compromised ecommerce website – urgent help needed
-
My website appears to be compromised and I’m not entirely sure how.
I need help, as quickly as possible.I have a self hosted ecommerce site using woocommerce, paypal and stripe for payments. A fair few orders have come in over the last 4-6 weeks, most likely due to Christmas, and I’ve been a bit overwhelmed with fulfilling orders that I skipped over looking at where payments were going to.
I noticed yesterday that an order came through with BACS as a payment method and as we do not accept BACS, decided to check the backend where Stripe was disabled, Paypal enabled but with another person’s email address in place of mine.
I’ve spoken to Paypal and they’re doing an investigation, but I also changed passwords and checked my user accounts to make sure there were no unauthorised admin.
Several hours later, I get a user registration email and see the account has used my admin username with a “2” at the end. I tried to login but my password had been deleted or changed, so I reset, went straight to the payments section and once again, stripe has been disabled, paypal is routed to another email address.
I’ve put the site on maintenance mode, logged that user out and deleted the account, changed my password and changed the login url for the backend, but I know that’s not enough.
So far, I’ve lost around £2.5k in sales money and I’m not hopeful Paypal will be able to recover it.
I need to know what I can do at this point to get my site safely back online and how this person managed to get in. My passwords are those randomly generated Google passwords, so nothing that should be easily solvable.
What can I do?
As a side note, I purchased an affiliate plugin several months ago and realised last month it wasn’t working. I contacted the developer and they asked for backend access to the site. Not wanting to give them access to everything, I installed a plugin and limited their access to various sections, however they insisted they needed access to restricted sections in order to check why it wasn’t working.
I created their login as a new Role type and didn’t give them admin rights or anything near, however they’re the only people who had privileges beyond customers and the timing between giving them access and no longer receiving payments through paypal is only off by 2 days.
- The topic ‘compromised ecommerce website – urgent help needed’ is closed to new replies.