Initial assessment without passwords Quote before intervention One accountable specialist from start to finish

Woocommerce Business Critical Compromise

When a WooCommerce Security Incident May Require External Notification

Prepare evidence for WooCommerce incident notifications involving payment providers, hosts, customers, regulators and insurers without guessing exposure.

Whether an incident requires notification depends on evidence, data, contracts, jurisdiction and payment arrangements—not on a WordPress scanner result. Technical responders should preserve facts and escalate decisions to authorised legal, privacy, payment and business owners.

Do not delay containment while waiting for perfect certainty.

Identify the notification stakeholders

List the hosting provider, payment gateway/acquirer, merchant-account provider, cyber insurer, customers, business partners and relevant authorities/process owners.

Contracts and payment rules may require rapid notice even before full scope is known. Keep current emergency contacts outside the compromised WordPress site.

Do not contact alleged attackers or public forums as a substitute.

Define the incident window

Record earliest credible compromise, first observed symptom, checkout containment and recovery milestones in one timezone. State log-retention gaps.

Separate confirmed access/actions from capabilities. "Code could read checkout fields" differs from evidence that it transmitted them.

Update the window as new provider logs arrive.

Inventory affected data and systems

Document which checkout/account/order/form fields the compromised component or account could access and what logs show. Include external payment/tokenisation architecture.

Do not collect card data that the store should not hold. Protect customer/order evidence and limit access.

Check staging, backups, email and third-party integrations.

Preserve authoritative evidence

Retain filesystem/database snapshots, access/PHP/audit logs, payment event IDs, checkout code hashes/domains, users/keys and containment record.

Store originals securely and keep a simple custody log. Share redacted summaries unless the authorised recipient requires controlled raw evidence.

Do not email databases, secrets or malware samples.

Contact payment parties promptly

For suspected payment-page manipulation, notify the gateway/acquirer through their official incident channel and follow their evidence/credential rotation instructions.

Do not test with real card data or change provider records to hide inconsistencies. Preserve transaction/webhook/payout events.

Coordinate customer payment guidance with the payment owner.

Coordinate hosting and service providers

The host/CDN/mail provider can preserve logs, suspend abuse and confirm account activity. Provide timestamps, paths and IDs rather than credentials.

Ask for written containment and restoration requirements. Record ticket IDs and responder.

Do not rely on a chat statement as proof no access occurred.

Coordinate insurer and forensic requirements

If cyber insurance or contractual incident response applies, contact the approved channel before destroying evidence or appointing an unapproved supplier. Record claim/ticket IDs.

Do not delay urgent containment. Preserve original logs/snapshots and keep a custody record so later reviewers can distinguish evidence from working copies.

Prepare customer communication facts

State what happened, affected timeframe/data/actions, what was done and what recipients should do—only after authorised review. Avoid unsupported reassurance or unnecessary technical payload detail.

Use communication channels not controlled by the compromised site. Keep translations consistent and update when facts change.

Do not blame a named employee/vendor without evidence.

Escalate legal and privacy decisions

Provide the evidence matrix to the organisation’s legal/privacy lead, including location of customers, categories of data, likely impact and containment time.

They determine applicable notification duties and deadlines. Technical teams should not guess current law or make unilateral regulatory claims.

Preserve the decision and its evidence basis.

Maintain an approved decision log

Record which stakeholders were consulted, facts available, decision, date and when it will be reassessed. New evidence can change notification scope.

Keep legal advice and sensitive customer details in their authorised systems, not the technical work ticket. The public incident summary should remain consistent with approved facts.

Verify the technical foundation

External notice does not replace recovery. Rebuild trusted code/data, close entry paths, rotate accounts/secrets and reconcile orders/payments.

Monitor original indicators and privileged changes. Retain incident evidence under the required schedule.

Request coordinated incident response when payment/customer data may be affected. Share facts and managed access—never card data, credentials, customer exports or malware publicly.

BEFORE YOU SEND THE REQUEST

Frequently asked questions.

Do you ask for passwords in the form?+

No. The public form never requests access. Secure credentials are requested only after the scope and quote are approved.

Who reviews the incident?+

The request goes to Jordi Ensenyat, founder of Code Barcelona and a WordPress specialist with more than 15 years of experience.

Is anything changed before the quote?+

No. Visible symptoms and scope are reviewed first. Intervention begins after approval and with a rollback path prepared.

Do you work internationally?+

Yes. WP Repair handles WordPress and WooCommerce incidents in English and Spanish through a remote service.

Assess my incident