rotated the affected platform, API and service credentials.

We have also completed intensive auditing across our VPS infrastructure. This review found no evidence that the unauthorised SSH keys were used successfully, and no evidence that customer VPS instances were accessed or compromised. This includes websites, files, databases and mailboxes stored within customer VPS instances.

Our investigation is continuing, and we will update customers if this assessment changes.

We have confirmed that customer names and email addresses held in the management platform were accessed and used to send the phishing emails referenced in our earlier update. Customers whose details were involved are being contacted directly.

We are also sending a notification email to all DreamIT Host customers summarising this incident and the precautions we recommend. That email will not ask you to confirm a password or sign in through a link. If you receive a message claiming to be from us that does, please treat it as suspicious.

As a precaution, we continue to recommend that VPS customers reset their control-panel and root passwords, and review /root/.ssh/authorized_keys for any entries they do not recognise.

Thank you for your patience and support while our team completes this work.

Updated
Aug 31, 2026 at 3:35am UTC

We are responding to a security incident involving our VPS management platform.

We have contained the known malicious activity, restricted administrative access, and begun remediation across the affected infrastructure.

We have confirmed unauthorised access to the management platform database, which contains customer account and service information(VPS IP/hostname).

At this time, we have found no evidence that data stored inside customer VPS instances was accessed. Our investigation is continuing, and we will update customers if this assessment changes.

As a precaution, affected customers will need to reset their control-panel password, and some customers will need to re-enrol in multi-factor authentication.

As a precaution, if you have root SSH access, we suggest resetting your root password and checking your /root/.ssh/authorized_keys files for any suspicious keys.

If you do not have root SSH access, this can be done via my.dreamithost.com.au > Products/Services

We are also rotating platform and infrastructure credentials.

Access to some management functions may be temporarily limited while remediation continues.

We will contact affected customers directly with any required actions and provide another update when further verified information is available.

Updated
Aug 31, 2026 at 1:00am UTC

We have identified unauthorised access to our VPS management platform.

During the incident, an SSH key was deployed to multiple infrastructure hosts.

Our existing SSH and firewall controls blocked the observed attempts to use this key for direct SSH access.

At this stage, we have found no evidence that customer VPS instances were accessed as part of this incident.

We are removing the remaining key entries, rotating affected credentials, and completing fleet-wide security checks.

Our investigation remains ongoing, and we will provide further updates as more information becomes available.

Created
Aug 30, 2026 at 10:00pm UTC

We are investigating a security incident involving unauthorised access to part of our infrastructure.

VPS customers may have received an email titled "DreamIT Compromised" from noc@dreamithost.com.au.

This email was not sent by DreamIT Host.

Please do not click any links or attachments in it, and do not enter your login, payment, or personal details on any page it links to.

VPS customer names and email addresses may have been accessed.

There is currently no evidence that data on virtual servers has been accessed.

During this time, your services are still running; however, management access will be temporarily restricted while we investigate this further.

We will provide further updates as they become available.