How do websites get hacked?

Most attacks are not aimed at a particular company, but at a known vulner­a­bility. If you know the ways in, you can close most of them.

  • Ways inWhich ways in are used almost every time
  • Warning signsHow to spot an attack before your customers do
  • Emergency planHow an emergency is handled and which preven­tion works
Your website can be closed
most common
Outdated plugin The update was out, but it was never installed
common
Weak password Reused, or simply guessed by brute force
common
Access details in old emails One stranger in a mailbox is enough
again and again
Theme of unknown origin Pirated copy, often with malware
The host itselfA flaw in the server, not in your website rare

How a known vulnerability turns into an attack

Two websites with the same vulner­a­bility. Only one of them gets the update from June 2.

Update installed Website 1
  • Update released, flaw describedMon, Jun 2
  • Update installedMon, Jun 2
  • Scan finds no old versionWed, Jun 4
The sequence ends here. The website simply keeps running.
Update not installed Website 2
  • Update released, flaw describedMon, Jun 2
  • Update left waitingMon, Jun 2
  • Scan finds the old versionWed, Jun 4
  • Malware plantedThu, Jun 5
  • Unknown admin, hidden spam pagesThu, Jun 5
  • Browser warning, a customer asksTue, Jul 1

Brute force on passwords

Using lists from other sites' data leaks. A password that is also used elsewhere falls first.

Access details in old emails

They sit for years with both sender and recip­ient. Whoever opens either mailbox has the website.

Pirated and deactivated plugins

Pirated premium versions often come with malware. Deactivated plugins remain open to attack.

How to recognize an attack

An attack is usually meant to go unno­ticed. Still, it shows in these four places.

A red warning in the browser before your website appears

Strange terms or languages in search results for your company

An admin user that nobody created

Unknown links or redirects to someone else's offers

Three cases from practice where access became the problem

Passwords in emails

Sent in plain text for years.

Since then: one-time links only.

Forgotten admin account

Active for months after a change of provider.

Since then: a checklist, review after 30 days.

Locked out by acci­dent

Login protection blocks after failed attempts.

Most common support case: quickly solved.

Handling an emergency

If the site is only cleaned and the way in stays open, the malware comes back. That is why there is a fixed order.

Cleaning only
Remove malware
Website back online
Way in still open
Infected again

The cycle starts over.

Fixed order
Isolate and back up
Scan and clean
Close the way in
Release, lift the warning

The incident is closed.

  1. 1Isolate
  2. 2Back up current state
  3. 3Scan
  4. 4Change passwords
  5. 5Clean
  6. 6Close the way in

How we protect websites against attacks

Updates, good passwords and a protected login area prevent most inci­dents. Every way in has a fixed coun­ter­mea­sure.

  • Outdated plugin Security updates first, tested on staging
  • Deactivated plugin Delete unused plugins, not just deac­ti­vate
  • Weak password Strong passwords, limited attempts, two‑factor where suit­able
  • Access details in emails Shared only by one-time link or through the customer area
  • Malware from unknown sources Regular malware scans
  • Forgotten access Remove old access at handover
  • Website outage 24‑hour uptime moni­toring
If something does happen, backups are kept in five places, going back three months.

Ready for dependable care?

Book a call
30 minutes by phone or video. You pick an open slot in the calendar.
Send a message
Briefly describe what you need. You will get a reply within 24 hours on working days.