Balgopal Commercial Limited Discloses Cybersecurity Incident at Third-Party Service Provider Under Regulation 30
Balgopal Commercial Limited disclosed a cybersecurity incident on 11 May 2026 at its third-party hosting and email service provider, caused by a critical zero-day vulnerability CVE-2026-41940 in cPanel/WHM, disclosed by cPanel on 30 April 2026. Despite the provider implementing security updates, a sophisticated cyberattack led to unauthorized access, deletion of database server data, and removal of historical backups, rendering certain data partially or entirely unrecoverable. The company clarified the incident did not affect its internal IT infrastructure, and as a precaution, its website has been taken offline while email communications remain disrupted. Balgopal Commercial is coordinating with the service provider on restoration efforts and has pledged to update the stock exchange on further material developments.

*this image is generated using AI for illustrative purposes only.
Balgopal Commercial Limited has filed a disclosure under Regulation 30 of the SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015, informing stock exchanges of a cybersecurity incident at a third-party service provider engaged by the company for hosting and managing its official email systems and website. The disclosure, signed by Company Secretary and Compliance Officer Ankit Ladha, is dated 11 May 2026.
Nature of the Cybersecurity Incident
The incident originates from a critical zero-day vulnerability, identified as CVE-2026-41940, affecting servers running the latest versions of cPanel/WHM. This vulnerability was disclosed by cPanel on 30 April 2026, with the advisory noting that it could potentially allow unauthorized access to hosting control panels, resulting in modification or deletion of user data. The company's third-party service provider, AapKaHost, communicated that despite immediately implementing the required security updates and mitigation measures upon receiving the advisory, its hosting infrastructure was subjected to a sophisticated cyberattack. The attacker gained unauthorized access and severely damaged user data and services, with multiple suspicious files identified on certain user accounts.
Impact on Data and Operations
The following table summarises the key details of the incident and its impact as disclosed by the company:
| Parameter: | Details |
|---|---|
| Disclosure Date: | 11 May 2026 |
| Vulnerability Identified: | CVE-2026-41940 |
| Vulnerability Disclosed By: | cPanel on 30 April 2026 |
| Systems Affected: | cPanel/WHM latest versions |
| Service Provider: | Third-party hosting and email management provider |
| Impact on Email: | Disruption of email communication services |
| Impact on Website: | Temporary unavailability; website taken offline |
| Data Status: | Database server data deleted; historical backups removed by attacker |
| Data Recovery: | Certain data may be partially recoverable or unrecoverable |
| Remediation Action: | Recoverable data migrated to a new server environment |
The attacker allegedly deleted the database server data as well as historical backup data from the compromised environment, thereby restricting restoration from backup sources. As the old server environment was deemed no longer secure or trustworthy, all remaining recoverable data has been migrated to a new server environment.
Company's Clarifications and Precautionary Measures
Balgopal Commercial has clarified that the incident occurred at the level of the external service provider and not within the company's internal IT infrastructure. The company is in continuous coordination with the service provider to assess the nature and extent of the incident, and the impact on the company's data and operations is currently being evaluated.
As precautionary measures, the company has:
- Temporarily taken its website offline
- Flagged that email communications may be disrupted or unreliable
- Advised stakeholders to exercise caution and verify any communication claiming to be from the company during this period
The service provider is currently undertaking restoration and remediation measures, including efforts to recover website content from alternative resources. The company has also stated it is reviewing additional safeguards to mitigate such risks going forward.
Regulatory Disclosure and Next Steps
The disclosure was made to BSE Limited in compliance with Regulation 30 of the SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015. A copy of the communication dated 11 May 2026 received from the third-party service provider has been enclosed as Annexure – A with the filing. Balgopal Commercial has committed to keeping the stock exchange informed of any further material developments in this regard.
Historical Stock Returns for Balgopal Commercial
| 1 Day | 5 Days | 1 Month | 6 Months | 1 Year | 5 Years |
|---|---|---|---|---|---|
| -8.71% | -9.30% | -4.80% | -27.78% | +28.44% | +4,778.69% |
How might SEBI respond to this incident by tightening third-party vendor cybersecurity compliance requirements for listed companies under Regulation 30?
Could the permanent loss of historical backup data expose Balgopal Commercial to regulatory penalties or legal liabilities from affected stakeholders?
What financial and reputational impact could prolonged website and email disruption have on Balgopal Commercial's business operations and investor confidence?

































