Automatic (machine) translation. This text was translated automatically from the Polish original and may contain inaccuracies. In case of any doubt, the Polish version is the authoritative one.
← Back to Knowledge
Knowledge

Acquiring data from OVH infrastructure — what can really be obtained and how to act fast

OVH (OVHcloud) is the largest European hosting provider and one of the most common 'waypoints' in internet-crime cases. OVH VPS servers are used for phishing, malware distribution, sextortion operations, scam campaigns and for logging into the webmail of Polish mail providers. In many proceedings, identifying the tenant of a specific OVH VPS is the final technical step leading to deanonymising the perpetrator.

Acquiring data from OVH infrastructure — what can really be obtained and how to act fast

OVH (OVHcloud) is the largest European hosting provider and one of the most common "waypoints" in cases involving internet crime. OVH VPS servers are used for phishing, malware distribution, sextortion operations, scam campaigns and for logging into the webmail of Polish mail providers. In many proceedings, identifying the tenant of a specific OVH VPS is the final technical step leading to deanonymising the perpetrator.

From a practitioner's perspective — a prosecutor, an expert, a victim's lawyer — OVH differs from Google or Meta in several important respects that are worth knowing before a case arises. The most important difference is that OVH has no self-service portal for law enforcement. Below — what can realistically be obtained, by which route, and how not to lose weeks on procedural mistakes.


1. What can realistically be obtained from OVH

Three categories of data are available in the OVH ecosystem:

Technical and subscriber data (non-content data) — this is the most commonly expected scope. It covers the service tenant's data (first name, surname, address, phone, contact e-mail), the payment method (card, SEPA, crypto) with the holder's data, the OVH customer account identifier, customer-panel login logs (date, IP, User-Agent — often the perpetrator's "clean" home IP, without a VPN), SSH/KVM access logs to the VPS itself, network netflow, and — particularly valuable — a list of all services assigned to the same customer account, i.e. the perpetrator's entire operational fleet.

Server content (content data) — files on the VPS/server disk, databases, machine images, memory dumps. Made available only on a court order, a European Investigation Order (EIO), or — from August 2026 — via the new EPOC procedure.

Data preservation — a temporary freeze of everything above for 90 days (extendable), carried out within 48–72 h.

The whole mechanism looks like this:


2. No LERS portal — how it changes your workflow

Google has LERS, Meta has the Law Enforcement Portal, Microsoft has the Law Enforcement Request Portal (LERP) — everywhere you log in with an official domain and submit a request by clicking. OVH has nothing like that. Requests go to a dedicated Trust & Safety Team / Compliance Department in OVH's Legal Department in Roubaix, which handles them the classic way, by e-mail and post.

In practice this means that:

  • you send a scan of the request with an electronic signature to legal@ovhcloud.com,
  • in parallel, a registered letter with acknowledgement of receipt to the address: OVHcloud — Trust & Safety Team, 2 rue Kellermann, 59100 Roubaix, France,
  • you receive an acknowledgement of receipt within a few business days,
  • for metadata you typically get a response in 2–6 weeks.

This is not complicated — it is simply different. Treat OVH like any other institutional partner: a letter with a reference number, a scan, a registered letter, a trace in the case file.


3. The golden rule — preservation within 48 hours

The biggest mistake we see in cases involving OVH is delaying preservation. Prosecutors and experts often start with a formal EIO, which takes 2–6 months, and during that time OVH logs may be deleted — standard netflow retention is 12 months, but for older events it is not guaranteed.

There is a faster route that is used too rarely: Article 29 of the Council of Europe Convention on Cybercrime (the Budapest Convention, Journal of Laws 2015, item 728). Poland and France are parties to the Convention and run 24/7 Network contact points. The route: the prosecutor's office → CBZC (the Polish 24/7 point) → OCLCTIC (the French counterpart within the DGPN) → OVH. A preservation request does not require an EIO, and OVH freezes the data within 48–72 h for a period of 90 days (extendable to 180).

Practical rule: send the preservation request on the same day you uncover the case. The formal non-content request or EIO is filed afterwards, calmly, without time pressure.


4. Three tricks that save weeks

Work with the VPS identifier, not just the IP. Every OVH VPS has a default hostname vps-XXXXXXXX.vps.ovh.net, where XXXXXXXX is a unique machine key. You can check it with a single command (nslookup 145.239.94.171 → vps-a70a94b5.vps.ovh.net). In your request to OVH, write explicitly "VPS instance a70a94b5" — IP addresses in OVH are rotated between customers, whereas the VPS identifier is permanent and historically unambiguous. This eliminates the risk of a reply that "the IP address was not assigned to any customer at that time".

Split your requests: metadata separately, content separately. Putting everything into a single EIO means that even simple subscriber data sits in the queue for 3 months together with a disk image. OVH provides subscriber data and logs on the basis of the prosecutor's EU request alone — this is the "fast track", without the need for an EIO.

Ask about related services. In your non-content request, add: "please provide a list of all services (VPS, dedicated servers, domains, SSL certificates) assigned to the same OVH customer account". A single question can reveal the perpetrator's entire operational fleet — a dozen or so VPS servers, domains and accounts from which they ran parallel campaigns. Without that question, you see only one machine from one case.


5. What an expert can do without any request to OVH

Before a formal request is filed, valuable material can be obtained from public resources: reverse DNS, RIPE NCC records, passive DNS (SecurityTrails, DNSDB), Certificate Transparency, Shodan and Censys, and reputation databases (AbuseIPDB, VirusTotal, MalwareBazaar, URLhaus). For a specific OVH IP, an expert can, within a few hours, map the history of domains, SSL certificates, earlier abuse reports and links to other campaigns. Material secured in this way — with SHA-256 checksums and timestamps — has full evidentiary value with respect to publicly available content and often makes attribution plausible even before the formal channel starts.

The expert practice FireNet supports prosecutors, law firms and law-enforcement agencies in obtaining and analysing data from OVHcloud infrastructure. We prepare ready-made drafts of preservation requests, non-content requests and EIOs for content data — in line with OVH's requirements and French criminal procedure. We help map the perpetrator's operational fleet, correlate OVH data with logs from Polish mail providers and telecoms operators, and reconstruct the technical infrastructure of attacks based on netflow, panel logs and OSINT analysis. In urgent cases we launch the Budapest Convention preservation route within hours.

Prepared by: Waldemar Chodasiewicz Date prepared: 14 July 2026