No response from abuse@ovh for two weeks – Fraudulent site hosted by OVH

Hello everyone,

I am a victim of active identity theft via a fraudulent site hosted on OVH's infrastructure: xenon-tv.fr

My original site: xenontv.io

This site is an exact copy of mine, used to scam my clients and sell illegal content under my name.

It is an organized repeat offender who has already operated under several fraudulent domains:

The site was initially hosted at Namecheap, which suspended it quickly after my report. Written confirmation received:
“Please be informed that the reported domain has been suspended.”

Immediately after this suspension, the fraudster changed his DNS records at Cloudflare to migrate to a new host — OVH SAS — in order to bypass the shutdown and continue his fraudulent activities.

Here is the chronology of the observed DNS changes:

Cloudflare confirmed this migration in writing and designated OVH SAS as the current host, explicitly providing me with the address abuse@ovh.net for follow‑up.

This behavior demonstrates a deliberate and organized fraudulent intent with active circumvention of suspension measures.

Despite several emails sent to abuse@ovh.net for more than two weeks, there has been no response and no action from OVH.

As a French hosting provider, OVH is subject to the LCEN (Law No. 2004‑575 of 21 June 2004, article 6), which requires prompt action upon notification of manifestly illegal content.

This prolonged inaction constitutes a serious breach of those legal obligations and engages the civil and criminal liability of OVH SAS as a host.

Without swift action, I will be forced to:

  • Involve ARCOM for non‑compliance with the LCEN
  • File a criminal complaint
  • Initiate an emergency summary proceeding

OVH is today the last line of defense to stop this fraudster. I have all the necessary evidence and am available to provide it immediately.

Can a moderator or OVH staff member escalate this case urgently?

Thank you

Hi @XenonTV

The email abuse@ovh.net, although it exists, is a public channel. Experience shows that emails sent there may not receive a quick response or may end up in a limbo :smirking_face:

The official procedure, clear and documented by OVHcloud, is to use the abuse report form. It is the tool designed for this purpose and is the one that has a more direct workflow for the Trust & Safety teams.

Go directly to this URL https://www.ovhcloud.com/es/abuse/

Make sure to read the terms of use. This form is the channel that generates an “optimized ticket” for the Abuse team.

I hope they provide a solution as soon as possible :folded_hands:

Best regards,
Sergio Turpín

Hello,
What exactly did CloudFlare answer you? Why don’t they cut off their CDN service?
I just looked and this hosting behind Cloudflare isn’t landing on OVH WebHosting (but maybe on a VPS or another service).

Hey,
In my opinion OVH is going to shut down your hosting.

Thanks for your feedback, the issue is that I can’t fill out the abuse form because its URL isn’t recognised by OVH as hosted with them, since it changed its DNS records at Cloudflare.

I’m completely blocked at this point and the only recourse is by email, but they completely ignore me..

Thanks for your reply. Could you be clearer, please?

It was Cloudflare that told me to contact OVV after I filed a report with them, saying that the site is hosted by them.

OVH, however, do not respond to me at all.

What does that mean, pls?

I'm really desperate here ..

Hello @XenonTV

Create an Incident ticket:

OVH Manager > https://www.ovh.com/manager/#/dedicated/useraccount/dashboard > My support requests > Create a request / ticket

then:

Call OVH support on Monday at +33 9 72 10 10 07.
Preferably between 8 a.m. and 9 a.m. in the morning, or around 3 p.m. there is less waiting.

Or on Twitter @ovh_support_fr or #OVHcloudsupport

Hello @XenonTV

The key is to obtain the real IP address of the OVH server hosting the fraudulent site, which is “hidden” behind Cloudflare. To do that, you can use an online IP‑lookup tool such as ipinfo.io or similar…

Having this IP, and given the complexity of your case, you can send your report by postal mail to the address:

OVHcloud – Trust & Safety Team – 2 rue Kellermann, 59100 Roubaix, France.

This is the most formal and legally binding route for this type of identity‑theft and fraud cases.

Alternatively, you can use the web form I mentioned and try to fill the “Content location” field with the OVH IP address you found so they will let you process it.

The postal route, although slower, guarantees that your report is formally recorded and OVH is required to process it. Don’t give up :flexed_biceps:

Sergio Turpín

Not easy, these situations where we go round in circles :joy:

I confirm, as support and encouragement for your approach, that I’m being spoiled in my inboxes by emails from this very active sender.

I recently experienced a similar situation: my mailbox was blocked because a spoiler acting apparently through an IP from an OVH IP block caused the public IP assigned by OVH to my server to be blacklisted on both IPv4 and IPv6.
As a result I can no longer send any outgoing emails.
I contacted Spamhaus and others, who ended up telling me: we can’t remove you from the blacklist because the IP (the IP block) belongs to OVH.
Okay, I reached out to OVH, and they replied: we can’t do anything because we don’t know which IP(s) are the culprits…
Conclusion: I’m left without an answer or a solution, my server being on a fixed, unique IP (KS series)… For how long?
I resigned myself to ordering two new SYS servers to get new IPs, and I also added an additional IPv4 block to get around this type of obstacle, and of course I terminated my KS server with its blacklisted OVH IPs! Luckily for me the deadline was June 30, sparing me a month’s bill for a server that could no longer serve me!

Not cool: no mail services for days and impossible to inform my contacts because they can’t receive my email, plus a monthly budget more than double for a solution that should protect me from a situation that isn’t my fault and depends on OVH, depriving me of my services. Not to mention the work of backing up my KS server, ordering and installing my new dedicated servers, my software, tools, configuring everything, setting it up, testing…

I can understand the issue as described by OVH, but I’m personally disappointed that OVH, my contacts (bot and email support – now an AI agent, automata or call centers) offered me no solution such as a server change or an additional IP pack for free, even though I only subscribed to basic support. I’ve been an OVH customer since day one; back then this wouldn’t have happened. But of course yesterday’s OVH is not today’s OVH, and with the massive size and growth we end up facing the same bureaucracy, task‑slicing and decision‑making delays, this (in)humanity that any large organization or institution suffers.
We are the first to praise the incredible, extraordinary things technology allows us to do, but we are also aware of its negative sides.

Wow, what a situation. What you're describing is the flip side of having an IP in an OVH range: if someone misbehaves in your same block, you end up paying the price. It's like getting fined for parking badly because your neighbor has the same car model and the same color :smirking_face:

Anyway, I hope your new SYS go better, and that OVH finally realizes that the reputation of its IPs is its own concern, not ours.

Regards.

Yes exactly. That’s the flaw I unfortunately discovered to my detriment.

I hadn’t been aware of it until now because I had never had any problem.

But for more than a decade I have been doing everything to be independent, control my data, not rely on the GAFAM or any other actor, even outside of IT. Autonomous, free. And so, as soon as I realized it, I decided to free myself from this dependence.

But naturally, freedom and independence come at a price, require effort, and you have to own it, take responsibility.

If at least my message has helped raise awareness in others, while perhaps OVH informs its customers of this risk, we can hope for it, can’t we?