Fake login pages found on my hosting
A phishing kit on your hosting is someone else's fraud running under your domain name. The pages copy a bank, Microsoft, Apple, or a delivery company, and the links are emailed to strangers who have never heard of you. Your own site usually looks completely normal, which is why almost nobody finds these on their own. Hosts and browser vendors both treat phishing as urgent, so this tends to move quickly once it's noticed.
We reply within 1 business day (Mon–Fri, 9–5 ET)
What you're seeing
- An abuse notice from your host, or from a bank or brand's security team, naming a URL on your domain
- A folder in your files you don't recognize, often deep inside uploads or a plugin directory, with names like a brand or a random string
- Browsers showing a red deceptive site warning for a URL on your domain
- Your host suspends the account, sometimes with very little warning
- Files with names like login, verify, secure, or update, plus a script that emails collected details somewhere
- Your homepage and real pages working perfectly the whole time
Why it happens
A phishing kit uploaded to your account
Attackers upload a ready-made bundle of pages and a small script that emails whatever victims type. It needs nothing from WordPress except somewhere to sit.
A vulnerable plugin or theme
The usual way in. A known file upload or arbitrary file write vulnerability in outdated code lets someone place files anywhere in your site.
Hidden deep in a folder you never open
The kit is almost always placed several levels inside wp-content/uploads or a plugin folder, sometimes behind an index file that returns a blank page so casual browsing shows nothing.
Stolen hosting or SFTP credentials
If the account details were captured elsewhere, no site vulnerability is needed at all, and the files can be placed outside WordPress entirely.
Your domain's reputation is the point
A phishing page on a real, established domain gets past filters that would block a brand new one. That reputation is what the attacker is borrowing, and what you get back once it's cleared.
What to do right now
Do this
- Get the exact URL from whoever reported it, and ask your host for the full list of files they found and when they appeared
- Ask your host what they need before they'll lift or avoid a suspension, and keep that reply
- Change hosting, SFTP, and WordPress passwords, and check for administrator accounts you don't recognize
- Check whether other sites share the same hosting account, since the kit may have been placed in more than one
Don't do this
- Don't just delete the folder and reply that it's handled. If the upload route is still open, the kit is back within days and the second abuse report is taken far less kindly
- Don't ignore it because your own site looks fine. The phishing pages are deliberately kept away from your real pages
- Don't leave the URL live while you decide what to do. Real people are being defrauded through it in the meantime
How we fix it
- 1Remove every phishing file and folder, including the copies that don't appear in the abuse report
- 2Find the upload route: the vulnerable plugin, the backdoor, or the stolen credential that let the files land there
- 3Check the rest of the account, including other sites on it, for the same kit and for anything else left behind
- 4Rotate passwords and security keys, update and harden the site, and remove any scheduled tasks or rogue accounts involved
- 5Write the summary your host's abuse team needs, and request review with Google Safe Browsing if your domain was flagged
Cleanups start at $349, with a money-back guarantee: if we can't clean your site, you don't pay.See pricing
Questions
Why would anyone target my small site?
You almost certainly weren't targeted. Attackers scan the whole web for a particular vulnerable plugin version and take whatever answers. What they want is somewhere to host pages under a domain with a clean reputation, and any site that lets them upload files will do.
My host suspended the account with no warning. Is that normal?
For phishing, yes. Hosts have their own obligations and their own reputation to protect, and phishing content is the one category they usually act on immediately. The route back is a genuine cleanup plus a clear reply to their abuse team explaining what was found and what was fixed, which is part of the work we do.
Will this affect my search rankings or my email?
It can do both. Browsers may show a deceptive site warning for your domain, and your domain or server address can end up on blocklists that also affect email delivery. Once the content is gone and the site is genuinely clean, we request the reviews and delistings needed to clear it.
Other symptoms
- Visitors get redirectedYour site sends people to spam, scam, or adult sites, often only on mobile or from Google.
- "This site may be hacked"Google shows a warning in search results, or Chrome shows a red "Deceptive site ahead" screen.
- Strange pages in GoogleJapanese, pharma, or casino pages you never created show up under your domain.
- Your host suspended youYour hosting company took the site offline or quarantined files for malware.
- Your site sends spamYour host or email provider says your server is sending spam or phishing emails.
- You're locked outYour admin password stopped working, or there are admin users you didn't create.
- It keeps coming backYou cleaned the site, and the malware was back within days.
- Card skimmer on checkoutCustomers' card details are being captured at checkout by injected code.
- Pharmacy spam in GoogleYour search listings mention pills or pharmacies, even though your pages look normal.
- A scanner says I'm infectedWordfence, Sucuri, or another plugin reports malware you can't get rid of.
Hacked right now? Let's get it fixed.
Start your cleanup and we'll take it from there. If we can't clean it, you don't pay.
We reply within 1 business day (Mon–Fri, 9–5 ET)