When TORX Racing, a manufacturer of performance watercraft parts, came to us, their WooCommerce store had three problems at once: unauthorised administrator accounts from a previous hack, spam posts and comments about betting, and a steady stream of fraudulent orders. Here is how we fixed it, step by step, so you can spot the same signs on your own site.
Signs your WordPress site has been hacked
- Administrator users you did not create
- New posts, pages or comments full of spam links
- Visitors redirected to unrelated sites
- Strange files in your uploads folder
- Warnings in Google Search Console or the browser
- Sudden bursts of failed orders on one product
Step 1: Contain and back up
Before changing anything we took a full backup, so nothing could be lost, and recorded what we found.
Step 2: Remove unauthorised access
We removed every administrator account the owner did not recognise, reset passwords and rotated security keys so existing sessions were logged out.
Step 3: Clean spam content
Auto-posted betting content and spam comments were removed from the database, and comment settings tightened.
Step 4: Update everything
WordPress core, all plugins and the theme were updated to their latest versions. Outdated plugins are one of the most common ways attackers get in.
Step 5: Diagnose the fake orders properly
The store already had CAPTCHA, yet fraudulent orders kept arriving. Looking at order patterns showed repeated failed transactions on the same product from rotating IP addresses. That is card-testing fraud: criminals checking stolen card numbers with small purchases. Blocking single IPs does not work because they rotate.
Step 6: Build a defence that matches the attack
We built a custom WooCommerce security plugin with three layers:
- Checkout rate limiting to slow repeated attempts.
- Automatic IP blocking based on how fast failed orders pile up.
- Site-wide lockdown mode that detects bursts of fraud even when IPs rotate.
The outcome
Fake orders and spam stopped, genuine customer orders kept coming in, and the site now runs without errors. The client then hired us for security work on another website.
How to protect your own store
- Keep WordPress, plugins and themes updated.
- Delete plugins you do not use.
- Use strong unique passwords and two-factor authentication for admins.
- Review your user list monthly.
- Watch for spikes in failed payments; they are an early warning.
- Keep off-site backups.
If your site shows any of these signs, our WordPress malware removal service can help. For ongoing care, see WordPress solutions.
FAQ
Is CAPTCHA enough to stop card testing?
Not always. Determined attackers work around it, which is why rate limiting and velocity-based blocking matter.
Will removing malware hurt my SEO?
No. Cleaning a hacked site protects your rankings. Spam URLs can then be removed from Google through Search Console.