My dedicated server is compromised, what should I do?
Unusual behavior, an alert from your antivirus, an email from a recipient's mail provider reporting spam sent from your IP, or simply a doubt. If you think your dedicated server has been compromised, every minute counts. Here is what to do:
1. Don't panic, but act fast
A compromised server can be used as a relay to attack other systems, send mass spam, or expose your customers' data. The sooner the situation is brought under control, the more the damage (technical, but also legal and reputational) will be limited.
2. Contact us immediately
The most effective route is to open a request from your Client Area, under "Open a request", clearly stating that this is a security emergency. You can also email us at technique@hodi.host. Tell us what raised your suspicions (error message, alert received, behavior observed). We can help you confirm the compromise, assess its scope, and support you on the actions to take.
If you subscribe to our MDR (managed cybersecurity) offering, delivered by our partner Acronis, monitoring of your infrastructure is already in place and allows a response with context already established for your environment.
3. Avoid these reflexes, which can make the situation worse
- Do not request an immediate reinstall of your server before the flaw behind the compromise has been identified, at the risk of reproducing it exactly. Note as well that reinstallation is not something you can carry out yourself, it must go through a request to our team
- Do not delete suspicious files or logs, they are valuable for understanding what happened
- Do not change all your passwords from the potentially compromised server itself, as an attacker present on the system could intercept your new credentials
4. Consider your obligations if personal data is involved
If the compromise may have exposed personal data (that of your customers, employees or users), it may constitute a data breach within the meaning of the GDPR, with obligations to notify the CNIL and, depending on the case, the people concerned. This point is worth checking with your GDPR officer or legal counsel.
5. Consider a clean return to service
Once the flaw has been identified and fixed with our team, it is often preferable to ask us to rebuild your server from a healthy backup rather than simply "cleaning" a system that may still be compromised at a deeper level. If you have subscribed to one of our Acronis granular backup options for dedicated servers (with or without Managed DRP), we can restore your environment to a state prior to the incident.
6. An in-depth analysis if needed
If the situation calls for it, we can put you in touch with our partners at Soobik, who specialize in analyzing what happened (forensic analysis) and in remediating this type of incident. Valuable support to understand precisely where the compromise came from and to make sure it does not happen again.
Reducing the risk going forward
Once the incident has been handled, it is also an opportunity to strengthen the protection of your dedicated server. Several of our cybersecurity products can help.
- Managed firewall. It must be ticked when you order your server, otherwise you remain responsible for managing your own firewall. Once enabled, it filters inbound access according to rules managed by our team
- v6Protect, our intelligent WAF. An application firewall that filters malicious web traffic before it reaches your applications
- Attack Surface Monitoring. Linked to v6Protect, it provides continuous monitoring of your server's exposure points on the Internet, to spot a vulnerability before it is exploited
- MDR, our managed cybersecurity offering. Delivered by our partner Acronis, it brings continuous monitoring of your server, with real-time threat detection and response
Do ask us for advice on the combination best suited to your business and your level of exposure.
An emergency in progress?
Open an urgent request from your Client Area, or contact us by email at technique@hodi.host, our technical team remains available to support you in handling the incident.
Updated on: 20/07/2026
Thank you!