• Plans & Pricing
  • Log in
  • Get started
  • WordPress Hosting
  • WordPress for Agencies
  • Become an Affiliate
  • Domain Names
  • AI Website Builder
  • Website Builder
  • Create a Blog
  • Newsletter
  • Professional Email
  • Website Design Services
  • Commerce
  • WordPress Studio
  • Enterprise WordPress 
  • Overview
  • WordPress Themes
  • WordPress Plugins
  • WordPress Patterns
  • Google Apps
  • Support Center
  • WordPress News
  • Business Name Generator
  • Logo Maker
  • Discover New Posts
  • Popular Tags
  • Blog Search
Get started
  • Sign up
  • Log in
About
  • Plans & Pricing
Products
  • WordPress Hosting
  • WordPress for Agencies
  • Become an Affiliate
  • Domain Names
  • AI Website Builder
  • Website Builder
  • Create a Blog
  • Newsletter
  • Professional Email
  • Website Design Services
  • Commerce
  • WordPress Studio
  • Enterprise WordPress  
Features
  • Overview
  • WordPress Themes
  • WordPress Plugins
  • WordPress Patterns
  • Google Apps
Resources
  • Support Center
  • WordPress News
  • Business Name Generator
  • Logo Maker
  • Discover New Posts
  • Popular Tags
  • Blog Search
Jetpack App
  • Learn more
  • Support Center
  • Guides
  • Courses
  • Forums
  • Contact
Search
  • Support Center
  • Guides
  • Courses
  • Forums
  • Contact
Forums / My account was hacked and they're editing my site.

My account was hacked and they're editing my site.

  • Unknown's avatar
    ameliespp · Member · Nov 22, 2011 at 8:23 pm
    • Copy link Copy link
    • Add topic to favorites Add topic to favorites

    Some little freak hacked my account. I logged out and logged back in, and changed my passoword. PLEASE tell me WP has a security setting or something I can buy. One of my neighbors told me that the first log in screen is not secure.

    The blog I need help with is: (visible only to logged in users)

  • Unknown's avatar
    timethief · Member · Nov 22, 2011 at 8:33 pm
    • Copy link Copy link

    I have been here for 5 1/2 years and the only time that a blog security has been compromised is when the blogger makes their log-in information accessible to others, or chooses a password that’s easily guessed. Changing your password was a good idea provided you actually chose one that’s not easy to guess.

    PLEASE tell me WP has a security setting or something I can buy.

    The weak link in all security issues is the blogger (see what I said above). There no such upgrade you can purchase. Support Staff offer excellent advice here:
    Security
    HTTPS

  • Unknown's avatar
    thesacredpath · Member · Nov 22, 2011 at 8:38 pm
    • Copy link Copy link

    As I understand it, the login temporarily and instantaneously switches to https when transmitting your username and password, but if you wish you can run the entire dashboard from https by going to users > personal settings and under “Browser Connection” select “Always use HTTPS when visiting administration pages”.

    You are going to get a good number of warnings popping up, especially if you use Internet Explorer as there are certain parts of some dashboard pages that are not in HTTPS. You will just have to deal with the warnings. HTTPS is also much slower since it has to jump through a bunch more hoops.

    The important thing is to have a very strong password that contains both upper and lower case letters, numbers and special characters such as &%#)* etc.

    Change or Reset Your Password

  • Unknown's avatar
    ameliespp · Member · Nov 22, 2011 at 8:39 pm
    • Copy link Copy link

    “The weak link in all security issues is the blogger”

    Um, what are you talking about? My passwords are rated “strong” on every site, I follow the recommendations and my boyfriend is a computer expert so we have excellent methods around here. What about bloggers on WP who tell me your security settings are weak? Several of my friends think their email accounts were hacked because WP did not protect them.

  • Unknown's avatar
    ameliespp · Member · Nov 22, 2011 at 8:40 pm
    • Copy link Copy link

    @Sacredpath Thank you for the info! Do you know if there is any way to get this particular hacker logged out short of starting my website from scratch? Maybe importing the site to another address?

  • Unknown's avatar
    ameliespp · Member · Nov 22, 2011 at 8:43 pm
    • Copy link Copy link

    @Sacredpath – done, and no warnings, it updated quite fast. WP has been good like that so far.

  • Unknown's avatar
    thesacredpath · Member · Nov 22, 2011 at 8:44 pm
    • Copy link Copy link

    WordPress does not have passwords to your email accounts. If someone hacks an email account, they are not getting the password from wordpress.

    WordPress.com is probably near the absolute top as far as security goes and virtually all instances of site being “hacked” here have either been due to easy to guess passwords, or someone making someone else an admin on their site who either has a weak password which was guessed, or that admin goes in and does mischief themselves.

  • Unknown's avatar
    auxclass · Member · Nov 22, 2011 at 8:47 pm
    • Copy link Copy link

    Change your password (probably done already)

    Look under Dashboard >> Users and make sure that there are no users that you did not authorize and delete any trash.

    Since WordPress.COM does not know anything much about any email other than the email address itself I can’t believe how WordPress.COM could contribute to any email hacking.

  • Unknown's avatar
    timethief · Member · Nov 22, 2011 at 8:53 pm
    • Copy link Copy link

    @emmiscafe
    Are you the only official user and only Administrator on your blog or not?
    user roles

  • Unknown's avatar
    ameliespp · Member · Nov 22, 2011 at 8:55 pm
    • Copy link Copy link

    @timethief Yeah I just looked under All Users, I’m the only one listed!

    Do you know if I can import my site, assuming that the person can stay logged in and now I cannot control what they write?

