After sending cease-and-desist letters to VMware users whose support contracts had expired and who subsequently declined to subscribe to one of Broadcom’s VMware bundles, Broadcom has started the process of conducting audits on former VMware customers. Broadcom stopped selling VMware perpetual licenses in November 2023 in favor of pushing a small number of VMware SKUs that feature multiple VMware offerings. Since Broadcom is forcefully bundling VMware products, the costs associated with running VMware have skyrocketed, with customers frequently citing 300 percent price hikes and some firms claiming even larger increases. As a result, some VMware users have opted to keep using VMware perpetual licenses, even though Broadcom refuses to renew most of those clients’ support services. This year, Broadcom started sending such VMware users cease-and-desist letters [PDF], telling organizations to stop using any maintenance releases/updates, minor releases, major releases/upgrades extensions, enhancements, patches, bug fixes, or security patches (except for zero-day security patches) that VMware issued since the user’s support contract ended. The letters also warned of potential audits, which appear to be underway now. Broadcom starts auditing Ars Technica reviewed a letter that a software provider and VMware user in the Netherlands received that is dated June 20 and informs the firm that it “has been selected for a formal audit of its use of VMware software and support services” [PDF]. The security professional who provided Ars with the letter asked to keep their name and their employers’ name anonymous out of privacy concerns. The anonymous employee told Ars that their company had been a VMware customer for “about” a decade before deciding not to sign up for a new contract with Broadcom’s VMware a year ago. The company had been using VMware Cloud Foundation and vSphere. “Our CEO decided to not extend the support contract because of the costs,” the employee said. “This already impacts us security-wise because we can no longer get updates (unless the CVSS score is critical).” The letter notes that an auditing firm, Connor Consulting, which is headquartered in San Francisco and has offices around the globe, will perform a review of the company’s “VMware deployment and entitlements, which may include fieldwork or remote testing and meetings with members of your accounting, licensing, and management information systems functions.” The letter informs its recipient that someone from Connor will reach out and that the VMware user should respond within three business days.