Spam posts appearing on my account
-
Hi,
My account seems to have been hacked and posts keep appearing advertising medications and so on. I have scanned my computer (malware seems to have been the original problem but it’s gone now), changed my password a few times and enabled two-step authentication but it’s still happening.
I looked for advice online but it was all aimed at people who host their own site. My hosting is provided by WordPress so I don’t have access to change the authentication keys or anything like that, as far as I’m aware.
Can you help with this?
Karen
The blog I need help with is: (visible only to logged in users)
-
Hi Karen,
My account seems to have been hacked and posts keep appearing advertising medications and so on.
Where do these posts appear? If you opened your site and looked at All Posts, would you see the spam there? If so, does it appear as if the Posts were created from your user account?
Or is the spam in your Comments?
Or in email notifications of new Posts?
If possible, send me a screenshot of the offending spam, so I can better understand the issue. You can simply upload the screenshot to your Media Library, like any other image, and I’ll be able to access it from there. Just drop me a note here once I can see the image.
The page at the following link has some helpful tips for taking screenshots:
We’ll get to the bottom of this. Thanks.
-
Hi Robyn,
Thanks for your response. The posts look exactly as if I have posted them myself. I am listed as the author and they appear at the top of All Posts. They go into the default category “uncategorised”.
I’ve put a screenshot in Media. The two posts at the top are spam – but that should be fairly obvious!
Thanks for your help with this.
Karen
-
Hi there Karen,
Thank you so much for uploading that image for me. What a pain!
In addition to the spam posts, have your existing posts ever been edited or deleted?
Is Post By Mail turned off for your account? If you’re not certain, please visit My Blogs to take a look.
I also think it would be a good idea, if you haven’t already, to change the password for the email account affiliated with your site. You should also turn on two-step verification with your email client. If your spammer hacked your account via your email, he could still have access.
I am going to continue looking into this issue for you, and I look forward to gathering the above information from you.
Thanks very much.
-
Hi Robyn,
No existing posts have been affected, just new ones posted. I did have post by email enabled, so I’ve deleted that now, and changed my email password. It doesn’t have the option of two-step verification yet.
Karen
-
Karen,
I think this is a pretty good start. I wish you could upgrade to higher security for your email. For a higher level of protection (for your email/blog/personal info), you may want to start a new account with gmail, hotmail, or another email client with two-step verification. The new email address could be dedicated as your administrative email for this blog.
I understand if that’s too inconvenient for you. You can wait and see if these adjustments you’ve already made do the trick first.
If you change email address, make sure your Domain Administrative info is also updated. That has to be done separately from your blog settings.
Please keep in touch and let me know how this works out. I am hoping you never hear from the spammer again.
All the best!
-
Hi Robyn,
You seem to have cracked it! There have been no more spam posts since I turned off post by email :)
Karen
-
- The topic ‘Spam posts appearing on my account’ is closed to new replies.