Phishing attacks on WooCommerce webshops: what are they and what can you do about them?
Do you manage a webshop via WordPress, and do you use WooCommerce? Then it’s good to be extra alert. There’s namely a phishing attack going on that’s specifically targeted at administrators of webshops that use WooCommerce.
What’s going on?
Fake emails are currently going around that look as if they come from WooCommerce. WooCommerce is a widely used plugin that turns a WordPress site into a webshop and already has more than eight million users.
In the fake email, it states that a security issue has been discovered in WooCommerce, and that your website would be affected by it too. The email suggests downloading a “patch” (update) to fix the issue.
Why is this dangerous?
The link in the email leads you to a website that closely resembles WooCommerce’s official site, but it isn’t. The scammers have done everything they can to make the domain name and website look trustworthy.
If you download the so-called security update on this malicious site, you’re actually installing malicious software. This hides among your existing plugins and creates a secret user account with full access to your site.
What can you do to stay safe?
First of all, it’s advisable to never carry out updates via email. Always go directly to your WordPress dashboard or visit WooCommerce.com yourself. In addition, always stay alert to suspicious emails, even if they look professional. It’s also important to always carefully check the web address (URL) for strange characters or spelling mistakes.
WooCommerce is currently working on taking the fake websites offline, but it remains important to stay alert.
Need help?
Curious whether your webshop is safe and up to date? Let us take a look. Send us a message or call 0591 71 46 99 We’re happy to think along with you to prevent this kind of thing as much as possible. Our specialists are ready for you.