Website Security & Maintenance
When websites shine too brightly: what we learned from a hacking incident Our lessons from a hacking attack on websites
A visible tag, compromised web projects, and an uncomfortable realization: a website is not a finished product. It is a running system – and anything meant to keep working reliably needs ongoing care.
"Don't shine too brightly"
"Jangan Terlalu Terang, Nanti Banyak Yang Ga Senang."
Loosely translated, this Indonesian phrase means: "Don't shine too brightly – or a lot of people won't like it." It surfaced in connection with a compromised web project. It almost sounds like a piece of life wisdom. In the context of websites, though, it takes on a very concrete meaning.
Anyone visible on the internet gets found. By customers. By search engines. By people looking for a particular service. But also by automated bots and scanners that search around the clock for known vulnerabilities.
In Luxembourg, people say: "Et ass näischt esou schlecht, datt et net fir eppes gutt ass." – Nothing is so bad that it isn't good for something. That's exactly what came to mind as we investigated and cleaned up compromised web projects.
Digital graffiti – what actually happened
In the real-world incidents, the tags "hacked by antonkill" and "hacked by Trenggalek 6etar" appeared. Other attacks are less obvious: visitors get redirected to unrelated sites, hidden spam content appears, or suspicious files get planted inside a web project.
For visitors, a visible defacement is a shock. For the affected business, it's also about availability, trust, and one key question: what happened – and how do we bring the website back to a reliable state?
Attacks like these feel personal, but often they aren't. Automated tools scan large numbers of reachable websites for known gaps. They don't distinguish between a trade business, an association, a practice, or an international company. Once an exploitable vulnerability is found, it can be used – not because a website is especially prominent, but because it's reachable.
What we know – and what can't be stated with certainty
A suspicious finding doesn't automatically prove the original point of entry. Outdated systems, no-longer-maintained extensions, old test installations, or overly permissive upload functions all raise the risk. In an individual case, though, it isn't always possible to reconstruct after the fact, beyond doubt, which gap was exploited first.
That's why a solid investigation, preserved evidence, and traceable documentation matter more than a spectacular assignment of blame. The goal isn't the most exciting story. The goal is a clean website and better protection going forward.
A website is not a poster
A modern website has long since stopped being just text and images. Behind it sit a content management system, a database, extensions, themes, user accounts, forms, interfaces, server components, and backups. All of these building blocks keep evolving – or aging.
Components with extensive permissions deserve particular attention: page builders, contact forms, file uploads, editors, shops, and connections to other systems. They make websites powerful and make everyday work easier. That's exactly why they need regular review.
Visibility isn't the problem. Visibility without ongoing maintenance is the risk.
Maintenance is more than clicking "Update"
Maintenance means removing extensions that are no longer needed, checking changes after updates, spotting anomalies in files and logs, verifying backup states, and not letting old installations fade into forgetfulness.
That's why we didn't want to sell these incidents as a shock story. We treated them as a learning curve – and as a reason to further develop our maintenance and security processes. It isn't about a single security product, but about several layers of protection working together:
- Spotting anomalies earlier: regular file and vulnerability scans flag suspicious findings for review.
- Keeping a central view of updates: CMS and extension versions are tracked clearly, so outdated or forgotten installations stand out faster.
- Preparing for recovery: backups are kept separate from the live web server, rotated, and checked for completeness.
- Shrinking the attack surface: critical directories and upload areas are treated more restrictively; unnecessary execution options and legacy installations are reduced.
- Not deleting findings blindly: scanners are allowed to raise the alarm. Evaluation and cleanup remain a traceable, human-controlled process.
What works behind the scenes
For file scanning, we rely on tools including Wordfence CLI and Linux Malware Detect. Panopticon provides a central overview of CMS and extension versions. Separate, rotating backup states form the basis for a controlled recovery.
For our customers, the names of these tools are secondary. What matters is their benefit: risks become visible earlier, responsibilities are clearer, and there's an orderly recovery path in place for the worst case.
Good website maintenance often stays invisible
When everything works, maintenance feels unremarkable. There's no alert, no repair, no big moment. That's exactly where its value lies. A well-maintained website shouldn't demand attention every day. It should stay reliably reachable, be developed under control, and make it possible to catch problems before small oversights turn into a major incident.
Good maintenance doesn't promise that nothing can ever go wrong. A promise like that would be neither honest nor credible. What it does is reduce avoidable risks, establish solid routines, and make sure that, in an emergency, no one first has to argue about responsibilities, backups, and next steps.
Security isn't a state you reach once. Security is a process.
Why the image still reads "HACKED BY VOID"
The tag in the image is not a literal rendering of a third incident. "HACKED BY VOID" is a fictionalized, slightly exaggerated nod to the real hacker tags – an artistic reworking, almost a parody.
So the focus isn't on an attacker's name. The focus is on the person in the TIME4DIGITAL shirt cleaning the wall again. The message isn't "nothing can happen to us." The message is: "We pay attention, we take care of it, and we learn from it."
Shining – but with responsibility
"Don't shine too brightly" can't be the answer for businesses, associations, and freelancers. A website should be visible. It should be found, build trust, and show what a business can do.
But digital visibility comes with responsibility. Running a website means running a piece of digital infrastructure – and infrastructure needs care, not just once something has already broken.
Maybe that's the upside of a bad experience: it forces you to question your processes and build something from it that ultimately benefits every website you maintain.
How well is your website prepared?
Not sure when your website was last fully checked, whether solid backups exist, or whether old extensions have quietly become a risk? Then let's talk. We'll look at the current state together and work out which maintenance model fits your website – transparently, understandably, and without scaremongering.