What happened? The background on the cPanel vulnerability
Since the end of April 2026, reports of compromised websites have been accumulating. At the core of the problem is a vulnerability in cPanel & WHM, known as CVE-2026-41940 was identified. This is an authentication management vulnerability (authentication bypass) that allows unauthorized persons to gain administrative privileges.
According to warnings from BSI and from CERT.at the situation is critical as exploits are already circulating. Affected systems often show an identical ransom note: the attackers demand the payment of 0.1 BTC to a specific Bitcoin address and demand the publication of a code on Twitter (X).
Who is at risk?
Potentially affected are all instances of cPanel and WHM that were not updated immediately after the security patches were released (versions from 110.0.x, 118.0.x, etc., depending on the release branch). This affects:
-
SMEs & Online Shops, who use shared hosting packages.
-
Web agencies, who operate reseller hosting for clients.
-
IT service provider, who manage server infrastructures via WHM.
-
Professional users (doctors, lawyers, tax consultants) whose CMS systems (e.g. WordPress) run on cPanel servers.
Immediate Action Checklist: What You Need to Do Now
If your website displays a ransom note or your hosting provider has informed you of a compromise, calm and deliberate action is crucial. Acting too hastily can make subsequent evidence gathering and the enforcement of claims massively more difficult.
-
Do not delete prematurely: Do not immediately delete the compromised website or server. The data is needed for IT forensics.
-
Securing evidence: Document the ransom note, the exact URL, and the Bitcoin address via screenshot (including timestamp).
-
Save logs: Immediately request your hosting provider or IT service provider to secure all server logs (access logs, auth logs).
-
No rash payments: Do not make any payment without first verifying its legal admissibility.
-
Change passwords: As soon as access is secure again, all passwords (WHM, cPanel, FTP, databases, CMS admin) must be changed.
-
Privacy check: Analyze whether access to personal customer data (names, emails, addresses, payment data) was possible.
-
Expert assistance: Contact specialized lawyers and IT forensics experts to investigate the incident in a structured manner.
The legal situation in Austria: GDPR and liability
A cyber attack in Austria is not just a technical problem, but triggers a chain of legal obligations.
Data protection notification obligations (GDPR)
As soon as you are aware that personal data has been compromised by the cPanel hack (personal data breach), the clock is ticking. According to Art. 33 GDPR must send a message to Austrian Data Protection Authority (DSB) generally within 72 hours take place. In the event of high risk, the affected individuals (customers, users) must also be informed.
Liability issues: Who pays for the damage?
This is where it gets complex for businesses and agencies. When a vulnerability like CVE-2026-41940 is exploited, the question of accountability arises:
-
Does the Hosting provider Were necessary security updates (patches) installed in a timely manner?
-
Did the maintenance obligation lie with a Web agency, who missed the update?
-
Were contractually assured security standards violated?
ATB.LAW checks contracts with IT service providers and hosts for you in order to assert potential claims for damages due to defective maintenance or breaches of protective obligations.
Should one pay the 0.1 BTC?
The demand of 0.1 BTC seems moderate compared to large corporate ransomware cases. Nevertheless, warns ATB.LAW against premature transactions. As of the current status (May 1, 2026), making a payment is not recommended. There is (currently) no way to contact and negotiate with the extortionists, and not least because of this, there are significant Compliance risks.
Evidence preservation and crypto-asset tracing by ATB.LAW
In a cPanel ransomware attack, the boundaries between technology and law become blurred. ATB.LAW acts as an interface here. We not only secure the on-chain evidence (the Bitcoin transaction paths), but also coordinate the collaboration with IT forensic experts to secure the off-chain evidence (server logs).
In the event of criminal prosecution, we will represent your interests as a private party in the criminal proceedings in order to assert any potential claims directly there.
FAQ: Frequently asked questions about the cPanel hack
My website shows the ransom note, but I have a backup. Should I just restore it? Only after prior evidence collection and clarification of the break-in vector. If the vulnerability CVE-2026-41940 is not patched, the attackers will immediately reinfect the backup.
Do I have to report the hack? A criminal complaint is often strictly required for claiming insurance benefits (cyber insurance) and helps with documentation vis-à-vis the data protection authority.
What happens if I miss the 72-hour GDPR deadline? This can lead to heavy fines. It is advisable to consider a „precautionary notification“ even if the facts of the case are unclear. ATB.LAW supports you in the legally compliant formulation of these notifications.
Conclusion: Quick action is the order of the day
The cPanel ransomware attack via the vulnerability CVE-2026-41940 shows how vulnerable digital infrastructure is, even with widely used software. Those affected should neither ignore the incident nor make it worse through rash actions (such as unsecured deletion or unverified payment).
If your website is affected, a ransom note is displayed, or your hosting provider has confirmed a potential cPanel/WHM incident, swift and structured action should be taken. ATB.LAW assists victims of cybercrime incidents, ransomware, data protection issues, evidence preservation, communication with hosting providers, and the assessment of claims.
Affected individuals can contact ATB.LAW 24/7 – We are at your disposal at any time by phone available.