Fall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowFall ResetAmazon USWork and home upgrades are worth comparing todayAmazon US: today's deals, useful picks and quick comparisons.See Picks×
Skip to content
Blog

After Social-Engineering Hack, Judge Says “Very Poor” Contract May Not Shield Hosting Company

By TheFinanceBase Team7 min read

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

A federal judge allowed a lawsuit against hosting provider 100TB.com to continue after questioning whether a “very poorly drafted” contract could limit the company’s exposure to roughly one month of hosting fees. But the February 2, 2017 ruling was not a finding that 100TB was liable, nor did it award Xat.com damages.

The decision in Xat.com Limited v. Hosting Services, Inc. rejected some claims and allowed others to proceed. Its practical lesson for businesses is narrower and more useful: liability language must match the security responsibilities a provider actually controls, especially account recovery, multifactor authentication and incident response.

What happened in the Xat.com–100TB case?

Xat.com Limited, described in the court’s order as a social-networking and instant-messaging company, sued Hosting Services, Inc., doing business as 100TB.com, in the U.S. District Court for the District of Utah. The case was 1:16-cv-00092-PMW, before Chief United States Magistrate Judge Paul M. Warner.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

According to Xat’s complaint, an unidentified attacker used social engineering to persuade 100TB to make sensitive changes to Xat’s hosting account. Xat alleged that the attacker:

  • Added an unauthorized email address to the account;
  • Disabled two-factor authentication;
  • Obtained control of Xat’s servers;
  • Accessed the systems again after Xat allegedly asked 100TB to secure or shut them down; and
  • Damaged or took software, databases, source code and other data while erasing logs.

Xat alleged that the first incident occurred on November 4, 2015, followed by another unauthorized-access event on November 8. It also alleged that it had warned 100TB repeatedly about social-engineering attempts during the preceding months.

The allegations included server damage, stolen or corrupted data, investigation and containment costs, lost revenue and profits, and possible regulatory or third-party exposure. Xat claimed at least $500,000 in damages. Those were allegations in the complaint, not losses established by the court.

The court’s description of the allegations appears in the memorandum decision and order.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What did the hosting contract promise?

Xat and 100TB signed a Master Service Agreement in 2008. As described in the order, the agreement addressed hosting and server stability, physical and digital security, and the use of “industry standard methods” to secure Xat’s property. It also described monitoring of the network, physical infrastructure, servers and applications on a 24×7×365 basis.

The agreement contained indemnification language concerning certain third-party claims arising from 100TB’s gross negligence or willful misconduct. At the same time, it broadly excluded liability for categories including:

  • Lost profits, revenue and business;
  • Loss, interruption or corruption of data;
  • Consequential, indirect, incidental, special and reliance damages; and
  • Exemplary and punitive damages.

Another provision stated that 100TB’s “maximum liability” would be the fees received during the month before the claim. 100TB argued that this limited Xat’s potential recovery to $2,715.95, the reported amount of one month’s fees, and reportedly placed that sum in the court registry.

Why the judge questioned the liability cap

Judge Warner described the Master Service Agreement as “very poorly drafted” and, at minimum, ambiguous. The problem was not simply that the proposed cap was small. The court focused on how the cap interacted with the rest of the agreement.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The provision repeatedly used broad “liability” language without clearly explaining whether it was:

  • Excluding particular types of damages;
  • Capping otherwise recoverable damages; or
  • Attempting to eliminate nearly all liability regardless of the provider’s conduct.

The one-month amount was also extremely small compared with the alleged harm. The court reasoned that the cap might operate as “window dressing” for eliminating liability altogether if it allowed a provider to engage in grossly negligent or willful conduct while facing only nominal financial exposure.

That does not mean every low liability cap is invalid. Nor did the court permanently strike down every limitation in the contract. It declined to enforce the one-month-fee limitation at the motion-to-dismiss stage because the language was ambiguous and its enforceability could not be resolved solely from the pleadings.

What the February 2, 2017 order actually decided

The ruling was a partial result:

Claim or issue Result What that meant
Gross negligence as a tort claim Dismissed The court applied the economic-loss rule because the parties’ relationship was governed by contract.
Unjust enrichment Dismissed The contract governed the relationship, so an unjust-enrichment theory was not appropriate on the pleaded facts.
Breach of contract Survived Xat could continue pursuing contractual relief.
Contractual recovery based on alleged grossly negligent conduct Not foreclosed Dismissal of the tort theory did not necessarily eliminate a contract-based theory involving the same conduct.
Equitable indemnification or contribution Survived Those issues remained legally live at the pleading stage.
One-month-fee liability cap Not enforced at this stage The court did not finally declare the cap invalid; it found the issue too ambiguous to resolve on a motion to dismiss.

A motion to dismiss tests whether the complaint states a legally sufficient claim. It does not determine that the alleged events occurred, that the defendant breached the agreement or that the plaintiff will recover damages.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why the decision matters for hosting and cloud contracts

The case illustrates a recurring technology-contract problem: the provider may control the operational action that creates or worsens the risk, while the contract attempts to limit recovery to an amount unrelated to that risk.

