AI News Feed
Market watch
Cybersecurity

Experts warn 2,000 hacked WordPress sites were secretly running a global crime ring

Check Point Research reveals a global cybercrime ring using 2,000 hacked WordPress sites and 5,000 infected computers.

The researchers found that the crime ring had made mistakes that alerted them to its operation, including screenshots and logs of victims, internal tools, and files referencing the hijacked domains. While reassuring, the StopAndProtect investigation raises questions about the security of WordPress sites.

WordPress currently provides content management for around 43% of websites worldwide, making it the most significant CMS available. It is also the most popular website builder, suitable for single-page websites, basic blogs, vast news sites, and even online stores. The investigation revealed that both the core software and third-party plugins were subverted, allowing the ring to distribute ransomware, conduct surveillance, steal data, and more.

“StopAndProtect shows how attackers can turn thousands of poorly maintained WordPress sites into a distributed criminal infrastructure for malware delivery, surveillance, data theft, and ransomware,” said Eli Smadja of Check Point Research.

The name StopAndProtect was initially applied to ransomware uncovered by Check Point Research earlier in 2026, but researchers decided to use it for the whole operation because it does not only distribute ransomware.

Smadja added: “Based on our research findings, we urge organizations be cautious of unexpected CAPTCHA prompts that instruct them to copy, paste, or run commands, keep their devices and security software updated, and immediately leave any website that asks them to perform unusual steps outside the browser.”

The investigation highlighted a WordPress-driven site running a five-year-old version of the CMS, compromised by around 40 vulnerabilities. Many small businesses rely on WordPress for their public-facing web presence, and in some cases for internal purposes too.

To avoid becoming hijacked, experts recommend ensuring websites run the most recent version of WordPress and that plugins are fully updated. Maintaining a regular update cycle, in conjunction with a web host that monitors for intrusions and suspicious activity, can also help protect against such attacks.