Experts warn 2,000 hacked WordPress sites were secretly running a global
crime ring
Date:
Sat, 22 Aug 2026 13:05:00 +0000
Description:
Compromised WordPress sites have been used by a global operation, using trusted websites to deliver malware, instruct infected devices, and even
store stolen documents.
FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Researchers uncover vast cybercrime ring running on computers and infected domains where outdated versions of WordPress were installed The StopAndProtect investigation
revealed the WordPress content management system was key to the rings
success; both the core software and third-party plugins were subverted Around 2,000 WordPress sites were hijacked by the cybercrime ring Check Point Research has unearthed a global cybercrime ring that relied on a network of WordPress websites. The investigation into an operation dubbed StopAndProtect found a network of 5,000 infected computers around the globe, and 2,000 WordPress domains.
WordPress currently provides content management for around 43% of websites worldwide, making it the most significant CMS available. It is also the most popular website builder, and is suitable for single page websites, basic blogs, vast news sites, and even online stores. The researchers found the crime ring had made some mistakes, which alerted them to their operation. These included screenshots and logs of victims, internal tools, and files referencing the hijacked domains. While reassuring, the StopAndProtect investigation raises questions about the security of WordPress sites. Latest Videos From TechRadar Watch full video here: How StopAndProtect did it WordPress has long been a target for hackers looking for an easy way to host malware and operate botnets, with several key incidents over the course of
its history. However, the CMS remains free and open source, and is easy to setup thanks to installation scripts and web builder plugins.
While StopAndProtect was initially the name given to the ransomware uncovered by Check Point Research earlier in 2026, they decided to use the name for the whole operation, as they found it doesnt only distribute ransomware. You may like Over 1 million WordPress sites at risk after popular plugins hacked Experts warn millions of WordPress websites could be at risk following reveal of worrying bugs WordPress users beware experts claim sites are being hijacked using a critical flaw in popular Everest Forms Pro plugin
Check Point Researchs Eli Smadja said : StopAndProtect shows how attackers
can turn thousands of poorly maintained WordPress sites into a distributed criminal infrastructure for malware delivery, surveillance, data theft, and ransomware. Can any WordPress domain be hijacked? Given the number of WordPress sites impacted by the crime ring uncovered by the investigation,
and the platforms prominence in the CMS and web builder market, the question has to be asked: is WordPress still safe? Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me
with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.
Based on our research findings, we urge organizations be cautious of unexpected CAPTCHA prompts that instruct them to copy, paste, or run
commands, keep their devices and security software updated, and immediately leave any website that asks them to perform unusual steps outside the browser," Smadja added.
Many small businesses rely on WordPress for their public-facing web presence, and in some cases for internal purposes too. The StopAndProtect investigation highlighted a particular WordPress-driven site running a five-year-old
version of the CMS, compromised by around 40 vulnerabilities.
If concerns surround WordPress, the quickest solution is to ensure the
website is running the most recent version, and that the plugins are not only running as intended, but also fully updated.
Maintaining a regular WordPress update cycle can avoid sites becoming hijacked, a strategy best used in conjunction with a web host that monitors for intrusions and suspicious activity. Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
======================================================================
Link to news story:
https://www.techradar.com/pro/security/experts-warn-2-000-hacked-wordpress-sit es-were-secretly-running-a-global-crime-ring
--- Mystic BBS v1.12 A49 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)