{"id":9065,"date":"2022-12-10T00:11:21","date_gmt":"2022-12-09T22:11:21","guid":{"rendered":"https:\/\/weaverbird.co.za\/?p=9065"},"modified":"2025-05-19T06:23:52","modified_gmt":"2025-05-19T04:23:52","slug":"why-and-how-websites-get-hacked","status":"publish","type":"post","link":"https:\/\/weaverbird.co.za\/en-au\/why-and-how-websites-get-hacked\/","title":{"rendered":"Why do websites get hacked?"},"content":{"rendered":"\r\n<p class=\"wp-block-paragraph\">So your site has been hacked and you&#8217;re probably wondering\u2026<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>Why?<br \/>HOW\u2026<br \/>And WHO?!<\/strong><\/p><div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<span class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/span>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #000000;color:#000000\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #000000;color:#000000\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/weaverbird.co.za\/en-au\/why-and-how-websites-get-hacked\/#Why_did_your_website_get_hacked_with_Malware\" >Why did your website get hacked with Malware?<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/weaverbird.co.za\/en-au\/why-and-how-websites-get-hacked\/#So_why_was_your_website_targeted_specifically\" >So why was your website targeted specifically?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/weaverbird.co.za\/en-au\/why-and-how-websites-get-hacked\/#Once_malware_Malware_gets_into_your_site_is_its_data_and_customer_info_compromised\" >Once malware Malware gets into your site, is its data and customer info compromised?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/weaverbird.co.za\/en-au\/why-and-how-websites-get-hacked\/#How_can_I_prevent_this_from_happening_or_from_reoccurring\" >How can I prevent this from happening or from reoccurring?<\/a><\/li><\/ul><\/li><\/ul><\/nav><\/div>\n\r\n\r\n\r\n\r\n<p><iframe loading=\"lazy\" class=\"giphy-embed\" src=\"https:\/\/giphy.com\/embed\/eIPM3j6YXHKXC\" width=\"480\" height=\"352\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/p>\r\n\r\n\r\n\r\n<div class=\"wp-block-spacer\" style=\"height: 30px;\" aria-hidden=\"true\">\u00a0<\/div>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">What do they want?<br \/>Is my info safe\u2026<br \/>Is my customer data protected?<br \/>How can I prevent this from happening again?<\/p>\r\n\r\n\r\n\r\n<p class=\"has-text-color wp-block-paragraph\" style=\"color: #ff0000;\">First things first, if you need <strong>urgent assistance <a href=\"https:\/\/weaverbird.co.za\/wordpress-website-malware-removal-prevention\/\"><span class=\"underline\" style=\"text-decoration: underline;\">removing Malware from your WordPress website<\/span><\/a><\/strong>, read this <span class=\"underline\" style=\"text-decoration: underline;\"><a href=\"https:\/\/weaverbird.co.za\/wordpress-website-malware-removal-prevention\/\">quick guide<\/a><\/span>.<\/p>\r\n\r\n\r\n\r\n<div class=\"wp-block-spacer\" style=\"height: 60px;\" aria-hidden=\"true\">\u00a0<\/div>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Now, to help you make sense of it all, let&#8217;s start with<\/p>\r\n\r\n\r\n\r\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Why_did_your_website_get_hacked_with_Malware\"><\/span>Why did your website get hacked with Malware?<span class=\"ez-toc-section-end\"><\/span><\/h2>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Cybercriminals <strong>make money<\/strong> through <strong>ransomware<\/strong>, <strong>spammy backlinks<\/strong>, and collecting and selling people&#8217;s data (even card info).<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">The most common WordPress malware changes a website so that when certain visitors come to it they are <strong>redirected to a spam website<\/strong> that usually asks the viewer to click something or answer a question which can then infect that person&#8217;s device.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">It looks something like this:<\/p>\r\n\r\n\r\n\r\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"600\" height=\"495\" class=\"wp-image-9070\" src=\"https:\/\/weaverbird.co.za\/wp-content\/uploads\/2022\/12\/Malicious-Redirect-Malware-Asking-Permission.png\" alt=\"\" srcset=\"https:\/\/weaverbird.co.za\/wp-content\/uploads\/2022\/12\/Malicious-Redirect-Malware-Asking-Permission.png 600w, https:\/\/weaverbird.co.za\/wp-content\/uploads\/2022\/12\/Malicious-Redirect-Malware-Asking-Permission-300x248.png 300w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/figure>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Fortunately, most people recognise that there&#8217;s something not quite right and close the page.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">But for the less internet-wise, if they make the wrong click they could be opening themselves up to a virus being downloaded to their device.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">And if their device is not well protected, then the virus can <strong>expose sensitive information for selling purposes<\/strong> or hold that person <strong>ransom <\/strong>by requesting that they either pay money or get &#8216;exposed&#8217;.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">There are other bad things these viruses can do, none of which are good.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">For example.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Some malware <strong>adds or changes links on your website to redirect to other dodgy sites<\/strong> to help them rank better on Google. This is called <strong>SEO spam<\/strong> and is one of the more lucrative ways cybercriminals monetize hacked sites.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">One of the scariest Malware types can <strong>sit silently on a site and steal customer card details<\/strong> during the checkout process.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">At the end of the day, it&#8217;s crime.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">And what do criminals want?<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>Money<\/strong>.<\/p>\r\n\r\n\r\n\r\n<div class=\"wp-block-spacer\" style=\"height: 60px;\" aria-hidden=\"true\">\u00a0<\/div>\r\n\r\n\r\n\r\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"So_why_was_your_website_targeted_specifically\"><\/span>So why was your website targeted specifically?<span class=\"ez-toc-section-end\"><\/span><\/h3>\r\n\r\n\r\n\r\n<p><iframe loading=\"lazy\" class=\"giphy-embed\" src=\"https:\/\/giphy.com\/embed\/WCJAoTn9AZG0JTyipz\" width=\"480\" height=\"480\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/p>\r\n\r\n\r\n\r\n<div class=\"wp-block-spacer\" style=\"height: 30px;\" aria-hidden=\"true\">\u00a0<\/div>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Actually, it&#8217;s nothing personal.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">The <strong>number one reason WordPress websites get Malware<\/strong> is from outdated plugins and themes which should be done weekly, or at least, monthly.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">The other main causes are <strong>insecure passwords<\/strong> and <strong>non-updated code<\/strong>.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Hackers (and cybercrime syndicates) create automated scripts that look for vulnerable WordPress websites with outdated code and insecure passwords.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">So you see, they are not targeting you specifically, they are just searching for <strong>easy targets<\/strong>.<\/p>\r\n\r\n\r\n\r\n<div class=\"wp-block-spacer\" style=\"height: 60px;\" aria-hidden=\"true\">\u00a0<\/div>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">The next big question is\u2026<\/p>\r\n\r\n\r\n\r\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Once_malware_Malware_gets_into_your_site_is_its_data_and_customer_info_compromised\"><\/span>Once malware Malware gets into your site, is its data and customer info compromised?<span class=\"ez-toc-section-end\"><\/span><\/h3>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Unfortunately, in extreme cases, <strong>yes<\/strong>.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">We haven&#8217;t experienced this before but it is possible for Malware to access customer info and payment details.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Not what you want to hear, I know, but it does emphasise the critical importance of website safety and security.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">This leads to the final questions;<\/p>\r\n\r\n\r\n\r\n<div class=\"wp-block-spacer\" style=\"height: 60px;\" aria-hidden=\"true\">\u00a0<\/div>\r\n\r\n\r\n\r\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_can_I_prevent_this_from_happening_or_from_reoccurring\"><\/span>How can I prevent this from happening or from reoccurring?<span class=\"ez-toc-section-end\"><\/span><\/h3>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Firstly, once a website is infected with Malware, it&#8217;s quite common in the first few weeks to be <strong>reinfected<\/strong>.<\/p>\r\n\r\n\r\n\r\n<p><iframe loading=\"lazy\" class=\"giphy-embed\" src=\"https:\/\/giphy.com\/embed\/RfEbMBTPQ7MOY\" width=\"480\" height=\"308\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/p>\r\n\r\n\r\n\r\n<div class=\"wp-block-spacer\" style=\"height: 30px;\" aria-hidden=\"true\">\u00a0<\/div>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">This happens if the site is not cleaned and secured thoroughly, or if hackers create a <strong>&#8220;back door&#8221;<\/strong> to regain access to the site.