Knowledgebase

Handling a Compromised Client Site Print

  • resellerbusinessbuilding, reseller, hacked, backup, spam, restore, malware, plugins, themes, woocommerce
  • 0

When one gets hacked.

IMMEDIATE PRIORITIES

Contain it, so other accounts are not affected Establish what happened Inform the client Clean it properly

CONTAINMENT

If the site is sending spam or serving malware, taking it offline temporarily is appropriate.

Tell the client before or immediately after, with the reason.

INFORMING THE CLIENT

Promptly and plainly. What happened, what you are doing, what they need to do.

Do not conceal it. They will find out, and concealment is worse than the compromise.

CLEANING

Restore a backup from before the infection, then update everything immediately.

Without a clean backup, replace core files and extensions with fresh copies and remove anything unaccounted for.

THE ENTRY POINT

Close it, or it recurs within days. Usually out-of-date software or nulled themes and plugins.

WHO PAYS

Depends on your agreement. If you were paid to maintain it and did not, that is yours.

If they declined maintenance, cleanup is chargeable. State that in your terms in advance.

AFTERWARDS

Review whether other client sites share the vulnerability.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot