- Job title
- System support specialist
- Sector
- Cosmetics
- Organization type
- medium-sized business
- Joined
- Apr 2025
- Message
- 15
We run an industrial packaging wholesale business based in Frankfurt. On our WordPress site which we've been using for four years, some really annoying anomalies started popping up last night. The store pulls in about 14,000 EUR a month, and several customers reported being redirected to strange external pages during the checkout step. But when we test it ourselves from our office PCs or mobile phones, everything looks completely normal.
When we logged into the admin dashboard, we spotted an unfamiliar email address listed under the admin users. Meanwhile, our freelance developer claims that a shipping tracking plugin update we ran last week messed up the database, and that the redirects might just be down to a corrupted plugin cache. However, this morning, totally unrelated foreign words started showing up under some of our products in Google search results.
Has someone actually breached the system, or are we just dealing with a messy plugin conflict? How can we know for sure? And before we rush to pull the server offline, what kind of initial response and cleanup sequence should we follow to preserve the evidence?