Home / Blog / WordPress Security After SocGholish: A Calgary Checklist
Security

Is Your Calgary Business's
WordPress Site Actually Clean?

By Sean Derondeau June 30, 2026 6 min read

Short version: if your business runs on WordPress, your site can look completely normal and still be quietly compromised. In June 2026, an international police operation cleaned almost 15,000 hacked WordPress sites in a single coordinated action. This is a plain-language checklist to help you confirm yours is clean and make it harder to break into next time. No fear-mongering, no jargon, and nothing to buy.

Your website is a revenue asset, so treat this like any other piece of business equipment that earns its keep right up until the day it needs a quick inspection.

What just happened

On June 18, 2026, law enforcement from the Netherlands, Canada, the United States, and Germany, coordinated by Europol and Eurojust, disrupted a malware network called SocGholish (also known as FakeUpdates). They took down roughly 106 servers and remotely cleaned 14,971 infected WordPress sites. The official Europol announcement has the full details.

SocGholish has been running since 2017. It quietly breaks into legitimate WordPress sites, usually through an out-of-date plugin or a stolen password, and injects a small piece of JavaScript. To a visitor, the site then shows a fake "your browser needs an update" prompt. One click installs malware, which has been used to deliver ransomware. The owner of the site often has no idea their business is the one handing it out.

The scale is the part worth your attention. In May 2026, the Shadowserver Foundation counted roughly 1.44 million compromised WordPress sites available to this one operation. WordPress runs a large share of the small business web, which is exactly why it gets targeted.

Why a small business should care

A compromised website is not just an IT headache. It is a business continuity problem. If your site starts serving fake update prompts, three things happen at once: customers lose trust, Google can flag or remove you from search, and your hosting company may suspend the site until it is cleaned. For a local shop, a clinic, or a service business that gets leads online, that is real revenue walking out the door while you scramble.

The good news is that the fixes are mostly basic maintenance. You do not need to be technical, and you do not need to spend money. You just need to work through the list below, or have someone do it for you.

The WordPress security checklist

This is the part that stays useful long after the news fades. These are the same steps the authorities gave to affected site owners, drawn from official, vendor-neutral guidance.

1. Update WordPress core, plugins, and themes

Out-of-date software is the front door. Log in to your dashboard and update WordPress itself, then every plugin and theme, including the ones you are not actively using. Better still, delete any plugin or theme you do not use at all, because each one is a potential way in. WordPress publishes an official Hardening WordPress guide that goes deeper if you want it.

2. Change your passwords, and make them real ones

Assume any password tied to the site could be known. Change the passwords for your WordPress admin accounts, your hosting account, your database, and your FTP or SFTP login if you have one. Use long, unique passwords from a password manager. Reusing one password across your email and your website is the single most common way small sites get taken.

3. Turn on multi-factor authentication

Multi-factor authentication (MFA) means a password alone is not enough to log in. Even if an attacker has your password, they still need the second factor on your phone. Turn it on for your WordPress admin login and your hosting account at a minimum. The Canadian Centre for Cyber Security has clear guidance on MFA if you want the official version.

4. Remove admin accounts you do not recognize

Open the Users section of your dashboard and look at everyone with an administrator role. If there is an account you do not recognize, or an old contractor who no longer needs access, remove it. Attackers often leave themselves a spare key in the form of a hidden admin account, so this step matters even when everything looks fine.

5. Back up, then keep watch

Make sure you have a recent, working backup stored somewhere off the site itself, so you can roll back if you have to. After that, watch for the warning signs: unexpected redirects, that fake update prompt, a sudden spike in traffic or spam, or a notice from your host or from Google Search Console. If you see them, take the site offline and have it cleaned before it does more damage.

The honest part

A takedown is good news, but it is not the end. The group behind SocGholish is tied to a long-running criminal operation that has rebuilt its infrastructure quickly before, and the stolen passwords from this campaign may still be circulating. Treat this as a current warning, not a closed case. The checklist above is worth doing whether or not your site was ever touched.

Knowing the list is not the same as being clean

Here is the honest part for a business owner. Reading a checklist and knowing for certain that your site is clean and locked down are two different things. Some of these steps take five minutes. Others, like confirming there is no leftover malicious code or a hidden admin account, are hard to verify if you are not in this stuff every day.

That is the kind of work we do. If you want a second set of eyes on your WordPress site, or you just want someone to walk the checklist with you so you can get back to running your business, we are glad to help. As an authorized Cloudbrink reseller, secure access is part of what we set up for clients, though most owners simply need the basics done right.

Frequently asked questions

How do I know if my WordPress site was infected?

The clearest signs are a fake "browser update" prompt on your pages, visitors being redirected to sites you do not recognize, or a warning from your hosting provider or Google Search Console. SocGholish is built to stay hidden, though, so no obvious signs is not proof you are clean. Working through the checklist above is the safer assumption.

Do I need to buy a security product to fix this?

No. Every step on the checklist uses tools you already have inside WordPress and your hosting account. Be careful with any pop-up or email telling you to install a specific "scanner" to clean your site, because that is sometimes the scam itself.

I am in Calgary and not very technical. Where do I start?

Start with updates and passwords, since those close the two most common doors, then turn on multi-factor authentication. If you get stuck, or you are not sure the site is actually clean, book a free consultation and we will walk through it with you.

Is the threat over now that police took the servers down?

Not entirely. The infrastructure was disrupted, but the operators are still active and have rebuilt before, and stolen credentials may still circulate. Keep the hardening steps in place for good, not just for this one event.

Ready to Work
Together?

Free 30-minute consultation. We will tell you exactly what we would do and what it would cost, in plain language.

Book My Free Consultation