Notification regarding the phishing campaign targeting Hostico
The Hostico brand is targeted by a large phishing campaign. Find out how to identify fraudulent messages and what protective measures we recommend.

In the last two days, the Hostico brand has become the target of a large-scale phishing campaign, through which fraudulent email messages are being distributed that unlawfully use the identity of our company. The purpose of these messages is to deceive the recipients and to lead them to access malicious web pages, where their personal data, authentication information, or banking details may be compromised.
The first reports were received on Saturday, October 10, 2026, around 1:00 PM, when several recipients informed us of the existence of suspicious emails, presented as official Hostico communications. Throughout the day on Sunday, October 11, 2026, the fraudulent activity intensified considerably, with repeated waves of messages identified being distributed to .ro domain holders.
What measures have I taken so far?
Immediately after receiving the first reports, we began the necessary steps to inform users and limit the impact of this campaign.
In the first stage, we published warnings in the notifications section of the Hostico website, as well as on our official social media channels, to raise awareness about the fraudulent messages in circulation.
Meanwhile, abuse notifications were sent to the entities responsible for managing the domains involved in the attack. These reports targeted both the domain associated with the addresses used for sending messages and the domain used for redirecting recipients to the malicious pages.
Considering the intensification of the campaign on Sunday, October 11, 2026, we have decided to expand the information measures. Thus, a notification was sent via newsletter to all Hostico customers, and this information was also published on our blog, so it can be consulted by anyone receiving such a message.
How can fraudulent messages be identified?
Attackers try to create the impression that messages come from Hostico, using the company's name and elements that may suggest legitimate communication. Such attempts may invoke issues related to services, domains, invoices, or account security, in order to prompt recipients to act without verifying the authenticity of the request.
An important element is the links included in these messages. They direct users to websites that imitate legitimate pages, with the purpose of collecting the entered information, including passwords or credit card details.
To facilitate the identification of these fraud attempts, we present below an example of a message sent during the current campaign. This illustrates how attackers try to use Hostico's identity to lend credibility to the requests and to prompt recipients to access external links.

We mention that the presented example does not necessarily represent the only version of the messages in circulation, being the version that was identified at the moment. The content, sender addresses, and links used may be modified throughout the campaign, which is why we recommend not to rely solely on the similarity with the illustrated message.
Until this moment, among the addresses identified in the distribution of fraudulent messages are:
- support@sin1.singularitymfg.com
- support@haysoft.com.br
Important: The two email addresses are not necessarily the only ones used. Attackers may also use other email addresses or domains to continue the campaign. For this reason, we recommend checking any suspicious message, regardless of the address or name of the displayed sender.
We clarify that these messages are not sent by Hostico and do not represent official communications from our company.
How do you check if a message is from Hostico?
Official communications regarding contracted services are sent to the email addresses associated with client accounts or authorized sub-accounts. Among the official addresses used by Hostico are:
- office@hostico.com | office@hostico.com
- commercial@hostico.com | commercial@hostico.com
- help@hostico.com | tehnic@hostico.com
Verifying the sender's address is the first step, but it should not be the only criterion taken into account, as certain fraudulent messages can even spoof the information displayed in the sender's field.
If you receive a message requesting a payment, updating authentication details, or confirming personal information, we recommend accessing the website hostico.ro directly by manually entering the address in your browser, without using the links from the suspicious message.
Invoices and payment status can be checked in the Hostico client area, in the Financial section. Any payment operation must be performed exclusively through the official channels and the payment processor used by Hostico.
What you should do if you accessed a suspicious link?
If you have received one of these messages, simply receiving the email does not mean that your information has been compromised. However, it is important not to click on the links and not to provide data through the indicated pages.
If you have already accessed a fraudulent link or entered information on a suspicious page, we recommend you take the following measures, depending on the data disclosed:
- Change your Hostico account password. If you have entered your login details on a suspicious page, immediately reset your client account password. If the same password is used for other services, change it there as well.
- Enable two-factor authentication (2FA). This feature provides an additional layer of protection against unauthorized access. You can refer to the documentation on enabling two-factor authentication.
- Contact your card-issuing bank immediately. If you have provided banking details or card information, request an assessment of the situation and, if necessary, block or replace the card to prevent unauthorized transactions.
- Check account activity. Monitor for any unusual logins, unsolicited changes, and transactions you do not recognize.
- Check the security of the device. If you have downloaded or executed files from suspicious messages, perform a scan with an updated security solution.
Phishing campaigns can evolve rapidly, both by changing sender addresses and by using new domains or variations of messages. That's why identifying a fraudulent address does not guarantee that subsequent attempts will use the same source.
We encourage you to treat any unsolicited communication that asks you to urgently make a payment, log in, or provide confidential information with caution. In case of uncertainties, direct verification through official channels is always preferable to accessing a link from a suspicious message.
For questions, verification of the authenticity of certain messages, or reporting phishing attempts that use the Hostico identity, you can contact us at office@hostico.com or through the official contact page.
Thank you to all of you who reported these attempts. The information provided has allowed us to respond as early as the first identified messages and to inform as many users as possible in a short time.

