I wanted to pro-actively make this post to make our customers, other hosting companies, and Internet users on the whole aware of a situation that has arisen.
We have been dealing with an extremely difficult customer for quite some time now. They have violated our TOS on numerous occasions, and while we attempted to work with them to resolve issues and ensure that their services were not interrupted, they have continually accused us of wrong-doing and poor service. When they refused to work with us to resolve issues we asked them to find a new hosting provider. We opted to allow them to keep their sites active until they could migrate to a new provider, and they responded with a demand that is essentially blackmail – threating a class action suit and threatening to post negative reviews on Internet sites if we do not give them a full refund for all fees paid since they started hosting with us.
We have done some research and found that this customer has apparently done the same thing to numerous other hosting companies. Due to the threatening nature of their final email to us, we are making it public so that other hosting companies can be made aware of this and can hopefully avoid a similar situation.
We have extensive logs pertaining to their abuse of resources and violation of our TOS, including logs showing them forwarding massive numbers of emails (approximately 49,000 in a very short period of time) to providers like Hotmail, Gmail, etc. This resulted in our servers getting blacklisted and causing issues for many of our other customers. We gave them ample opportunity to remove the email forwards so that we would not have any further blacklisting issues, but due to their refusal to do so, we were forced to suspend their account until the issue was resolved. We worked with them to give them time to remove the forwards so that their downtime was minimized, yet they still accused us of bad business practices.
They are now apparently claiming that one of their sites was compromised and that this is what caused their resource abuse. They are placing the blame for the compromise on us despite the fact that there were no other reported compromises on that server. Further, the logs pretty clearly show that the resource abuse was the result of the forwarding of massive amounts of mail to external providers.
Based on what has happened here, the manner in which this customer has handled this situation, and the long history this customer has of trying to initiate class action lawsuits against providers, it appears that this may be a very well planned out and strategic attempt to receive free services and possibly even obtain financial gain. The issue is not the money they are asking for as a refund. In fact, from what we can tell, this is just the first step, and if we give in here, the threats and the monetary demands will just increase.
Because this customer is located in another country, we cannot initiate legal action to counter their blackmail attempts. So we have taken the money they are demanding – which is a relatively nominal amount – and donated it to the Support Crimes of Persuasion Foundation (http://www.crimes-of-persuasion.com/) since it is not the money that is the concern, it is the intent and malice these people are operating with.
Quote
1) We suspended their account because they simply refused to turn off their mail forwards (which were literally mail bombing Hotmail, Gmail, and others) so that we would not become blacklisted.
2) We agreed to re-activate their account based on 2 conditions: 1) they immediately remove all mail forwards and 2) they find a new hosting provider within 96 hours
3) Once they moved all of their accounts off of our servers, they began claiming that one of their sites were exploited and that was the cause of the problem, yet our logs show otherwise
4) We clearly showed them that only the one domain had suspicious files (out of the 100 or so domains they were hosting on one particular server), and that they had poor coding on that site which could potentially allow an injection. We later discovered that it is likely they uploaded that "malicious" code themselves. Regardless, the logs are pretty clear that the email abuse was resulting from external mail being forwarded and not any code injection they may or may not have had.
Here is a copy of the email they sent us:
Quote
We are requesting a full refund for all the payments we have made which is a
total of USD 244.89. We never received the full services we have paid for
and in addition we had paid extra for bandwidth that was caused by an
unauthorized upload into our website folder. Cartikahosting has wrongfully
accused our company of sending a large amount of emails which we believe
was due to a virus and files on your server. You have also suspended our
account which took down all our websites and caused disruptions in our
business which we suffered financial loss. This includes but not limited to
lost sales of 1500 USD per day, lost information and data, and advertising
of 2,042.94 + 450.18 for one period of July. We have had some of your emails
and information reviewed by legal advisors and we believe you are legally
liable for compensation to our company.
If you do not agree to the refund, we will continue to fight this by
complaining to the Better Business Bureau, as many online organizations in
regards to fraud, and will post this issue online to let others know this
bad business practice. We will continue to do so until we receive the full
refund. We have had damages in the thousands of dollars due to your
suspension of our account and we have all the documentation. However, if
you refund the full amount by July 17th and come to an agreement with us, we
will consider not proceeding to a legal suit against Cartikahosting.com to
claim the full damages. If not agreed upon, we are now notifying you that
we will post this issue online and let as many people know that we were
harmed by and a victim of Cartikahosting. We will continue to post this
issue on as many web hosting reviews and continue as long as we believe we
have not been compensated for your wrongful accusations and bad business
behaviour and ethics.
Please refund all payments made to you via our paypal account
REMOVED.
The amounts that need to be refunded by July 17:
#1DR6977010866152P USD 60.
#19D18121782024451 USD 60.
#9CA906532L040301L USD 40.
#97J608820P6436320 USD 40
#16582606S2775843X , USD 44.89
-------------------------------------------------
Total = 244.89
Payment is to be made via Paypal to our account REMOVED.
I want to thank all of our loyal customers in advance for your continued support and invite any comments. If any customer feels the way this customer does, I urge you to speak up as well and let your feelings be known. We value your feedback and will continue to strive to provide top quality hosting and customer service.
Edited by andrew-admin, 15 July 2009 - 11:30 PM.
formatting