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Or, it could be due to a plugin or theme not being up to date, or a compromised and unsafe plugin.<\/p>\r\n\r\n\r\n\r\n<h5 class=\"wp-block-heading\">Why all the updates?<\/h5>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Plugins and themes are upgraded so regularly to evolve and improve with the <strong>ever-changing improvements and vulnerabilities<\/strong> of the web.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">The greatest benefit of WordPress websites is also one of its biggest weaknesses &#8211; <strong>Plugins<\/strong>.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Even some of the most widely used plugins (some used on millions of websites) have become compromised. For example, let&#8217;s say a plugin is used on 100,000 sites and it gets a virus, then all <strong>100,000 sites are exposed<\/strong>.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">These issues are picked up really quickly and a security patch is released within days, but if you don&#8217;t update the plugin&#8217;s latest version with the security patch, your website will eventually pick up the malware.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">So, it&#8217;s pretty clear what you need to do:<\/p>\r\n\r\n\r\n\r\n<div class=\"wp-block-spacer\" style=\"height: 60px;\" aria-hidden=\"true\">\u00a0<\/div>\r\n\r\n\r\n\r\n<h4 class=\"wp-block-heading\">To prevent malware infections and reinfections, our first recommendation is to use a premium Malware removal and prevention service called <a href=\"https:\/\/www.malcare.com\/\" target=\"_blank\" rel=\"noreferrer noopener\"><span class=\"underline\" style=\"text-decoration: underline;\">Malcare<\/span><\/a>.<\/h4>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">For step-by-step instructions, check out our <strong><a href=\"https:\/\/weaverbird.co.za\/wordpress-website-malware-removal-prevention\/\"><span class=\"underline\" style=\"text-decoration: underline;\">quick guide for WordPress website malware removal &amp; prevention.<\/span><\/a><\/strong><\/p>\r\n\r\n\r\n\r\n<div class=\"wp-block-spacer\" style=\"height: 60px;\" aria-hidden=\"true\">\u00a0<\/div>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">I\u2019m here to chat if you have any questions,<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Stay safe,<br \/>Dan \ud83d\ude42<\/p>\r\n","protected":false},"excerpt":{"rendered":"<p>Cybercriminals make money through ransomware, spammy backlinks, and collecting and selling people&#8217;s data (even card info). The most common WordPress malware changes a website so that when certain visitors come to it they are redirected to a spam website that usually asks the viewer to click something or answer a question which can then infect that person&#8217;s device.<\/p>\n","protected":false},"author":1,"featured_media":9066,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_joinchat":[],"footnotes":""},"categories":[72,116,115],"tags":[],"class_list":["post-9065","post","type-post","status-publish","format-standard","has-post-thumbnail","category-web","category-website-maintenance","category-website-security"],"_links":{"self":[{"href":"https:\/\/weaverbird.co.za\/en-au\/wp-json\/wp\/v2\/posts\/9065","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/weaverbird.co.za\/en-au\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/weaverbird.co.za\/en-au\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/weaverbird.co.za\/en-au\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/weaverbird.co.za\/en-au\/wp-json\/wp\/v2\/comments?post=9065"}],"version-history":[{"count":7,"href":"https:\/\/weaverbird.co.za\/en-au\/wp-json\/wp\/v2\/posts\/9065\/revisions"}],"predecessor-version":[{"id":16430,"href":"https:\/\/weaverbird.co.za\/en-au\/wp-json\/wp\/v2\/posts\/9065\/revisions\/16430"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/weaverbird.co.za\/en-au\/wp-json\/wp\/v2\/media\/9066"}],"wp:attachment":[{"href":"https:\/\/weaverbird.co.za\/en-au\/wp-json\/wp\/v2\/media?parent=9065"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/weaverbird.co.za\/en-au\/wp-json\/wp\/v2\/categories?post=9065"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/weaverbird.co.za\/en-au\/wp-json\/wp\/v2\/tags?post=9065"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 6a7d676da0132878a3d2baa7. Config Timestamp: 2026-08-13 06:42:52 UTC, Cached Timestamp: 2026-08-24 08:46:57 UTC -->