Guide
Why malware attacks are increasing
Nobody chose your website. Attacks on small and medium sites are a volume business, and almost every part of the economics has been moving in the attacker's favour.
The most common thing we hear from a business after a compromise is some version of "why us?" The honest answer is that nobody chose you. Attacks on small and medium websites are a volume business, and almost everything about the economics has been getting better for the attacker.
1. Attacks are automated, so scale costs nothing
Nobody sits looking at your website deciding whether it is worth the effort. Software sweeps enormous ranges of addresses looking for one specific signature — a plugin version, an exposed file, a login form that answers. Once the tooling exists, trying it against ten million sites costs barely more than trying it against ten. That is why a small business site with modest traffic gets probed constantly.
2. The window between disclosure and exploitation keeps shrinking
When a vulnerability is published, the details are public — including for the people writing the scanners. Exploitation of newly disclosed website vulnerabilities now routinely begins within days, sometimes hours. "We'll update at the end of the sprint" was a reasonable policy when that gap was measured in months.
3. There is more software in every website than there used to be
A typical site runs a CMS, a theme, and a stack of plugins, each with its own dependencies and its own maintainer. Every one of those is a potential entry point, and some are abandoned — no longer maintained, so the fix never arrives at all. The attack surface grew without anyone deciding to grow it.
4. Attacking is now a supply chain of its own
The person who breaks in is frequently not the person who exploits the access. Initial access is found, catalogued and sold on; somebody else installs the spam, the skimmer or the miner. This specialisation is why compromised sites often contain several unrelated infections, and why the entry point may be months older than the symptom you noticed.
What this means in practice
Because access is resold, removing today's payload does not remove tomorrow's buyer. Unless the way in is closed and the persistence is gone, a cleaned site is simply back on the market.
5. AI has lowered the skill floor
Two effects are visible rather than speculative. Phishing and social engineering have lost the obvious tells — the broken grammar that used to give them away is gone, and messages can be tailored to a specific company cheaply. And writing or adapting exploit and obfuscation code no longer requires the expertise it once did, which widens the pool of people capable of running these campaigns.
It is worth being precise here rather than dramatic: AI has mostly made existing techniques cheaper, faster and more convincing. It has not, so far, changed what the attacks fundamentally are.
6. Credentials leak continuously
Passwords exposed in one breach get tried everywhere else, automatically. If an administrator reused a password that appeared in an unrelated leak, no software vulnerability is needed — the attacker simply logs in, which is also why the intrusion leaves so little trace.
7. Servers are worth money regardless of your traffic
Even a site nobody visits has value: CPU for mining, an IP address for sending spam, disk space for hosting phishing pages, and a clean domain reputation to borrow for SEO spam. "There's nothing worth stealing on our site" misunderstands what is being stolen.
What actually reduces your exposure
The defences that work are unglamorous, and they follow directly from the causes above:
- Update quickly, and own it. Most compromises exploit something that was already patched. The gap is process, not knowledge.
- Remove what you do not use. Every dormant plugin and parked staging site is attack surface with no upside.
- Unique credentials and two-factor everywhere. This defeats credential stuffing outright.
- Harden the server, not just the site. Block execution in uploads, lock down SSH and the firewall, isolate sites from each other.
- Monitor continuously. Dwell time is the reason small incidents become expensive ones — the damage compounds while nobody is looking.
- Fix the entry point, every time. Cleaning without closing is how sites end up on the reinfection treadmill.
Monitoring, hardening and unlimited cleanups — one monthly price.
See plansRelated guides
Unlimited malware removal, for one monthly price.
We clean websites and VPS servers as often as it happens, monitor them 24/7, and harden them so it doesn't happen again.