We caught an attacker one day before they came back to plant more.
AOS Attic Ladders — a Dublin trade business we work with — had their WordPress site hacked in July 2026. An outdated Astra theme let an automated attacker in. Over nine days the attacker created five hidden administrator accounts, installed a remote code execution shell, and was returning weekly to top up their access.
Arran, the owner, had no idea. His pages loaded, his phone rang, his booking form worked. He only noticed something was wrong when the site briefly crashed — and that's when he called us.
Within eight hours we had found every attacker account, deleted every planted file, restored the modified core files, rotated every credential, installed Wordfence, and turned on two-factor authentication. The site is back up, hardened, and Arran has a written report he can hand to his accountant if the tax office ever asks.
"I hadn't a clue anything was wrong — phone was still ringing, booking form was working, everything looked normal. Wayne had the whole thing cleaned out and locked down by dinner time, and I wouldn't run a business without that peace of mind now."
— Arran O'Sullivan, AOS Attic Ladders
The audit that would have caught it in day one costs €399. That's why we built it.