Skip to content
Security

What to Do If Someone Gets Root Access to Your VPS

17 June 2026 11 min read ESAGAMES Team

Finding out that someone else has root on your server is a gut-punch - but panicking makes it worse. This is a calm, practical incident-response plan for a hacked VPS: how to contain the damage, work out what happened, recover cleanly, and make sure it does not happen again.

First: how do you know you are compromised?

Common warning signs of a rooted VPS:

  • Unknown processes eating CPU or bandwidth (often crypto-miners or a botnet agent).
  • Logins, SSH keys or user accounts you did not create.
  • Outbound spam, scanning or attack traffic your host warns you about.
  • Changed passwords, disabled security tools, or files you cannot explain.
  • Your server suddenly part of a DDoS - as a source, not a target.

If you are seeing these, assume the worst and act methodically.

Step 1 - contain, do not destroy

Your instinct may be to wipe everything immediately. Resist it for a moment. First contain the incident so it cannot spread or do more harm, while preserving evidence of what happened:

  • Isolate the server from the network (your host's panel can usually cut networking or firewall it off).
  • Do not reboot yet - useful forensic data lives in memory and running processes.
  • If it holds customer data, treat it as a data breach and note the time you discovered it.

Step 2 - assume total compromise

This is the hardest mindset to accept: once an attacker has root, you can no longer trust anything on that machine. Logs can be edited, system binaries can be swapped for trojaned versions (rootkits), and clean-up tools running on the box can be lied to. You cannot reliably disinfect a rooted server - you can only learn from it and rebuild.

Once someone has had root, the only honest assumption is that nothing on that server can be trusted again.

Step 3 - investigate before you rebuild

Learn how they got in, so you do not just recreate the same hole. Look at:

  • Auth logs for the first unexpected login and its source IP.
  • New users, SSH authorized_keys entries and cron jobs - see diagnosing cron jobs if scheduled tasks look unfamiliar.
  • Recently modified files and unfamiliar listening ports.
  • Whether the way in was a weak SSH password, an exposed service, or an unpatched vulnerability.

Where you can, copy the logs and a disk snapshot off the machine first, so analysis happens on a trusted system.

Step 4 - rotate every credential

Anything that touched that server is now suspect. Change it all: SSH keys, root and user passwords, database credentials, API tokens, and any password that was stored or typed on the box. If the same password was reused elsewhere, change it there too.

Step 5 - rebuild clean

Do not "clean" the old install - rebuild from scratch. Provision a fresh OS, harden it before exposing it, restore only data (never binaries or system files) from a backup taken before the compromise, and patch fully before it goes live.

Step 6 - close the door for good

Whatever let them in, fix it on the new server, then harden properly:

How to explain this if you host other people's data or servers

If the compromised VPS hosted a game server, customer data or anyone else's content, be upfront with the people affected as soon as you have the facts - what happened, what data may have been exposed, and what you are doing about it. A quiet, honest disclosure early costs far less trust than a cover-up that comes out later.

The takeaway

A root compromise is recoverable if you stay calm: contain, investigate, rotate, rebuild clean, and harden. The pain is real - which is exactly why prevention, and good recent backups kept off the server, is worth far more than any cleanup. Managed, well-patched infrastructure removes a lot of this risk in the first place.

Less to worry about

Host on managed, patched, protected infrastructure — fewer doors left open, and backups when you need them.

See VPS hosting
More from the blog

Keep reading

Security

What Is the AISURU Botnet? The Terabit DDoS Threat Explained

One of the most powerful DDoS botnets of 2025–2026 — how AISURU infects IoT devices and why gaming is its #1 target.

5 June 2026
Security

DDoS Trends of 2025–2026: Bigger, Faster, and Aimed at Gamers

DDoS trends 2025–2026: attacks are bigger, faster and increasingly aimed at gaming. The key trends and what they mean for you.

20 May 2026
Buyer's guide

How to Choose a Game Server Host (2026 Buyer's Guide)

CPU, Anti-DDoS, location, panel, billing and support — the full checklist that actually matters before you choose a game server host.

8 May 2026
Infrastructure

Why Frankfurt Is the Best Location for EU Game Servers

Home to the world's biggest internet exchange — why Frankfurt gives EU game servers the lowest, most stable ping.

22 April 2026
Guides

Best Minecraft Modpacks to Host in 2026

From All The Mods 10 to RLCraft and Create — the best modpacks to run a server with this year, and the RAM each needs.

11 June 2026
Buyer's guide

How Much Does a Game Server Cost? (2026 Pricing Guide)

What actually drives the price of a game server by game and RAM — and what to expect to pay in 2026.

9 June 2026
Comparison

FiveM vs RedM: What's the Difference?

FiveM vs RedM: what each is, community size, setup differences, and which to choose for your roleplay server.

