• Plans & Pricing
  • Log in
  • Get started
  • WordPress Hosting
  • WordPress for Agencies
  • Become an Affiliate
  • Domain Names
  • AI Website Builder
  • Website Builder
  • Create a Blog
  • Newsletter
  • Professional Email
  • Website Design Services
  • Commerce
  • WordPress Studio
  • Enterprise WordPress 
  • Overview
  • WordPress Themes
  • WordPress Plugins
  • WordPress Patterns
  • Google Apps
  • Support Center
  • WordPress News
  • Business Name Generator
  • Logo Maker
  • Discover New Posts
  • Popular Tags
  • Blog Search
Get started
  • Sign up
  • Log in
About
  • Plans & Pricing
Products
  • WordPress Hosting
  • WordPress for Agencies
  • Become an Affiliate
  • Domain Names
  • AI Website Builder
  • Website Builder
  • Create a Blog
  • Newsletter
  • Professional Email
  • Website Design Services
  • Commerce
  • WordPress Studio
  • Enterprise WordPress  
Features
  • Overview
  • WordPress Themes
  • WordPress Plugins
  • WordPress Patterns
  • Google Apps
Resources
  • Support Center
  • WordPress News
  • Business Name Generator
  • Logo Maker
  • Discover New Posts
  • Popular Tags
  • Blog Search
Jetpack App
  • Learn more
  • Support Center
  • Guides
  • Courses
  • Forums
  • Contact
Search
  • Support Center
  • Guides
  • Courses
  • Forums
  • Contact
Forums / My account was hacked and they're editing my site.

My account was hacked and they're editing my site.

  • Unknown's avatar
    ameliespp · Member · Nov 22, 2011 at 9:17 pm
    • Copy link Copy link

    @Auxclass thank you, and yeah that was done on my blog a while ago, a visitor was oversharing about her (I’ll be euphamistic here) personal life way too much. So many nuts in this world! :(

  • Unknown's avatar
    ameliespp · Member · Nov 22, 2011 at 9:20 pm
    • Copy link Copy link

    @Toothless wow, scary stuff! Tomorrow I will probably laugh about this (assuming no more hacker stuff shows up) because the person was fairly benign except they put ads in my posts and put political agenda in the body of comments from friends – their grammar was terrible! LOL

  • Unknown's avatar
    ameliespp · Member · Nov 22, 2011 at 9:22 pm
    • Copy link Copy link

    @Toothless otherwise for me, WP has been excellent generally speaking, my only complaints are that the site sometimes moves extremely slow (on days when all other sites are fine) and seems to have very very odd glitches, other folks have commented on that. However I realize a site like this is extremely hard to make perfect and anyway it’s free, although I’d be willing to pay for certain features. I value it greatly, our Vox community would have been destroyed otherwise.

  • Unknown's avatar
    lynnf08 · Member · Nov 24, 2011 at 3:11 pm
    • Copy link Copy link

    My site was hacked five hours ago. The intruder first attempted “lost/changed password” for “admin” a few times, then registered and made him/herself an admin even though I have not allowed self-registration for some time. S/he renamed the site “babun,” renamed my theme from “Morning Coffee” to “babun,” and changed my main page to show a Guy Fawkes mask and an incoherent message about Allah and Facebook. I’ve put in a service request to Dreamhost to help me figure out for sure which code is the intruder’s and advise me about theme re-installation.

    According to Sitemeter, the activity during that period included an entry from a Facebook page (which Facebook wouldn’t let me access for security reasons) and a visit of not quite 18 minutes. I have identified two IP addresses that may be involved.

    I do have a registration under the Admin username, but I never use it, preferring to log in under another admin name, my username for posting. It was transferred to me by the previous blog owner. Besides deleting Admin and changing my username password, is there anything else I should be doing immediately security-wise?

  • Unknown's avatar
    auxclass · Member · Nov 24, 2011 at 3:31 pm
    • Copy link Copy link

    Changing to a very secure password and making sure that there are no users that are not authorized should do it.

