Abuse Policy
This policy explains how Hyper ICT handles suspected abuse involving IPv4 resources and related network services, including reporting, investigation, customer response and protective actions.
abuse[at]hyper-ict[dot]com
If you identify suspected abuse involving an IP address associated with Hyper ICT or an IP resource managed through our services, please send us sufficient technical information to investigate.
1. Introduction
Hyper ICT Oy (“Hyper ICT”, “we”, “our”, or “us”) is committed to maintaining the security, integrity, and reputation of the IPv4 resources and network services provided through our infrastructure and partners.
This Abuse Policy explains:
- what types of activities we consider abusive or prohibited;
- how abuse involving our IP resources should be reported;
- how we review and handle abuse reports; and
- what actions we may take when abuse is identified.
This policy applies to all IPv4 resources and related network services provided or managed by Hyper ICT.
2. Reporting Abuse
If you identify suspected abuse originating from an IP address associated with Hyper ICT or an IP resource managed through our services, please report it to:
Please submit reports in English where reasonably possible.
To allow us to investigate efficiently, the report should contain sufficient technical information to identify the incident.
3. Information to Include in an Abuse Report
Where applicable, please include:
- IP address involved;
- date and time of the incident;
- timezone of the timestamp;
- type of abuse;
- relevant URL or domain name;
- source and destination information;
- relevant log entries;
- email headers for spam or phishing reports;
- screenshots or other supporting evidence where useful; and
- a brief description of the incident.
For network attacks, relevant logs, timestamps, ports, protocols, and other technical evidence should be provided where available.
Please do not send passwords, payment card information, unnecessary identity documents, or other sensitive personal information that is not required for the investigation.
4. Types of Abuse
Activities that may constitute abuse include, but are not limited to:
- Spam and unsolicited bulk email
- Phishing
- Credential harvesting
- Malware distribution
- Ransomware
- Botnet or command-and-control infrastructure
- Fraud and scams
- Hacking and unauthorized access
- Brute-force attacks
- DDoS and DoS attacks
- Reflection and amplification attacks
- Unauthorized vulnerability scanning
- Unauthorized mass scanning or reconnaissance
- IP spoofing used for malicious purposes
- Copyright or intellectual property infringement
- Distribution of stolen or unlawfully obtained data
- Unauthorized BGP announcements
- Route hijacking
- Other unlawful or malicious use of network resources
Additional restrictions are described in our Terms and Conditions.
5. Review of Abuse Reports
Hyper ICT reviews abuse reports based on the information and evidence available.
Where appropriate, we may:
- verify that the reported IP resource is associated with our services;
- review technical information relating to the incident;
- compare the report with other abuse or security information;
- request additional evidence from the reporter;
- notify the responsible customer;
- request investigation and mitigation from the customer; or
- take technical protective action.
Receiving an abuse report does not automatically establish that a violation has occurred.
Reports may be evaluated for credibility, technical relevance, supporting evidence, severity, and potential impact.
6. Customer Notification and Response
Where appropriate, credible abuse reports may be forwarded or communicated to the customer responsible for the affected IP resource.
Unless a shorter response time is reasonably necessary due to the seriousness of the incident, customers are expected to respond to an abuse notification from Hyper ICT within 24 hours.
The customer may be required to:
- investigate the incident;
- stop confirmed abusive activity;
- remove malicious or unlawful content;
- secure compromised systems;
- block or terminate responsible users;
- provide evidence of mitigation; and
- explain the corrective measures taken.
A response from the customer does not by itself mean that an abuse case has been resolved. Hyper ICT may require additional mitigation where reasonably necessary.
7. Urgent and Serious Abuse
Certain incidents may require immediate action.
Examples may include:
- active phishing;
- malware distribution;
- botnet or command-and-control activity;
- active network attacks;
- significant fraud;
- serious security threats;
- unauthorized BGP announcements;
- route hijacking;
- continued malicious activity;
- activity creating an immediate material risk to third parties or IP resource reputation.
In such circumstances, Hyper ICT is not required to wait for the standard customer response period before taking protective action.
8. Protective Actions
Depending on the nature, credibility, severity, and urgency of an incident, Hyper ICT may take one or more protective actions, including:
- requesting immediate mitigation;
- temporarily suspending affected IP resources;
- withdrawing routing support;
- removing or modifying route objects;
- modifying or revoking RPKI/ROA authorizations;
- setting an applicable ROA authorization to AS0 where appropriate;
- modifying relevant registry information;
- restricting the affected service; or
- terminating the service.
The action taken will depend on the circumstances and the level of risk involved.
Where immediate intervention is reasonably necessary to protect network integrity, third parties, IP resource reputation, or legal compliance, Hyper ICT may take technical action without prior notice.
9. Spam and Email Abuse
Hyper ICT does not permit its IPv4 resources to be used for spam or unauthorized bulk email activity.
Reports relating to email abuse should preferably include:
- the sending IP address;
- complete email headers;
- date and time;
- relevant message identifiers; and
- sufficient evidence to identify the reported activity.
Customers are expected to maintain appropriate email security, authentication, consent, and abuse-handling practices where email use has been approved.
Repeated spam complaints or significant email reputation problems may result in restrictions or suspension.
