Whether an incident requires notification depends on evidence, data, contracts, jurisdiction and payment arrangements—not on a WordPress scanner result. Technical responders should preserve facts and escalate decisions to authorised legal, privacy, payment and business owners.
Do not delay containment while waiting for perfect certainty.
Identify the notification stakeholders
List the hosting provider, payment gateway/acquirer, merchant-account provider, cyber insurer, customers, business partners and relevant authorities/process owners.
Contracts and payment rules may require rapid notice even before full scope is known. Keep current emergency contacts outside the compromised WordPress site.
Do not contact alleged attackers or public forums as a substitute.
Define the incident window
Record earliest credible compromise, first observed symptom, checkout containment and recovery milestones in one timezone. State log-retention gaps.
Separate confirmed access/actions from capabilities. "Code could read checkout fields" differs from evidence that it transmitted them.
Update the window as new provider logs arrive.
Inventory affected data and systems
Document which checkout/account/order/form fields the compromised component or account could access and what logs show. Include external payment/tokenisation architecture.
Do not collect card data that the store should not hold. Protect customer/order evidence and limit access.
Check staging, backups, email and third-party integrations.
Preserve authoritative evidence
Retain filesystem/database snapshots, access/PHP/audit logs, payment event IDs, checkout code hashes/domains, users/keys and containment record.
Store originals securely and keep a simple custody log. Share redacted summaries unless the authorised recipient requires controlled raw evidence.
Do not email databases, secrets or malware samples.
Contact payment parties promptly
For suspected payment-page manipulation, notify the gateway/acquirer through their official incident channel and follow their evidence/credential rotation instructions.
Do not test with real card data or change provider records to hide inconsistencies. Preserve transaction/webhook/payout events.
Coordinate customer payment guidance with the payment owner.
Coordinate hosting and service providers
The host/CDN/mail provider can preserve logs, suspend abuse and confirm account activity. Provide timestamps, paths and IDs rather than credentials.
Ask for written containment and restoration requirements. Record ticket IDs and responder.
Do not rely on a chat statement as proof no access occurred.
Coordinate insurer and forensic requirements
If cyber insurance or contractual incident response applies, contact the approved channel before destroying evidence or appointing an unapproved supplier. Record claim/ticket IDs.
Do not delay urgent containment. Preserve original logs/snapshots and keep a custody record so later reviewers can distinguish evidence from working copies.
Prepare customer communication facts
State what happened, affected timeframe/data/actions, what was done and what recipients should do—only after authorised review. Avoid unsupported reassurance or unnecessary technical payload detail.
Use communication channels not controlled by the compromised site. Keep translations consistent and update when facts change.
Do not blame a named employee/vendor without evidence.
Escalate legal and privacy decisions
Provide the evidence matrix to the organisation’s legal/privacy lead, including location of customers, categories of data, likely impact and containment time.
They determine applicable notification duties and deadlines. Technical teams should not guess current law or make unilateral regulatory claims.
Preserve the decision and its evidence basis.
Maintain an approved decision log
Record which stakeholders were consulted, facts available, decision, date and when it will be reassessed. New evidence can change notification scope.
Keep legal advice and sensitive customer details in their authorised systems, not the technical work ticket. The public incident summary should remain consistent with approved facts.
Verify the technical foundation
External notice does not replace recovery. Rebuild trusted code/data, close entry paths, rotate accounts/secrets and reconcile orders/payments.
Monitor original indicators and privileged changes. Retain incident evidence under the required schedule.
Request coordinated incident response when payment/customer data may be affected. Share facts and managed access—never card data, credentials, customer exports or malware publicly.