2 June 2026
Security

How to Protect Your Game Server From DDoS Attacks

Why game servers get attacked, what real DDoS protection looks like, and what you can (and can't) do yourself.

28 May 2026
Guides

Best Free Minecraft Server Plugins in 2026

EssentialsX, LuckPerms, WorldGuard, CoreProtect and more — the free plugins every Paper/Spigot server should run.

12 June 2026
Guides

Best CS2 Server Plugins in 2026

Metamod:Source, CounterStrikeSharp, MatchZy and more — the plugins that turn a CS2 server into retakes, pugs or practice.

12 June 2026
Guides

Best Rust Server Plugins in 2026 (Oxide / Carbon)

Admin tools, kits, economy, clans, raidable bases — the Oxide/Carbon plugins that build a sticky Rust server.

12 June 2026
Guides

Best FiveM Scripts & Resources in 2026

ESX/QBCore, ox_lib, ox_inventory, pma-voice and more — the resources every FiveM RP server is built on.

12 June 2026
Guides

Best Garry's Mod Server Addons in 2026

ULX, Wiremod, PAC3, DarkRP, TTT and more — the addons and gamemodes that make a Garry's Mod server.

12 June 2026
Guides

Best Valheim Mods to Run on Your Server in 2026

BepInEx, QoL, building and content mods — the best Valheim mods to run on a dedicated server this year, with a starter pack and sync rules that stop join failures.

12 June 2026
Guides

Best ARK Mods to Run on Your Server in 2026

Super Structures, Spyglass, Cryopods and more — the best ARK mods to run on a server this year, with load order and the ASE-vs-ASA differences that trip people up.

12 June 2026
Guides

Best Project Zomboid Mods for Your Server in 2026

QoL, vehicles, weapons and overhauls — the best Project Zomboid mods to run on a server this year.

12 June 2026
Guides

Best Palworld Mods & Server Tweaks in 2026

PalDefender, config tuning and QoL mods — the best ways to customise a Palworld dedicated server, plus the RAM and restart setup that keeps it stable.

12 June 2026
Guides

The Best Games to Host a Server For in 2026

Minecraft, Rust, FiveM, CS2, Palworld, Valheim, DayZ and more — the best games to run a server for this year.

12 June 2026
Security

What Is a DDoS Attack? A Plain-English Guide for Server Owners

No jargon — what a DDoS attack actually is, DDoS vs DoS, the main types, and how to actually stay online.

24 May 2026
Security

How ESAGAMES Anti-DDoS Protection Works

A look under the hood of our Anti-DDoS protection — multi-Tbps Frankfurt filtering and in-house XDP mitigation, always on.

23 May 2026
Infrastructure

What Is XDP DDoS Filtering? Line-Rate Protection Explained

eBPF/XDP filters packets in the kernel at line rate, before they reach your game. How it stops DDoS, and its limits.

21 May 2026
Security

What Is an IP Stresser or Booter? (And Why You Should Never Use One)

Booters and stressers are DDoS-for-hire. How they work, how they're abused against gamers, and the legal reality.

19 May 2026
Security

Layer 4 vs Layer 7 DDoS Attacks Explained

Network-layer floods vs application-layer attacks — the real difference, gaming examples, and how each is stopped.

17 May 2026
Security

Is My Game Server Being DDoSed? How to Tell

Attack or just lag? The tell-tale signs of a DDoS, how to confirm it with real tools, and what to do during and after.

15 May 2026
Infrastructure

Inside the ESAGAMES Network: Frankfurt, Peering and Low Ping

Why we build in Frankfurt, what peering actually means, how it cuts ping, and how it ties into DDoS filtering.

13 May 2026
Guides

Game Server Lag: Is It Your CPU or Your Network?

Lag comes from two places: CPU tick rate or the network. How to tell which is hurting you, and how to fix it.

12 May 2026
Security

What Is a Botnet? How Everyday Devices Become DDoS Weapons

A botnet is an army of hijacked devices used to launch attacks. How they are built, controlled, rented and stopped.

31 May 2026
Security

What Is the Mirai Botnet? The Malware That Rewrote DDoS

The IoT malware that launched record DDoS attacks and inspired today's botnets. What it is and why it still matters.

30 May 2026
Security

DDoS Attack Vectors Explained: UDP, SYN, Amplification and More

A detailed tour of the main DDoS techniques - UDP, SYN, amplification, fragmentation, Layer-7 - and how each is stopped.

1 June 2026
Security

How to Protect a TeamSpeak or Voice Server From DDoS

Voice servers are easy targets and very sensitive to lag. Why TeamSpeak gets hit and how to actually protect it.

29 May 2026
Reference

Anti-DDoS Glossary: Key Terms Every Server Owner Should Know

Plain-English definitions of the DDoS and Anti-DDoS terms you will actually run into - from botnet to XDP.