10. Phishing and Malware
Reports involving phishing, malware, credential theft, ransomware, botnets, or similar malicious infrastructure are treated as high-priority security matters.
Please include the relevant IP address, URL or domain, timestamp, and supporting technical evidence where available.
Hyper ICT may take immediate protective action where credible evidence indicates that an IP resource is actively being used for serious malicious activity.
11. Network Attacks
Reports concerning DDoS, DoS, brute-force attacks, exploitation attempts, scanning, or other network attacks should contain sufficient technical evidence to support investigation.
Where available, please include:
- source IP address;
- destination information;
- timestamps and timezone;
- source and destination ports;
- protocol;
- relevant firewall or server logs; and
- a description of the observed activity.
Hyper ICT may take immediate action where ongoing malicious traffic creates a significant security or operational risk.
12. Copyright and Intellectual Property Reports
Copyright or intellectual property complaints should clearly identify:
- the relevant IP address;
- the allegedly infringing material;
- the location of the material, where applicable;
- the rights involved;
- sufficient information to evaluate the complaint; and
- contact information for the complainant or authorized representative.
Hyper ICT may forward relevant complaints to the responsible customer for investigation and appropriate action.
Hyper ICT does not automatically determine ownership of disputed intellectual property solely on the basis of receiving a complaint.
13. Blacklists and Reputation Services
Hyper ICT monitors or receives information from security, anti-spam, abuse, threat intelligence, and reputation services.
A blacklist or reputation listing does not automatically establish abuse or automatically require termination of a customer.
However, Hyper ICT may investigate listings and related evidence to determine whether they indicate:
- spam;
- malware;
- phishing;
- compromised infrastructure;
- malicious network activity;
- repeated abuse; or
- other material risk to the affected IP resources.
Where a listing or related activity presents a significant risk, Hyper ICT may require mitigation or take protective action.
14. Repeated Abuse
Repeated abuse involving the same customer, service, network, or pattern of activity may result in stronger enforcement action.
This may apply even where individual incidents have previously been resolved.
Hyper ICT may consider factors including:
- frequency of complaints;
- severity of incidents;
- responsiveness of the customer;
- effectiveness of mitigation;
- recurrence of similar activity;
- blacklist history; and
- overall risk to IP resources and third parties.
Repeated or persistent abuse may result in permanent termination of the affected service or refusal of future service.
15. False, Misleading, or Abusive Reports
Hyper ICT takes legitimate abuse reports seriously.
However, abuse reporting mechanisms must not be used to:
- knowingly submit false allegations;
- harass customers or third parties;
- submit fabricated evidence;
- impersonate another person or organization;
- interfere improperly with legitimate services; or
- repeatedly submit irrelevant or unsupported complaints.
We may disregard reports that are clearly fraudulent, malicious, irrelevant, or lack sufficient information to permit a reasonable investigation.
16. Cooperation with Third Parties
Where appropriate and legally permitted, Hyper ICT may cooperate with:
- customers;
- upstream providers;
- LIRs;
- Regional Internet Registries;
- network operators;
- CERTs and CSIRTs;
- security organizations;
- abuse-handling organizations;
- reputation and threat intelligence services;
- rights holders or their authorized representatives; and
- competent law enforcement or regulatory authorities.
Information is shared only where reasonably necessary and in accordance with applicable law and our Privacy Policy.
17. Law Enforcement Requests
Requests from law enforcement or other competent authorities should be submitted through appropriate official channels and contain sufficient information to identify the relevant matter.
Hyper ICT will review such requests in accordance with applicable Finnish and European Union law.
Nothing in this Abuse Policy requires Hyper ICT to disclose information where disclosure is not legally permitted or appropriately authorized.
18. Privacy and Abuse Data
Abuse reports may contain personal data, IP addresses, technical identifiers, communication information, or other information relating to individuals or organizations.
Such information is processed for purposes including:
- investigating abuse;
- protecting network and IP resources;
- preventing security incidents;
- communicating with responsible customers;
- establishing or defending legal claims; and
- complying with applicable legal obligations.
Personal data associated with abuse handling is processed in accordance with our Privacy Policy and applicable data protection law.
19. No Guarantee of Immediate Resolution
Hyper ICT aims to review credible abuse reports appropriately, but we cannot guarantee a specific resolution time for every report.
The time required may depend on:
- severity of the incident;
- quality of the evidence;
- customer response;
- technical investigation requirements;
- involvement of third parties; and
- applicable legal requirements.
Serious and active security threats may be prioritized over lower-risk reports.
20. Relationship with Terms and Conditions
This Abuse Policy forms part of the rules governing the use of Hyper ICT services and should be read together with our Terms and Conditions and Privacy Policy.
Where a customer violates the Terms and Conditions, Hyper ICT may exercise the suspension, termination, routing, RPKI/ROA, or other rights provided under those Terms.
21. Changes to This Policy
Hyper ICT may update this Abuse Policy from time to time to reflect changes in our services, security practices, legal requirements, or abuse-handling procedures.
The current version will be published on our website with an updated revision date.
22. Contact
Business ID: 3394765-5
VAT: FI-33947655
Merituulentie 38 A, Floor 6
02200 Espoo
Finland
Need to report suspected abuse?
Send the affected IP address, timestamp, timezone and relevant technical evidence to our abuse team.