Our website got hacked!

CYBERS 22.02.2021

“We got hacked” – is a sentence that a cyber security provider should not ever say to stay in business… but here is our story! And no need to panic it was our WordPress site hosted by a third party. Our services and customer data are safe and sound, we don’t have any kind of impact to our customers or company data. As a cyber security company sharing our experience about all type of attacks with our community helps to avoid the same situations in other companies.

What happened?

We noticed on February 8th that something seems wrong with our homepage. When you would have tried to visit our page, you would have been redirected to different addresses chosen by our webpage attacker. Our incident response team confirmed the fact promptly and got into action. The culprit was a vulnerability that hit the news at the 6th of February, in one of the plugin named –Ultimate GDPR & CCPA Compliance Toolkit for WordPress which CYBERS used. The exploitation allowed an unauthenticated user to change the settings of the plugin and redirect traffic to an external website. It took us 35 minutes to identify the problem and return the site operation back to normal. 

What issues did it bring us?

First, it is still an unnecessary hassle. Investigations started together with our partners and manhours spent for post-analysis report, notifications to our CERT-EE as regulations demand. All these activities are necessary, but my point is that it is easier to protect better to avoid the impact. 

Hence this is what we learned: 
  • Our regular patching and scanning of vulnerabilities using general tools were OK, but not enough to cover niche plugin-related vulnerabilities. 
  • Monitoring of website needed improvements.
  • Additional protection tools needed to be implemented. 
Let’s not this go to waste!

It is always better to learn from others’ mistakes. WordPress security is a topic of huge importance for every website owner. Google blacklists around 10,000+ websites every day for malware and around 50,000 for phishing every week. If you are a business owner and are worried about how is your WP homepage protected check out the list below. These WordPress security tips help you to protect your website against hackers and malware: 

  • Add Security Questions to WordPress Login Screen 
  • Add Two Factor Authentication 
  • Automatically log out Idle Users in WordPress 
  • Install a WordPress Security Plugin 
  • Change the Default “admin” username 
  • Change WordPress Database Prefix 
  • Disable Directory Indexing and Browsing 
  • Disable File Editing 
  • Disable PHP File Execution in Certain WordPress Directories 
  • Disable XML-RPC in WordPress 
  • Enable Web Application Firewall (WAF) 
  • Install a WordPress Backup Solution 
  • Limit Login Attempts 
  • Move WordPress Site to SSL/HTTPS 
  • Password Protect WordPress Admin Page 
  • Scanning WordPress for Malware and Vulnerabilities 

 

If you need help with WordPress security do not hesitate to contact us and let us check together what is the status of your business main gateway!  

Share

Share

Latest blog posts

31.07.2025

Cyber turbulence: why airlines must take cybersecurity as seriously as air safety

The aviation industry is facing an escalating wave of cyber threats that go far beyond flight delays or data leaks. Airlines are now prime targets in modern cyber warfare—critical infrastructure vulnerable to sabotage, espionage, and geopolitical disruption. The July 2025 cyberattack on Aeroflot, which destroyed 7,000 servers and halted dozens of flights, is a stark warning of what’s to come. As digital systems control everything from aircraft operations to passenger data, this article explores why the skies are no longer safe from cyber conflict—and what the industry must do to defend itself.

Keep reading
23.07.2025

Building confidence, not just compliance: how Axinom validated their web application security

In high-trust industries, security is more than a checkbox—it’s a competitive advantage. Learn how Axinom validated the resilience of their DRM platform with NEVERHACK’s Offensive Security team, using deep manual testing to uncover what automation misses. A case study in turning compliance into confidence.

Keep reading
21.01.2025

Cybersecurity in 2025: Challenges and Strategies

Cybersecurity has become a crucial part of business strategy, determining organizations’ ability to protect their digital assets and continue operations during crises. The economic impact of cyberattacks is estimated to reach 1.5% of the global GDP, making 2025 a year of significant challenges and the need for continuous development in defense strategies. This is especially […]

Keep reading