Phishing Leads to Web Site Compromise
Or, why searching Google for a domain name instead of just using your browser's address bar is a bad idea.
This example was reported to an industry group of which ITS is a member, by a forensic specialist. Attackers exploited a widely used WordPress hosting service to compromise their customers (side note: ITS hosts WordPress also, but for less).
This service, to whom we'll refer using the generic hostname example.com, allows paying customers to use their domain for web sites, such as mysite.example.com. It seems the attacker set up an account using idnetity.example.com, which is a typo of the real name this service uses for actual customer logins, identity.example.com. They then duplicated the real login page.
A web developer searched for the login page instead of just browsing to it. Unfortunately, the first result was the fake page, listed as a paid ad in that search engine. They attempted to log in, including MFA, which they were told failed. Under two minutes later, the attacker logged into the real account using the stolen credentials.
The attacker installed malicious WordPress plugins and injected malicious JavaScript code into the web site, allowing them to run code in visitors' web browsers.
Takeaways:
- type into your address bar, or use a bookmark/favorite, instead of searching for a domain name
- check URLs you type in for typos
- be aware whether the search engine is showing you ads or search results (usually ads are labeled)
- attackers are happy to pay for ad space if they can make money off the "ads"
- regularly scan your web site for malicious code (ITS does this)
- report failing logins promptly, especially if it is the MFA step that fails (post-password)
- don't help others spoof your web site
And as always keep WordPress, and its plugins and themes, updated, just like any other software.
August 2026
Send this article to a friend!
Subscribe to The ITS Connection
Related articles









