Cybercrime

cPanel ransomware attack

Critical vulnerability CVE-2026-41940 puts websites at risk

If you are currently affected by a ransomware attack, we are available to you at any time by phone available. We take over the coordination of an incident response team and guide you through all aspects of damage management.

„To recover your files, kindly send 0.1 BTC…“ – If this sentence suddenly appears instead of your website, you are most likely the victim of a current, large-scale Cybercrime incidents. A critical security vulnerability in the administration interfaces cPanel and WHM (Web Host Manager) is currently being actively exploited to compromise servers and issue ransomware demands.

Numerous companies, agencies, and online shops in Austria are affected, as their hosting is based on cPanel. The situation is serious because the vulnerability CVE-2026-41940 may potentially allow attackers administrative access. For those affected, urgent questions now arise: How could this happen? What data has been leaked? And what legal obligations arise toward customers and the data protection authority?

ATB.LAW supports affected companies in the legal and strategic management of this incident – from evidence preservation to crypto asset tracing.

cPanel/WHM leads to ransomware attacks on websites - ATB.LAW supports victims

Table of Contents

What happened? The background on the cPanel vulnerability

Since the end of April 2026, reports of compromised websites have been accumulating. At the core of the problem is a vulnerability in cPanel & WHM, known as CVE-2026-41940 was identified. This is an authentication management vulnerability (authentication bypass) that allows unauthorized persons to gain administrative privileges.

According to warnings from BSI and from CERT.at the situation is critical as exploits are already circulating. Affected systems often show an identical ransom note: the attackers demand the payment of 0.1 BTC to a specific Bitcoin address and demand the publication of a code on Twitter (X).

Who is at risk?

Potentially affected are all instances of cPanel and WHM that were not updated immediately after the security patches were released (versions from 110.0.x, 118.0.x, etc., depending on the release branch). This affects:

  • SMEs & Online Shops, who use shared hosting packages.

  • Web agencies, who operate reseller hosting for clients.

  • IT service provider, who manage server infrastructures via WHM.

  • Professional users (doctors, lawyers, tax consultants) whose CMS systems (e.g. WordPress) run on cPanel servers.

Immediate Action Checklist: What You Need to Do Now

If your website displays a ransom note or your hosting provider has informed you of a compromise, calm and deliberate action is crucial. Acting too hastily can make subsequent evidence gathering and the enforcement of claims massively more difficult.

  1. Do not delete prematurely: Do not immediately delete the compromised website or server. The data is needed for IT forensics.

  2. Securing evidence: Document the ransom note, the exact URL, and the Bitcoin address via screenshot (including timestamp).

  3. Save logs: Immediately request your hosting provider or IT service provider to secure all server logs (access logs, auth logs).

  4. No rash payments: Do not make any payment without first verifying its legal admissibility.

  5. Change passwords: As soon as access is secure again, all passwords (WHM, cPanel, FTP, databases, CMS admin) must be changed.

  6. Privacy check: Analyze whether access to personal customer data (names, emails, addresses, payment data) was possible.

  7. Expert assistance: Contact specialized lawyers and IT forensics experts to investigate the incident in a structured manner.

The legal situation in Austria: GDPR and liability

A cyber attack in Austria is not just a technical problem, but triggers a chain of legal obligations.

Data protection notification obligations (GDPR)

As soon as you are aware that personal data has been compromised by the cPanel hack (personal data breach), the clock is ticking. According to Art. 33 GDPR must send a message to Austrian Data Protection Authority (DSB) generally within 72 hours take place. In the event of high risk, the affected individuals (customers, users) must also be informed.

Liability issues: Who pays for the damage?

This is where it gets complex for businesses and agencies. When a vulnerability like CVE-2026-41940 is exploited, the question of accountability arises:

  • Does the Hosting provider Were necessary security updates (patches) installed in a timely manner?

  • Did the maintenance obligation lie with a Web agency, who missed the update?

  • Were contractually assured security standards violated?

ATB.LAW checks contracts with IT service providers and hosts for you in order to assert potential claims for damages due to defective maintenance or breaches of protective obligations.

Should one pay the 0.1 BTC?

The demand of 0.1 BTC seems moderate compared to large corporate ransomware cases. Nevertheless, warns ATB.LAW against premature transactions. As of the current status (May 1, 2026), making a payment is not recommended. There is (currently) no way to contact and negotiate with the extortionists, and not least because of this, there are significant Compliance risks.

Evidence preservation and crypto-asset tracing by ATB.LAW

In a cPanel ransomware attack, the boundaries between technology and law become blurred. ATB.LAW acts as an interface here. We not only secure the on-chain evidence (the Bitcoin transaction paths), but also coordinate the collaboration with IT forensic experts to secure the off-chain evidence (server logs).

In the event of criminal prosecution, we will represent your interests as a private party in the criminal proceedings in order to assert any potential claims directly there.

FAQ: Frequently asked questions about the cPanel hack

My website shows the ransom note, but I have a backup. Should I just restore it? Only after prior evidence collection and clarification of the break-in vector. If the vulnerability CVE-2026-41940 is not patched, the attackers will immediately reinfect the backup.

Do I have to report the hack? A criminal complaint is often strictly required for claiming insurance benefits (cyber insurance) and helps with documentation vis-à-vis the data protection authority.

What happens if I miss the 72-hour GDPR deadline? This can lead to heavy fines. It is advisable to consider a „precautionary notification“ even if the facts of the case are unclear. ATB.LAW supports you in the legally compliant formulation of these notifications.

Conclusion: Quick action is the order of the day

The cPanel ransomware attack via the vulnerability CVE-2026-41940 shows how vulnerable digital infrastructure is, even with widely used software. Those affected should neither ignore the incident nor make it worse through rash actions (such as unsecured deletion or unverified payment).

If your website is affected, a ransom note is displayed, or your hosting provider has confirmed a potential cPanel/WHM incident, swift and structured action should be taken. ATB.LAW assists victims of cybercrime incidents, ransomware, data protection issues, evidence preservation, communication with hosting providers, and the assessment of claims.

Affected individuals can contact ATB.LAW 24/7 – We are at your disposal at any time by phone available.

More articles

ATB.LAW Cybercrime Lawyer

Cybercrime in Austria

Legal situation, figures, and action steps
Picture of Roman Taudes
Roman Taudes
Business Email Compromise (BEC)

Business E-Mail Compromise

Who is liable – and when does a GDPR reporting obligation apply?
Picture of Roman Taudes
Roman Taudes
Cyberattack reporting obligations NIS GDPR MAR

Reporting obligations in the event of cyber attacks

What the TeamViewer case means for Austrian companies
Picture of Roman Taudes
Roman Taudes