    Also make sure that your computer is not left logged in and not attended, this also assumes you don’t have some sort of key logger virus on your machine. Some people get in trouble when they have some sort of auto-login and someone uses their computer.

  • Unknown's avatar
    tandava108 · Member · Nov 24, 2011 at 3:43 pm
    • Copy link Copy link

    lynnf08:
    Your domain has been hacked not your worpress.com account. It appears to be registered with dreamhost.com. You will need to deal with them to resolve the situation.

  • Unknown's avatar
    tandava108 · Member · Nov 24, 2011 at 3:52 pm
    • Copy link Copy link

    The login screen is http but the login form specifies an action as follows

    <form class=”login” method=”post” action=”https://wordpress.com/wp-login.php”>

    This means that the login is secure even though coming from an insecure page. I know that this panics some users, so perhaps WordPress could change it to a login button that goes to an https page. It would only be slightly more secure(*) but would give people the reassurance of seeing the https, the padlock, etc.

    (*) In theory someone on your network could change the page being downloaded so that it sent your login details somewhere else instead of logging you in to WordPress. This is quite a small risk though, someone would have to compromise internet routing equipment to do it.

  • Unknown's avatar
    lynnf08 · Member · Nov 24, 2011 at 3:58 pm
    • Copy link Copy link

    Thanks so much for helping me understand what’s happened, and for the advice. Yes, I have contacted Dreamhost.

  • Unknown's avatar
    justjennifer · Member · Nov 24, 2011 at 5:43 pm
    • Copy link Copy link

    @lynnf08- if you are talking about the site linked to your username http://www.citybarbs.com/ , then you are posting in the wrong forum as your site is not hosted on WordPress.com.

    This is the help forum for WordPress.com blogs. It’s great you found assistance here, but for the future you should really be posting over at http://wordpress.org/support/ because the software we use here is especially engineered for WordPress.com and different from the standalone version of WordPress.

  • Unknown's avatar
    tandava108 · Member · Nov 24, 2011 at 5:53 pm
    • Copy link Copy link

    @justjennifer
    We don’t know whether it was a .com or .org site. It could have been a wordpress.com site with domain hacking. If you use domain mapping and your domain account with the registrar is hacked they can point it to anywhere.

    In any case it is nether a .com nor a .org issue now, the only people who can help are the regstrar, in this case dreamhost.com

  • Unknown's avatar
    thesacredpath · Member · Nov 24, 2011 at 6:20 pm
    • Copy link Copy link

    …then registered and made him/herself an admin even though I have not allowed self-registration for some time.

    The above, not to mention that @lynnf08 mentions contacting dreamhost would lead one to believe it is self-hosted. We at wordpress.com cannot have “self-registration” but on a .ORG site you can.

  • Unknown's avatar
    raincoaster · Member · Nov 24, 2011 at 10:44 pm
    • Copy link Copy link

    And of course, nobody knows where Toothless’s blog is hosted. Sounds like a troll to me.

  • Unknown's avatar
    toothless · Member · Nov 25, 2011 at 4:25 am
    • Copy link Copy link

    Hi emmicafe,

    It looks like you are now inactive. Sorry I didn’t respond sooner. I’m trying to stay off wordpress.

    raincoaster, I’m not a troll. Both of the blogs that have been hacked are on WordPress. If that’s what you mean. The artwork on the headers have been altered.

  • Unknown's avatar
    raincoaster · Member · Nov 25, 2011 at 4:40 am
    • Copy link Copy link

    And you claimed “me too!” and we still don’t know where you’re hosted.

  • Unknown's avatar
    thesacredpath · Member · Nov 25, 2011 at 4:53 am
    • Copy link Copy link

    There are two types of wordpress sites. Those hosted here at wordpress.COM, and those that are self-hosted on third-party hosting services such as dreamhost, bluehost, etc., using the software from wordpress.ORG. Two totally different things.

