Phishing scheme from third party app

  • Unknown's avatar

    Greetings
    We were emailed Monday from our own domain a phishing scheme. As our password is 4 random words separated by dashes not something that would be easily guessed or generated, it is determined the sender gained access through ‘Email Subscribers & Newsletters’ by Icegram website plug in we added a few months ago, around when the person claims to have access (they lied about several things in the email unsure if this is true)
    Very frustrated wordpress doesn’t have live support like the website developing softwares I used for my websites outside of this job.
    Thanks

    WP.com: Unknown
    Jetpack: Yes
    Correct account: Unknown

  • Hi @robinsonscointown, I don’t see a site on this account, but I wonder if you’re using a copy of the open source WordPress software project, rather than our managed services. If you’re using your own installation with another hosting service), I recommend getting in touch with your host to ask about backups (depending on the backup system they may be able to identify what files were added or modified), then secure your site so it’s safe:

    Jetpack

    Or (after the hack is cleared) you’d be welcome to move your site to our services, so we can take care of maintenance and security for you:
    https://wordpress.com/support/com-vs-org/#overview-of-options

    We offer direct support for all of our paid users, and those who install outside plugins and themes using our Business or eCommerce plans get fast 24/7 support. Not by phone, but we do have chat and email. We also proactively monitor for security issues. If you’re interested, you can read more here:
    https://wordpress.com/business

  • Oh! One other thing you’ll want to look into:

    We were emailed Monday from our own domain a phishing scheme

    Do check to see if the email was spoofed, too. Your host can likely help with that. Good luck!

  • The topic ‘Phishing scheme from third party app’ is closed to new replies.