Active WordPress incident? Initial assessment within 4 hours. (Mon–Fri 8am–8pm, Sat 9am–2pm (CET/CEST))

Case Studies

Case studies of WordPress security incidents

We only publish cases that have been anonymized and approved by the client. Each case study covers the initial symptom, technical findings, entry path, cleanup, data-exfiltration indicators, hardening, and outcome.

No client-approved case studies are currently available for publication.