Was my WordPress account hacked?

  • Unknown's avatar

    I received 500+ emails within a very short frame and they were mostly WordPress-generated… I am trying to locate where the breach occurred so I can update my information accordingly. Thanks.

    The blog I need help with is: (visible only to logged in users)

  • HI there,

    Our system has not sent you any emails recently apart from the email when you started this thread.

    Are the emails you’re receiving coming from a wordpress@ address or form @wordpress.com? All emails from us will come from @wordpress.com, no exceptions.

    If it’s wordpress@, the emails are not from us. Whatever appears before @ in an email address is irrelevant. If you want to know who’s sending the emails you need to look at the domain after the @. The owner of that domain is who is responsible for the emails.

    What is most likely happening here is that someone managed to obtain your email address and is now using it to register new user accounts on self-hosted WordPress sites, likely in an attempt to hack those sites.

    You can try reporting them to their domain provider, or to their email provider (you can see who that is if you look at the email’s HTML headers), but otherwise I’d recommend you set up a filter matching the common words/phrases in the subject lines and have Gmail automatically delete those as they come in.

  • The topic ‘Was my WordPress account hacked?’ is closed to new replies.