Work / Shared hosting account · 2026
Hosting incident: 7 WordPress sites restored in one day
An admin account with a weak password on a shared hosting account I managed was compromised. I noticed when the server stopped responding, contained it and restored all 7 affected WordPress sites within a day, then hardened them to make a repeat much harder.
- Role
- Solo: detection, recovery and hardening
- Date
- 09/2026
- Stack
- Tools: Login-attempt limits, Read-only core and plugin files, Hidden login URL
- Result
- 7 sites restored within one day
- Status
- Private · details on request
Detection
The server stopped responding, which led me to the compromise.
Containment and recovery
I stopped the damage the same day and restored all 7 affected sites to working order.
Root cause
A weak password on an admin account. That was my responsibility.
Fixes and prevention
- Limited login attempts.
- Made core and plugin files read-only, so nothing can be changed from the dashboard.
- Moved the dashboard login to a non-default URL.