Website hacking: how a simple password sharing crippled an SME
La situation
It all started with an action that seemed harmless. On September 2, 2024, the company's website administrator performed a routine task: backing up the CMS (the site management system), updating the extensions, and, to help out or advance a project, exchanging passwords with an acquaintance.
The next day, the trap closed. No access to the CMS worked anymore. The company's website was suddenly hijacked and replaced with completely foreign content. Anxiety rose a notch two months later when the site disappeared outright, replaced by a blank page that offered no hope of logging into the admin area.
Initially, the company thought it was a simple technical issue, a redirect error or an inadvertent change to the DNS rules. But the reality was far harsher: the SME's web infrastructure had been compromised, directly affecting its brand image and online operations.
Ce que nous avons fait
Faced with this emergency, Fidelilium’s IT security experts intervened immediately to conduct a rigorous technical analysis and understand the cause of the blockage.
Our team first secured access with the hosting provider to audit domain ownership, dissect the DNS rules, and meticulously analyze the Web and FTP logs (activity histories). This is where Fidelilium’s expertise made the difference, shedding light on the true nature of the incident:
- DNS rules analysis: No suspicious redirection was detected, ruling out a simple technical error.
- FTP log audit: Our technicians observed suspicious connections on the exact day the site went blank. The crucial CMS configuration file and the htaccess file (which manages server security and access) were downloaded, emptied of their content, and re‑uploaded, rendering the site completely inoperable.
- Web log analysis: Fraudulent requests targeted the admin pages while the legitimate client was locked out. The proof was clear: an intruder had indeed taken over the company’s server.
Fidelilium immediately attempted a clean re‑installation of the CMS to regain control. However, a technical constraint linked to the hosting provider blocked the procedure (error notifications were configured to be sent to the victim’s end‑client rather than to the victim themselves).
After a 3‑hour‑30‑minute intervention, and based on our clear conclusions, the client chose to take over directly with the hosting provider to apply a full restoration of the original backup.
Because cybersecurity is foremost a matter of good human practices, our experts used this intervention to provide the client with comprehensive educational support. We raised their awareness of the dangers of sharing credentials, the crucial importance of strong passwords, and the essential processes for secure managed services and maintenance.