Home Security stories When a former developer defaced a client’s website

When a former developer defaced a client’s website

Shield icon with checkmark

The first sign of trouble came when the client contacted her about unexpected changes to several pages.

The client texted me about pages on the website not looking the way they should. [The changes] appeared to be on purpose, not just a normal website bug.

A former developer accessed her administrator account and vandalized the website. The new password was too similar to the old one, making it easy for someone who knew the old password to guess it.

The server logs confirmed that it was serious

At first, the changes might have looked like a website bug. But something about them seemed intentional, so the developer checked the server logs to find out what had happened.

The moment I realized it was really serious was when I looked in the server logs and saw the old company’s IP address had accessed admin area URLs and the edit page URLs for the vandalized pages.

This gave the investigator evidence that the changes were not the result of a routine bug. 

Although the submission did not report financial loss or prolonged downtime, the incident still had a clear human impact.

The biggest consequence was mostly the stress.

The lesson

The experience highlighted a risk that can remain after a professional relationship ends: familiar credentials and accounts that may still provide access to a website.

Better client education on changing passwords and checking more thoroughly for any accounts a previous developer may have had access to.

Changing a password isn’t enough if the new one is easy to guess from the old one. A change in developer, agency, employer, or other work relationship should also prompt a broader review of access.

This means reviewing administrator accounts, removing unnecessary access, and replacing existing credentials with strong, unrelated passwords.

When someone stops working with your organization, are you confident that every route they had into your website has been closed?

Have you dealt with a WordPress security incident?

Your story can show what security incidents really look like beyond the statistics, including the impact and lessons that are easy to miss.

Tell us what happened, what the experience was like, and what you learned from it. Stories may be published anonymously.

Story at a Glance

  • Business Type Digital agency
  • Website Type Corporate website
  • Impact Website downtime, defacement, and significant stress
  • Incident Type Administrator account compromise
  • Discovered By The client