7 lessons from six months of fighting a website hacker

You don’t expect to spend six months fighting the same website hack over and over.

What started with a puzzling email from Google Search Console turned into thousands of spam posts, hidden malicious code, mystery admin accounts and a lesson in why simply cleaning up a hacked WordPress site isn’t always enough.

If you run your own website, Andy Candler shares the mistakes, the warning signs and the seven things he wishes he’d known before it all started….

If you run a WordPress site, this is the post he wished he found and read last February.

It started at an airport

Last February, just as I was about to board a plane to Colombia, an email landed from Google Search Console telling me that someone was now an owner of my website. The address given was an odd, throwaway Gmail account.

I logged into Search Console straight away, heart sinking, and found nothing. There was no record of that user anywhere in my Search Console. The email said they were an owner. They weren’t. I was very confused.

Then I looked at the site itself. On desktop, everything was fine. On mobile, my pages were serving up gambling content. That is called cloaking, showing one thing to most visitors and something else to phones or to search engines, and it is exactly why these hacks can run for days before you notice. You glance at your site on your laptop, it looks normal, and you move on.

Kim Ellis happened to be sat with Richard Price at a L&D cowork and put him in touch with me. Richard kindly went through the site, got the mobile version working again, and we thought that was the end of it. The trip was going to be trouble-free.

It was not.

Read the full post on LinkedIn.

**Alt text:** Graphic promoting a blog about website security, showing the headline "What to do when hackers keep popping up" beside a cybersecurity-themed whack-a-mole arcade machine with an L&D Free Spirits logo and blog button.