How We Cleaned a Hacked WooCommerce Store and Stopped Fake Orders

Rogue admin accounts, betting spam and a wave of fake orders: how we cleaned up TORX Racing’s WooCommerce store and built a custom plugin to stop card-testing fraud.
How we cleaned a hacked WooCommerce store and stopped fake orders, MIVAQ case study cover

When TORX Racing, a manufacturer of performance watercraft parts, came to us, their WooCommerce store had three problems at once: unauthorised administrator accounts from a previous hack, spam posts and comments about betting, and a steady stream of fraudulent orders. Here is how we fixed it, step by step, so you can spot the same signs on your own site.

Signs your WordPress site has been hacked

  • Administrator users you did not create
  • New posts, pages or comments full of spam links
  • Visitors redirected to unrelated sites
  • Strange files in your uploads folder
  • Warnings in Google Search Console or the browser
  • Sudden bursts of failed orders on one product

Step 1: Contain and back up

Before changing anything we took a full backup, so nothing could be lost, and recorded what we found.

Step 2: Remove unauthorised access

We removed every administrator account the owner did not recognise, reset passwords and rotated security keys so existing sessions were logged out.

Step 3: Clean spam content

Auto-posted betting content and spam comments were removed from the database, and comment settings tightened.

Step 4: Update everything

WordPress core, all plugins and the theme were updated to their latest versions. Outdated plugins are one of the most common ways attackers get in.

Step 5: Diagnose the fake orders properly

The store already had CAPTCHA, yet fraudulent orders kept arriving. Looking at order patterns showed repeated failed transactions on the same product from rotating IP addresses. That is card-testing fraud: criminals checking stolen card numbers with small purchases. Blocking single IPs does not work because they rotate.

Step 6: Build a defence that matches the attack

We built a custom WooCommerce security plugin with three layers:

  1. Checkout rate limiting to slow repeated attempts.
  2. Automatic IP blocking based on how fast failed orders pile up.
  3. Site-wide lockdown mode that detects bursts of fraud even when IPs rotate.

The outcome

Fake orders and spam stopped, genuine customer orders kept coming in, and the site now runs without errors. The client then hired us for security work on another website.

How to protect your own store

  • Keep WordPress, plugins and themes updated.
  • Delete plugins you do not use.
  • Use strong unique passwords and two-factor authentication for admins.
  • Review your user list monthly.
  • Watch for spikes in failed payments; they are an early warning.
  • Keep off-site backups.

If your site shows any of these signs, our WordPress malware removal service can help. For ongoing care, see WordPress solutions.

FAQ

Is CAPTCHA enough to stop card testing?

Not always. Determined attackers work around it, which is why rate limiting and velocity-based blocking matter.

Will removing malware hurt my SEO?

No. Cleaning a hacked site protects your rankings. Spam URLs can then be removed from Google through Search Console.

Keep reading

Dessert shop website design case study for Sip and Scoop Edinburgh, MIVAQ cover
Case StudiesWebWordPress
How we designed and built Sip & Scoop, a dessert and drinks destination in Edinburgh, in WordPress and Elementor, and what every
SEO for video production companies, SmartVideo case study cover
Case StudiesSEO
Video agencies have great portfolios but often weak search visibility. How we approached SEO for SmartVideo in Belfast, and what other creative
On-page SEO audit checklist with a real estate website example, MIVAQ cover
SEO
The on-page SEO audit we ran on Privé Properties, a Puerto Cancún luxury real estate website: what we checked across 20+ pages

Need help putting this into practice?

We turn ideas like these into working websites, stores and growth plans. Tell us what you are working on.