  • Unknown's avatar
    ameliespp · Member · Nov 22, 2011 at 8:58 pm
    • Copy link Copy link

    This was what the person in question said:

    “Guess what? The default login pages for services like Twitter and WordPress are NOT encrypted with HTTPS. What can be done about this? Don’t enter your login information on the default page. Click the login button but leave the username and password fields blank. This will then take you to a page that is secured with HTTPS”.

    So that was the issue *they* brought up. My password was considered strong. I did change it to an even more jacked up one that hopefully will work. Just pointing out, emmiscafe is right there as my user name and all they needed was to guess my password. Not sure how they did it, I was using that one for one single other blog since 2006 and never had anything like this happen.

  • Unknown's avatar
    timethief · Member · Nov 22, 2011 at 8:59 pm
    • Copy link Copy link

    Please don’t panic and move any content as yet. I flagged this thread for Staff attention when I posted above the first time. I think you ought to go to Staff because they can tell exactly when the blog was accessed and by which IP. Here’s the link http://en.support.wordpress.com/contact/ After you use the searchbox, under the search results, at the bottom of the page there will be a section that says “Have you found the answer to your question?” You can choose either “Yes I found the answer to my question.” or “No I didn’t find the answer to my question and I would like to contact support for help.” The no option will reveal the contact form.

  • Unknown's avatar
    thesacredpath · Member · Nov 22, 2011 at 8:59 pm
    • Copy link Copy link

    If the password has been changed since the other person logged in, when they try to access a page, they will again get the login since the cookie wordpress put on their computer would differ from the new one, so you should have no worries in that respect.

    If you are on wireless in your house, make sure your wireless is secured and not open to anyone.

  • Unknown's avatar
    ameliespp · Member · Nov 22, 2011 at 9:01 pm
    • Copy link Copy link

    Just an FYI, I get the feeling it was this nutjob right here. I say that because there is one news site I subscribe to and have left a handful of comments, “she” recently replied to every one of them with, “Yes I agree Emmy” and it was the only website I linked to my blog.

    http://www.queenasalah.com/

  • Unknown's avatar
    ameliespp · Member · Nov 22, 2011 at 9:02 pm
    • Copy link Copy link

    @Timethief thank you and actually yes I contacted them first, but I *was* panicked so I posted here, LOL! Any more info I can get is great, I will check in again tonight. I really appreciate the info.

  • Unknown's avatar
    ameliespp · Member · Nov 22, 2011 at 9:07 pm
    • Copy link Copy link

    @Sacredpath Whew, that’s good! Thanks for the info, I have not seen anything suspicious since I logged out. I think I need to limit my comments (linked with my WP blog) to private individuals only and never link it to a news site, too many weirdos out there.

  • Unknown's avatar
    timethief · Member · Nov 22, 2011 at 9:09 pm
    • Copy link Copy link

    @emmiscafe
    Hi again,
    As you went to Staff previous to posting here I will remove the flagging. :)

  • Unknown's avatar
    auxclass · Member · Nov 22, 2011 at 9:09 pm
    • Copy link Copy link

    Also set comments on your blog to required to be approved by moderator then you will have no surprises by nuts or trolls.

  • Unknown's avatar
    toothless · Member · Nov 22, 2011 at 9:11 pm
    • Copy link Copy link

    Hi, my account has been hacked a lot of times. The headers have all been changed on my blogs along with a lot of text. The one on my blog about Children of Divorce is sort of funny. It was the picture of grass growing, it’s called “Benevolence” by Theron Parlin. Someone changed the grass to look trampled. It’s sort of funny but also pretty scary.

    There is absolutely no security on this site. Thanks for the tips, though. I will try them.

  • Unknown's avatar
    ameliespp · Member · Nov 22, 2011 at 9:16 pm
    • Copy link Copy link

    @Timethief Oh, thank you. Sorry, I should have opened with that info, that I had contacted Support.

1 2 3
  • The topic ‘My account was hacked and they're editing my site.’ is closed to new replies.

Tags

  • hacked account
  • official users
  • security
  • strong password

About this topic

  • In: Support
  • 10 participants
  • 41 replies
  • Last activity 14 years
  • Latest reply from ameliespp

Couldn't find what you needed?

Contact us

Contact us

Get answers from our AI assistant, with access to 24/7 expert human support on paid plans.

Browse our guides

Browse our guides

Find step-by-step solutions to common questions in our comprehensive guides.

WordPress.com

Products
  • WordPress Hosting
  • WordPress for Agencies
  • Become an Affiliate
  • Domain Names
  • AI Website Builder
  • Website Builder
  • Create a Blog
  • Professional Email
  • Website Design Services
  • WordPress Studio
  • Enterprise WordPress
Features
  • Overview
  • WordPress Themes
  • WordPress Plugins
  • WordPress Patterns
  • Google Apps
Resources
  • WordPress.com Blog
  • Business Name Generator
  • Logo Maker
  • WordPress.com Reader
  • Accessibility
  • Remove Subscriptions
Help
  • Support Center
  • Guides
  • Courses
  • Forums
  • Contact
  • Developer Resources
Company
  • About
  • Press
  • Terms of Service
  • Privacy Policy
  • Do Not Sell or Share My Personal Information
  • Privacy Notice for California Users
DeutschEspañolFrançaisBahasa IndonesiaItalianoNederlandsPortuguês do BrasilSvenskaTürkçeРусскийالعربيةעִבְרִית日本語한국어简体中文繁體中文English

Mobile Apps

  • Download on the App Store
  • Get it on Google Play

Social Media

  • WordPress.com on Facebook
  • WordPress.com on X (Twitter)
  • WordPress.com on Instagram
  • WordPress.com on YouTube

Automattic

Automattic
Work With Us
    • WordPress.com Forums
    • Sign up
    • Log in
    • Copy shortlink
    • Report this content
    • Manage subscriptions