The company recently realized the breach through informational alerts that an adversary had accessed their servers. Explaining how it happened, the company stated in their notice,
This server contained an authorization token, which was used to obtain further access and escalate privileges to our system RESTful API Server. This API Server is used to query the details about our clients and their accounts.The database contained non-financial information of the users, such as their usernames, first names, email addresses, IP addresses, and hashed passwords. In all, it had information of about 14 million customers. Thus, the company suspects the breached might have impacted all 14 million users.
However, they assure that the financial information of users remained safe during the incident.
Payments for Hostinger services are made through authorized and certified third-party payment providers. It means that we never store any payment card or other sensitive Client financial data on our servers and it has not been accessed or compromised.The incident also did not affect the ‘data stored on accounts’ such as domains, websites, and hosted emails.
In addition, as they continue with the investigations, they have set up a dedicated status page to keep everyone updated.
Let us know your thoughts in the comments.