Danish hosting and email provider webhot.dk disclosed a serious ransomware attack that forced it to take all systems offline and begin a full reconstruction of its environment. According to the company’s incident notice and subsequent reporting, the outage began on July 15 after a major security incident, and investigators concluded within hours that normal restoration was not possible. The provider rebuilt core systems from scratch rather than attempting a standard recovery.
webhot.dk said email service was restored later, but all email received before restoration was permanently lost, creating a significant data-loss event for customers. The company also required users to recreate accounts during recovery, and reports noted an unusual verification process that asked customers to provide the first or last three characters of their password along with their public IPv4 address, raising concerns about the sensitivity of the recovery workflow.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
On July 17, 2026 at 15:22, webhot.dk restored email service. The company said all email received before that time was permanently lost and that user accounts would need to be recreated during recovery.
By early July 16, 2026, the company's investigation concluded that normal restoration was not possible. webhot.dk decided to fully rebuild its systems as part of recovery from the incident.
webhot.dk disclosed that it shut down all systems on July 15, 2026 at 19:22 following a major security incident. The outage affected the provider's hosting and email services.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.