Although there are many potential vulnerabilities that can be exploited by hackers, one thing that you do not need to worry about is server security. Our servers have advanced security modules that assure the best possible protection, such as mod_security, Suhosin PHP hardening, PHP open_basedir protection, and others. Check What Security Measures Does Hostinger Use? for more information.
We also have an automatic Malware Scanner on your hPanel, that will help identify and remove malicious files on your account.
If you suspect that your account or website was hacked, check the article below for the possible reasons, actions you can take, and how to prevent it.
Why Did It Happen?
The most common reasons are:
Outdated web applications - Using older versions of your CMS (WordPress, PrestaShop, Joomla, etc.)
Outdated or nulled extensions - Third-party extensions such as plugins, modules, or themes can be vulnerable if outdated. Also, be aware of paid extensions offered for free on unofficial sites, as they may have been modified to include malware
Weak, exposed, or breached passwords - Using passwords that are easy to guess, repeating the same password across different services, or using passwords that were publicly posted (for example, if you have it written down on a sticky note at your desk)
Infected local computer - Some computer viruses can steal your login information and use it to add malicious code to your web files
What to Do if a Profile or Site Is Hacked?
There are a few things to look for that can indicate a potential hack:
If you notice these or other unusual changes, the recommended actions are:
Checking your devices for any viruses and malware (you can use Malwarebytes for this)
Checking your browser for any suspicious extensions
For website hacking:
For account hacking:
And make sure to notify our Customer Success team, so we can perform additional checks on our part.
How to Prevent It?
Here are some measures you can take to protect your account and your sites:
Never provide your login and password to anyone. If you wish for a developer to manage your website, you can use our Access Manager feature
Scan regularly all your devices with up-to-date antivirus and antimalware software
Keep your CMS and application extensions updated to the latest version
Download extensions/plugins/modules/themes only from trusted sources
Always use secure and strong passwords. You can find some useful recommendations here: How to create a strong password?
And if your website is WordPress-based, here are additional methods to protect it
By following these practices, you will ensure maximum protection for your website!
If you're using a VPS, check this article: What to Do if Your VPS Has Been Hacked?