Social engineering is not necessarily only a customer-side failure. If a provider’s support staff can add an administrator, reset credentials or disable multifactor authentication, the provider’s identity-verification process becomes part of the security boundary. A contract that promises security and continuous monitoring may be read alongside those operational practices.

The same issue arises when a provider advertises multifactor authentication but permits support personnel to disable it after a weak verification process. MFA can reduce account-takeover risk, but it does not protect an account if its recovery and reset procedures are easily manipulated.

Likewise, backups are not automatically a solution. They may be useless if they were never completed, were overwritten, used the same compromised credentials as production, omitted the affected database or source code, or were never tested through restoration.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Contract questions for businesses buying hosting

Before signing or renewing a hosting, cloud or managed-services agreement, ask precise questions rather than relying on a general promise to use “industry standard” security:

Best Value
Sale
Cyber Security Awareness Month Cybersecurity Fun Nerdy T-Shirt
  • This fun, nerdy, geeky, retro Cybersecurity Awareness Month design is perfect to wear this October. Great for cyber security professionals and experts who keep people safe on the internet, safe online, and safe online.
  • Wear this for October National Cyber Security Awareness Month this October, raise awareness about cyber security on smartphones, laptops at your school, in the classroom or on your college or university campus. Be safe online and make sure others are too!
  • Lightweight, Classic fit, Double-needle sleeve and bottom hem
  • Account changes: Who may add an email address, reset credentials, change an administrator or grant console access?
  • MFA controls: What verification is required before MFA is reset or disabled? Must the provider notify the customer first?
  • Authorized contacts: Are changes limited to named contacts, and can those records be independently verified?
  • Emergency response: Can the provider suspend access or isolate systems quickly, and what notice must it give?
  • Logs and evidence: Must the provider preserve access logs, support records and forensic evidence after an incident?
  • Backups: How often are backups made, how long are they retained, are they isolated from production credentials and is restoration tested?
  • Incident notification: How quickly must the provider report suspected unauthorized access?
  • Financial exposure: Are data-security incidents subject to the ordinary cap, a higher incident-specific “supercap” or no cap for specified misconduct?
  • Indemnity: Does it cover third-party claims, investigation costs or regulatory-notification expenses?
  • Exit rights: Can the customer retrieve data and obtain reasonable recovery assistance after an incident or termination?

“Industry standard” is also fact-sensitive. It does not identify one fixed set of controls. Its meaning may depend on the service, threat environment, practices at the time, prior warnings, the provider’s representations and whether the customer purchased managed security.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Contract design lessons for hosting providers

For providers, the case highlights the danger of combining broad security promises with a nominal liability cap and unclear exclusions. A more durable agreement should clearly separate:

  • Excluded categories of damages;
  • The general liability cap;
  • Any higher cap for security incidents or confidentiality breaches;
  • Responsibility for the provider’s personnel and support-mediated access changes;
  • Customer duties, such as maintaining authorized-contact records and securing its own credentials; and
  • Carve-outs for gross negligence, willful misconduct or other conduct that applicable law does not permit a contract to shield.

The commercial trade-off is straightforward. A very low cap may reduce the provider’s exposure and help contain prices, but it can leave a customer with little practical recovery after a catastrophic incident. A higher cap, incident-specific supercap or cyber-insurance requirement may cost more while better aligning the provider’s financial responsibility with the risks it controls.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What this ruling did not establish

The order did not establish that:

  • 100TB was liable for the alleged breach;
  • Xat won $500,000 or any other damages;
  • The contract was definitively unenforceable;
  • All hosting-company liability waivers are invalid;
  • A provider is automatically responsible whenever social engineering is involved;
  • Federal courts nationwide must apply the same rule; or
  • The court found as a final fact that 100TB disabled Xat’s security controls.

The decision was a federal trial-level ruling on a motion to dismiss. The available record for this article confirms the February 2, 2017 order, but does not establish the lawsuit’s ultimate disposition. Later discovery, settlement, a different ruling on the cap or a trial judgment could have changed the outcome.

The financial takeaway

For a business, the headline risk in a hosting agreement is not just the monthly bill. A provider-controlled account takeover can create recovery costs, downtime, data-loss claims, investigation expenses and possible obligations to customers or regulators. A contract that promises security but caps recovery at a nominal amount may leave the customer carrying nearly all of that risk.

The Xat decision therefore offers a precise warning rather than a blanket rule: a liability limitation is more likely to protect a provider when it is clear, internally consistent and tied to the security responsibilities the provider actually undertakes. When broad operational promises, provider-controlled access and an extremely low cap point in different directions, the contract may become a source of litigation instead of a reliable shield.

Quick Recap

SaleBestseller No. 2
SaleBestseller No. 4
SaleBestseller No. 5
Cyber Security Awareness Month Cybersecurity Fun Nerdy T-Shirt
Cyber Security Awareness Month Cybersecurity Fun Nerdy T-Shirt
Lightweight, Classic fit, Double-needle sleeve and bottom hem
$15.29

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.