Knowledgebase

Unusual activity or login from a new location Print

  • password, hacked, twofactor, cron, email, domain, filemanager, security, malware
  • 0

A security notification.

WHAT TO DO IMMEDIATELY

If it was not you, change the password for that account now.

Enable two-factor authentication if it is not already active.

Check for changes: new administrator users, altered settings, unfamiliar files, new cron jobs.

IF IT WAS YOU

Confirm the location and device make sense. Mobile networks frequently show unexpected locations, which is normal.

CHECKING FOR DAMAGE

Review the user list in your application. Any administrator you do not recognise is a compromise.

Check recently modified files in File Manager, sorted by date.

Check cron jobs for entries you did not add.

Run a malware scan.

IF YOU FIND ANYTHING

Treat it as a full compromise: change every credential, clean thoroughly, close the entry point.

PREVENTING IT

Two-factor authentication on hosting, application administrators, email and your domain registrar.

Unique passwords everywhere. A password reused from a breached service is the most common route in.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot