How Small Business Websites Get Hacked, and What Actually Prevents It
We looked at how 14 hacked local business websites were set up. An out-of-date WordPress was rarely the common thread. Here are the likelier ways in, and the habits that close them.
When we tell a business owner their website has been hacked, the first question is always the same: how? The honest answer is that nobody can say for certain from the outside. The server's logs record how someone got in, and only the owner or their web host can see those.
What we can do is look at what the hacked sites have in common. In our look at 14 hacked local business websites, a few patterns stood out, and some of them aren't what people expect.
What the hacked sites had in common
It wasn't only WordPress. Eleven of the 14 sites run on WordPress, but three don't use WordPress at all, and they were changed just the same. To edit those, someone needed access to the hosting account or to the files themselves.
Most were running a recent version of WordPress. Of the 11 WordPress sites, 10 were on a recent version. Only one was years behind, on a version released in 2018. An out-of-date WordPress makes an attacker's job easier, but in this group it wasn't the common thread. A site can also be broken into while it's out of date and updated later, and updating doesn't remove whatever was left behind.
Some of the spam was posted from real accounts. On two sites, the gambling articles were published under genuine logins: one under the main administrator account, and one under a named account that appears to belong to someone at the business. On another, they came from an account with an unfamiliar name, and creating a new account takes administrator access. That points to someone logging in, not slipping through a software bug.
Old add-ons were still installed. One site was running a slider plugin several years out of date. Plugins that come bundled with a premium theme often can't update themselves, so they quietly fall behind.
The likely ways in
From what we saw, and from how small business sites are commonly broken into, these are the doors worth closing.
Passwords that leaked or were reused
If anyone who logs into your website uses the same password somewhere else, a breach at that other service can hand it to attackers, who try leaked passwords against websites automatically. Passwords also leak from computers infected with malware that collects saved browser passwords. Without two-factor authentication, a correct password is all it takes.
Plugins and themes that fell behind
WordPress itself updates automatically on most hosts, but plugins and themes often don't, and premium ones bundled with a theme usually need a licence to update. Abandoned plugins never get fixed at all. Most of the security holes reported in WordPress sites each year are in plugins and themes rather than WordPress itself.
Access to the hosting and the files
The three sites without WordPress show that the files themselves were reachable. That can mean a hosting control panel or FTP login that leaked, an old developer's account that was never removed, or another neglected site on the same hosting account that let someone in next door.
Websites nobody is looking after
Behind all of this is usually a site that was built years ago and then left alone. The designer has moved on, nobody logs in, nothing gets updated, and nobody would notice a change. Attackers count on that.
What actually prevents it
None of this needs expensive tools. It needs someone to own it.
- Unique passwords and two-factor authentication on the website login, the hosting account, the domain registrar and the email accounts behind them.
- Fewer accounts. Remove former staff and old developers. Every login is a door.
- Update plugins and themes, not just WordPress. Delete anything you don't use, and if a premium plugin can't update, find out why.
- Backups kept somewhere other than the website's own server, so you can go back to a clean copy.
- Someone responsible. Whether it's you, a staff member or your web provider, someone should log in regularly and notice when something changes.
- Google Search Console, which can email you if Google finds a security problem on your site.
If your site has already been hacked
Cleaning up properly takes more than deleting the spam. Change every password involved, including the website, hosting, FTP, database and email. Remove accounts you don't recognize. Replace WordPress and its plugins with fresh copies, or restore a backup from before the break-in, then update everything. Once the site is clean, you can ask Google to review it through Search Console so any warning comes off.
Skip the step of finding how they got in, and the spam usually comes back.
Keep reading
All articlesWe Found 14 Hacked Local Business Websites. Here's What Was Hidden on Them
While reviewing Ontario business websites, we came across 14 that had been quietly filled with hidden gambling links and pages. What was added, why owners rarely notice, and how to check your own site in a few minutes.
Read articleThe Network Security Gaps Most Small Businesses Don't Realise They Have
Most small business networks share the same firewall and segmentation gaps. Here are the ones we find most often, and how to close them before they cost you.
Read articleWhat a NIST Cybersecurity Risk Assessment Actually Involves
A plain-language walk through what a NIST cybersecurity risk assessment looks at, what you receive at the end, and why any small business benefits.
Read articleLet's build something great.
On-site assessments are free for new business projects. We'll come to you, evaluate your needs, and provide a clear, no-obligation quote.