Updated: 11/08/2026
WordPress websites are currently under attack!
For the past few weeks, there has been an ongoing wide-scale attack on WordPress sites.
This is not isolated event, as the attacks have been ongoing, peaking just a little under a week ago.
*This is affecting everyone with a WordPress site*
So what can you do to protect your site? With just a few simple precautions, you can protect yourself.
To put things in the proper perspective, we first want to inform you about the nature of the attacks. Potential hackers are employing “Brute Force” methods to access WordPress sites.
Once they have gained access to your account, they can then use various hacks to take over or destroy your site.
What is a “Brute Force” attack? Very simply, it is a way of guessing for valid passwords. It is not a very sophisticated attack, and is not targeting anyone in particular. What makes it dangerous is that it appears that they are employing massive botnets–casting a very wide net so to speak, making no distinction as to what kind of sites or businesses to target.
In response to this, we advis you to take the proper precautions towards making sure that your WordPress site is not affected.
There are some very simple ways to protect yourself which you can actually do yourself:
Change Your Password:
Brute Force attacks are very resource intensive and only have a chance of succeeding if your passwords are not secure. Change your password right after reading this article.
Make sure that it is a secure password, you can use this link to help you generate a secure, strong
password:
http://strongpasswordgenerator.com/
Secure Your Username:
The username is half of the equation – using a common username is effectively giving malicious hackers that part of the equation – making it that much easier for them. If you login to your WordPress dashboard and go to “users” on the left hand navigation – you will be given a list of users.
We never leave the “admin” user as live on our Client sites, but we are aware that people change them after we’ve set everything up. If you see a user called “admin” this is the default user) – you need to change the username immediately.
Roughly 90% of all the successful attempts are done through the “admin” login. So just by making this simple change you are protecting the site.
(Note that when you delete the user “admin” you will be asked if you want to attribute any posts to another user. Simply click the user you wish them to be attributed too. That way, you won’t lose the posts).
Remove any other user that you are not familiar with.
In conclusion:
We would recommend accessing your site as soon as possible to ensure that the username and passwords are secure.
We provide a 5 Point Security Plan, where our Team of WordPress Security Professionals can create multiple layers of security customised for your WordPress website:
- Backing up
- File Security
- Database Security
- Secure Settings
- Security Plugins
This 5 Point Security Plan involves over 28 separate lock-downs to secure your site against malicious online attacks.
Contact us today or click here for more information on our WordPress Security Service.
