WA TG

← Home

Jets-News — Detecting and Removing a Website Compromise

The Challenge

Jets-News contacted us with a serious website security issue: visitors were occasionally redirected to websites containing adult content when clicking links on the site.

These unexpected redirects were damaging both the user experience and the company's reputation.

What We Discovered

We investigated the website and reviewed recent user activity and traffic patterns.

Our analysis showed that, several weeks before contacting us, an old administrator account had been used to access the website. The account had not been disabled after the administrator left the company.

Several backdoors had subsequently been placed on the website, allowing unauthorized actions to be performed.

What We Did

We analyzed the site's recent traffic and activity, identified the source of the unwanted redirects and located the malicious code.

We then:

  • removed the malicious code and backdoors;
  • disabled the compromised user account;
  • checked the parts of the system associated with the attack;
  • documented the findings of our technical investigation;
  • prepared technical documentation and evidence for the client's further communication with the former employee and potential legal proceedings.

The Result

The source of the compromise was removed and the old account could no longer be used to access the system.

The unwanted redirects stopped and the website's reputation was restored.

The client did not need to rebuild or migrate the website. After the security issue was resolved, the existing system continued operating normally.

Get in touch

Contact me via
Urgency

Thank you

We'll get in touch soon.