A compromised client account threatens your other clients, not just that one.
IMMEDIATE ACTIONS
- Suspend the account if it is actively sending spam or serving malware. Stop the harm first.
- Change all passwords on that account: cPanel, email, FTP, databases, and the site's admin logins.
- Check whether any other account shows similar signs.
- Open a ticket with us so we can check server-side and confirm the scope.
FINDING THE ENTRY POINT
Run ImunifyAV over the account. Sort files by last modified. Check for PHP files in uploads folders, unknown admin users, unfamiliar cron jobs, and mail queue activity.
Usually the cause is an out-of-date plugin, a nulled theme, or a reused password.
CLEANING
Restore from a clean backup and update everything, or replace core files, plugins and themes with fresh downloads and remove anything unaccounted for.
TELLING THE CLIENT
Be straightforward about what happened and what it will take. If the cause was software they installed or refused to update, say so plainly and in writing.
AFTERWARDS
Update, harden, rotate credentials, and monitor for a few weeks. A cleaned but unhardened account is compromised again within days.