When a customer has been hacked.
WHAT THE SIGNS ARE
Spam sent from their account Unfamiliar files on their site Their site serving unexpected content Complaints from third parties Sudden resource use
WHAT TO DO FIRST
Contain it: suspend sending, or take the site offline if it is serving harm.
WHY CONTAINMENT FIRST
Ongoing harm affects others and your reputation.
WHAT TO TELL THE CUSTOMER
What you found What you did What they need to do
WHAT TO AVOID
Blaming them.
WHY
They already feel foolish, and it achieves nothing.
WHAT TO PRESERVE
Evidence, before cleaning.
WHAT THE COMMON CAUSES ARE
Outdated software Weak or reused passwords A compromised local machine A vulnerable plugin or theme
WHAT TO ESTABLISH
Which, so it does not recur.
WHY THAT MATTERS MOST
Cleaning without finding the route means it returns within days.
WHAT TO RECOMMEND
Changing every credential Updating everything Restoring from a known-good backup
WHY RESTORING IS SAFER THAN CLEANING
You rarely know everything that was changed.
WHAT TO CHECK BEFORE RESTORING
That the backup predates the compromise.
WHAT TO OFFER
Help, and paid cleanup if you provide it.
WHAT TO DOCUMENT
The incident, and what was found.