CustomerHandwerksbetrieb (anonym) IndustryHandwerk · eigener Online-Shop SystemWordPress / WooCommerce RelationshipSEO-Erstkunde, langjährig

A broken checkout process was reported. We discovered a store that had been compromised for years.

A small business reported payment issues with its online store. Upon investigation, we found 24,476 hidden spam entries—invisible to visitors but readable by Google. We cleaned up the store in a single pass without losing a single legitimate record.

The findings in numbers

It was reported as harmless. But we found something else.

The company first found us through SEO years ago and later built its own WooCommerce store. During the pandemic, our collaboration slowed down, but we never lost touch. A small follow-up inquiry brought us back to the site—and led us to our findings.

What was reported

It was no longer possible to complete orders properly in the shop. Credit card payments weren't working. A quick fix was supposed to solve the problem—a routine task, or so it seemed.

What we found

The database contained thousands of entries unrelated to the trade. An administrator account that no one knew about. Hidden casino text mixed in with legitimate products. The site wasn't broken—it had been hijacked.

Start over, do a quick cleanup—or perform a forensic cleanup.

Option A

Start over

Throw everything away and start over.

Risk real data + SEO history gone
Time weeks
Costs high
Episode lost content
Option B

Delete only visible spam

Remove the obvious spam pages.

Risk The infestation is returning
Time low
Costs short-term
Episode Backdoor remains open
Option C

Perform forensic cleaning & resolve the root cause

Check the database and file system, perform a thorough cleanup, and close the gap.

Risk can be checked in the code
Time Core cleanup in 1 day
Costs A fraction of A
Episode Data remains, page cached

Not a single moment. A gradual process that has unfolded over the years.

Phase 01
The Break-in

The attackers gain access through a plugin vulnerability. They create a dormant user account and wait.

around 2019
Phase 02
The first injection

Hidden casino text is moved to the shop page. Invisible via CSS, but fully readable by Google.

May 2021
Phase 03
The Test

The attackers enter random text into the database. This is how they check to see if anyone responds. No one responds.

2022
Phase 04
Scaling

New casino posts are added regularly in over ten languages. A new administrator account was created in April 2026.

by 2026

What the adjustment actually means

We removed the infected part—we didn't throw the page away.

Before deleting any data, we verified that the actual store content remained intact. All 23 genuine product categories were unaffected. A file system audit revealed no backdoor code. The attack was carried out exclusively through the database.

// cleanup_log · production
// Removed from the database
: spam_pages: 17
, spam_posts: 293 + 82
, spam_categories: 24,476
hidden_divs: 6 // genuine products
rogue_accounts: 2
typo_redirect: 1//

integrity after cleanup
real_categories: 23
file_backdoors: 0
data_loss: 0
status: "clean"
Audit · Database + File System STATUS · CLEAN

Stack & Tools.

Platform

WordPress Store

  • WordPress + WooCommerce
  • Flatsome-Theme
  • ~280 echte Produkte
  • gewachsene Installation
Forensics

Audit & Cleanup

  • Datenbank-Audit in 5 Stufen
  • Dateisystem-Scan auf Webshells
  • Benutzerkonto-Review
Curing

To make sure it doesn't happen again

  • eigene Login-Adresse + 2-Faktor
  • xmlrpc abgeschaltet
  • Alarm bei neuem Admin-Konto
  • Bot-Schutz + Datei-Integrität

Three lessons that make this case replicable.

01 · Prevention is better than cure. An unattended system quietly falls into disrepair. The attack took root during this period of neglect.

02 · Black Hat SEO damages the reputation. No theft of money or data—just abuse of the domain’s reputation. The damage manifests itself in visibility over the years.

03 · Relationship beats transaction. Contact was never lost. A small follow-up inquiry led to the site’s rescue.

Frequently Asked Questions

Is there something running on your site that you can't see?

We’ll take a look at your WordPress or WooCommerce installation: hidden content, unauthorized accounts, database clutter, and visibility history. You’ll receive a clear report.