Security stories from the people who experienced real incidents

There is no shortage of data about website security. Vulnerability databases, security vendor reports, industry reports on attacks, compromised websites, and wider security trends…
That data is valuable, but it only tells part of the story.

The Wall of Security Stories captures the other side of the coin, through first-hand accounts of the disruption, recovery work, financial impact, lost time, and lessons behind the statistics.

Security Book

Explore real-life stories

As an SEO, I perhaps naively wasn’t expecting to encounter something like this.

You can be 0% responsible for the security of a WordPress website and still get the blame when something goes wrong, even if just temporarily. A freelance SEO consultant was working with a building company in the London area when the client suddenly emailed to ask whether they had done something to break the website. […]

To the story

I have over 50 years of experience in the software industry, and I am fully retired at this point – except for taking care of the organization's needs.

When a VP of Technology was asked to help a nonprofit political organization with its WordPress multisite in September 2024, he was stepping into much more than a routine maintenance job. The network hosted around 40 websites used by affiliated local groups. Around half were very active, with activity across the network increasing at particularly […]

To the story

It was so stressful! It took a lot of our personal time. We are a 2-person agency and had to work nights and weekends on this, which directly cut into our lives and our time with our families.

There were several times that we thought we had resolved the issue, but then it popped up again. What happens when you run a small two-person agency and one of your nonprofit clients’ websites gets hacked? That is exactly what happened to this WordPress agency. The compromise quickly became much more than a website cleanup. […]

To the story

The client texted me about pages on the website not looking the way they should. [The changes] appeared to be on purpose, not just a normal website bug.

The first sign of trouble came when the client contacted her about unexpected changes to several pages. The client texted me about pages on the website not looking the way they should. [The changes] appeared to be on purpose, not just a normal website bug. A former developer accessed her administrator account and vandalized the […]

To the story

The fact that you lose traffic long-term for something that is, to some extent, outside of your control (or at least not actively done by you) is rough.

After logging in to Google Search Console, I saw traffic had basically gone to 0. For the owner of a small reptile blog and e-commerce store, the first indication of a security incident did not come from the website itself, but from Google Search Console. The first sign of trouble was an email warning that […]

To the story

The next day, all the files were back again. All those weirdly named files came back into the server.

On the surface, it [the incident] looked like someone had just tried to hack the website to put out a message. But [the defacement] was actually a false cover for what was going on. Under the surface, there were [malicious] files scattered throughout the site’s file system, and [the compromise] wasn’t limited to just one […]

To the story
People network
Fineger snap
Speach bubble