    WordPress.com vs. WordPress.org

  • Unknown's avatar
    toothless · Member · Dec 9, 2011 at 4:27 am
    • Copy link Copy link

    My blog is hosted at WordPress.com.

  • Unknown's avatar
    raincoaster · Member · Dec 9, 2011 at 4:30 am
    • Copy link Copy link

    What is the URL then? at least one of the people in this thread isn’t hosted at WP.com; it’s not possible for people to add themselves as Users to a WP.com blog.

    Disable Post by email immediately if you think you’ve been hacked. Delete all people with User permissions you don’t want as Users. And do not re-enable post by email; that seems to be the weak link here. And change the password on your email as well.

  • Unknown's avatar
    raincoaster · Member · Dec 9, 2011 at 4:43 am
    • Copy link Copy link

    And I’m sorry I called you a troll. It had been a very long day.

  • Unknown's avatar
    iamtheonlyrightcoastgirl · Member · Dec 11, 2011 at 7:02 pm
    • Copy link Copy link

    This occurred three years ago you did nothing, he has hacked my account, inserted a banner that I’ve screen shots of everything, inserts his articles, changes my articles, the banner he inserted just showed up on this page, I don’t know if you’ll receive this. He’s got blogs on WordPress , Simonthongwh.wordpress.com, is one, I think the other is Simonthg.wordpress.com, he deleted a Blog of men and I paid for a premium theme and haven’t used it yet! http://iamnobody.wordpress.com.
    Help me this is so illegal the least you can do is ban him from word press. He changed my Avatar, inserted his on the sticky post front page.
    Please help me,this is out of hand, I keep buying things from you and look what happens.
    Thank you
    Rhoda

  • Unknown's avatar
    iamtheonlyrightcoastgirl · Member · Dec 11, 2011 at 7:04 pm
    • Copy link Copy link

    That’s not my avatar he changed. It again my hacked blog is http://warcriminals.wordpress.com
    Rhoda

1 2 3
  • The topic ‘My account was hacked and they're editing my site.’ is closed to new replies.

Tags

  • hacked account
  • official users
  • security
  • strong password

About this topic

  • In: Support
  • 10 participants
  • 41 replies
  • Last activity 14 years
  • Latest reply from ameliespp

Couldn't find what you needed?

Contact us

Contact us

Get answers from our AI assistant, with access to 24/7 expert human support on paid plans.

Browse our guides

Browse our guides

Find step-by-step solutions to common questions in our comprehensive guides.

WordPress.com

Products
  • WordPress Hosting
  • WordPress for Agencies
  • Become an Affiliate
  • Domain Names
  • AI Website Builder
  • Website Builder
  • Create a Blog
  • Professional Email
  • Website Design Services
  • WordPress Studio
  • Enterprise WordPress
Features
  • Overview
  • WordPress Themes
  • WordPress Plugins
  • WordPress Patterns
  • Google Apps
Resources
  • WordPress.com Blog
  • Business Name Generator
  • Logo Maker
  • WordPress.com Reader
  • Accessibility
  • Remove Subscriptions
Help
  • Support Center
  • Guides
  • Courses
  • Forums
  • Contact
  • Developer Resources
Company
  • About
  • Press
  • Terms of Service
  • Privacy Policy
  • Do Not Sell or Share My Personal Information
  • Privacy Notice for California Users
DeutschEspañolFrançaisBahasa IndonesiaItalianoNederlandsPortuguês do BrasilSvenskaTürkçeРусскийالعربيةעִבְרִית日本語한국어简体中文繁體中文English

Mobile Apps

  • Download on the App Store
  • Get it on Google Play

Social Media

  • WordPress.com on Facebook
  • WordPress.com on X (Twitter)
  • WordPress.com on Instagram
  • WordPress.com on YouTube

Automattic

Automattic
Work With Us
    • WordPress.com Forums
    • Sign up
    • Log in
    • Copy shortlink
    • Report this content
    • Manage subscriptions