27 May 2026
Guides

Game Server Security Checklist (Beyond Anti-DDoS)

DDoS is one threat among many. A practical hardening checklist for passwords, admin access, backups and more.

26 May 2026
Security

The Biggest DDoS Attacks in History: Records That Broke the Internet

From the Mirai attack that took down Twitter to record multi-terabit floods - the attacks that broke the internet.

10 June 2026
Security

Why Do People DDoS Game Servers? The Motives Behind the Attacks

Rivalry, revenge, extortion, boredom - the real reasons people attack game servers, and what it means for you.

9 June 2026
Guides

What Is Tick Rate? Why 64 vs 128 Tick Matters

Tick rate is how often a server updates the world per second. What it means, and why 64 vs 128 tick matters.

7 June 2026
Guides

What Is Netcode? Why Your Shots Don't Always Register

Netcode keeps online players in sync. What it is, why hit-reg feels off, and how lag compensation works.

6 June 2026
Guides

What Is Ping, and How Do You Lower It?

Ping is the delay between you and the server. What causes high ping, and practical ways to lower it.

4 June 2026
Comparison

Dedicated vs Shared Game Server Hosting: What's the Difference?

Shared, VPS or dedicated? What each means, the real trade-offs, and which is right for your community.

3 June 2026
Guides

How to Secure a Linux VPS: A Hardening Checklist

SSH keys, firewall, updates, brute-force protection, least privilege - the essentials to harden a Linux VPS on day one.

14 June 2026
Guides

How to Harden SSH and Stop Brute-Force Attacks

SSH is the most attacked service on most servers. How to harden it: keys, no root login, and stopping brute-force bots.

13 June 2026
Security

Famous Linux Vulnerabilities Every Server Owner Should Know

Heartbleed, Shellshock, Dirty Pipe, PwnKit, regreSSHion - the famous Linux bugs, what they did, and the lessons.

16 June 2026
Security

The XZ Backdoor: How the Internet Almost Got Backdoored

A hidden backdoor in a core Linux library, planted by a trusted maintainer over years and caught by luck. The story.

15 June 2026
Infrastructure

What's Changing in Linux & OS Security (And Why It Matters)

Rust in the kernel, Wayland, the memory-safety push, io_uring caution, the CentOS shift - the changes reshaping OS security.

11 June 2026
Web Hosting

How to Speed Up a WordPress Website (2026 Guide)

The things that actually make WordPress fast - from hosting and caching to images, plugins, database and CDN.

14 July 2026
Web Hosting

How to Migrate a WordPress Site to a New Host (Without Downtime)

Move WordPress to a new host without breaking it - the safe, zero-downtime way, step by step.

13 July 2026
Comparison

Shared vs VPS vs Dedicated Hosting: Which Do You Need?

A plain-English comparison of the three hosting tiers - cost, performance, control and who each is really for.

12 July 2026
Buyer's guide

How to Choose a Web Hosting Provider (2026 Checklist)

What actually matters when picking a web host - and the red flags that give a bad one away.

11 July 2026
Comparison

cPanel vs DirectAdmin vs Plesk: Which Control Panel?

The three big hosting control panels compared - ease of use, features, speed, security and cost.

10 July 2026
Web Hosting

How to Secure a WordPress Website: A Practical Checklist

The practical steps that stop the vast majority of WordPress hacks - no paranoia required.

9 July 2026
Security

Januscape (CVE-2026-53359): The KVM Bug That Lets a VM Escape to the Host

A 16-year-old Linux KVM flaw lets a guest VM break out to the host on Intel and AMD. Are you affected, and what to do.

15 July 2026
Security

TeamSpeak 3 Server Vulnerabilities (CVE-2026-4390/4391/4392): Update to 3.13.8

Three High-severity crash bugs hit TeamSpeak 3 Server 3.13.7 and below - what they do and how to patch.

13 July 2026
Security

cPanel & WHM Authentication Bypass (CVE-2026-41940): Patch Now

A critical, actively-exploited cPanel & WHM auth bypass (CVSS 9.8). Are you affected, and exactly what to do.

14 July 2026
Comparison

ESX vs QBCore vs Qbox: Which FiveM Framework in 2026?

The one FiveM decision that is expensive to reverse — compared honestly on scripts, performance and community.

17 July 2026
Guides

Does SourceMod Work on CS2? (No — Here's What to Use)

SourceMod does not support CS2 — not in 2026, not through a bridge. Here is what actually replaced it.

17 July 2026
Payments Secure checkout with cards, banking apps and digital wallets.

Choose the payment flow that fits your stack and region without leaving the platform.

Pay by Zen Visa Mastercard Paysafecard PaysafeCash Skrill Trustly Bancontact UnionPay iDeal WebMoney