Work / Shared hosting account · 2026

Hosting incident: 7 WordPress sites restored in one day

An admin account with a weak password on a shared hosting account I managed was compromised. I noticed when the server stopped responding, contained it and restored all 7 affected WordPress sites within a day, then hardened them to make a repeat much harder.

Role
Solo: detection, recovery and hardening
Date
09/2026
Stack
Tools: Login-attempt limits, Read-only core and plugin files, Hidden login URL
Result
7 sites restored within one day
Status
Private · details on request

Detection

The server stopped responding, which led me to the compromise.

Containment and recovery

I stopped the damage the same day and restored all 7 affected sites to working order.

Root cause

A weak password on an admin account. That was my responsibility.

Fixes and prevention

  • Limited login attempts.
  • Made core and plugin files read-only, so nothing can be changed from the dashboard.
  • Moved the dashboard login to a non-default URL.

View CV · Email me