Hackers Are Scanning Every Business Website for a Way In: ACSC Alert Explained

The ACSC has warned that hackers are scanning websites worldwide, including many Perth small businesses, for outdated CMS software and plugins to plant hidden backdoors. Here's what to check. From Computer Mechanics, Perth IT specialists since 1997.

XanderXander · Web Developer & IT Technician
14 August 2026
5 min read
Cybersecurity
Website Security
IT Support
Perth Business

If your business runs its own website on WordPress, Joomla, or a similar content management system, there's a real chance it's currently being scanned for a way in. The Australian Signals Directorate's Cyber Security Centre (ACSC) issued a critical alert warning that attackers are running a large-scale, automated campaign against websites worldwide, planting hidden backdoors called webshells on any site running outdated software. Many small and medium Australian businesses have already been affected. Here's what it means and what to check this week.

What's actually happening

A content management system, or CMS, is the software that runs your website behind the scenes; WordPress is the best-known example, but Joomla, Craft CMS and others work the same way. Most CMS platforms rely on plugins for extra features, like contact forms, file uploads or page builders, and those plugins are usually where the trouble starts.

The ACSC says attackers are automatically scanning the internet for websites running CMS software or plugins with known, unpatched vulnerabilities. When they find one, they exploit it to upload a webshell, a small hidden file that gives them ongoing remote access to the site without needing a username or password. From there, they can deface the site, steal data, redirect visitors to scam pages, or use the compromised server as a launchpad to attack other systems.

The alert specifically names WordPress, Craft CMS, MaxSite CMS, MetInfo CMS and Joomla's JCE editor, with vulnerable plugins including Simple File List, WavePlayer and Ninja Forms among those exploited. If your site uses any of these, or you're not certain what it's built on, this is worth a proper look rather than a guess.

Why this matters even for a "simple" brochure website

It's tempting to assume a small, mostly static company website isn't worth a hacker's time. That assumption is exactly what makes this campaign effective, because attackers aren't targeting your business specifically. They're running automated tools that scan millions of sites for the same handful of known flaws, and a five-page brochure site on outdated WordPress plugins is just as vulnerable as a large e-commerce store.

Once a webshell is planted, the damage isn't limited to the website itself. A compromised web server can be used to send phishing emails that look like they come from your domain, host malware that gets served to your own visitors and customers, or act as a stepping stone into other parts of your network if the hosting is shared with other systems. It can also sit there undetected for months, quietly doing none of the above until an attacker decides to use it, which is what makes "we haven't noticed anything wrong" poor evidence that a site is clean.

What to check this week

  1. Confirm your CMS core and every plugin are on the latest version. This is the single biggest factor. If your site was set up once and never touched again, that's the profile this campaign is designed to catch.

  2. Remove plugins you don't actually use. Every inactive plugin is still a potential door if it's ever exploited; deleting the ones you don't need shrinks the target.

  3. Look for anything unfamiliar in your website's file list, particularly newly created files with odd names in upload folders, or files with a recent modification date you can't account for. This isn't always visible without hosting/admin access, so ask whoever manages your site to check if you can't.

  4. Check who has admin access to your CMS, and remove any accounts that shouldn't still be there, particularly from past staff or old contractors.

  5. Confirm you have a recent, working backup of the website, separate from the live server. If a site does turn out to be compromised, restoring from a known-good backup is the cleanest fix; without one, cleanup is far slower and less certain.

If you find anything that looks like a webshell, or your site is already showing odd behaviour like unexpected redirects or unfamiliar admin accounts, the ACSC's guidance is to treat the server as compromised: isolate it, don't just delete the suspicious file and move on, and restore from backup once the vulnerability that let the attacker in has been patched.

The pattern behind this alert

This campaign is a good example of why "set and forget" doesn't work for anything internet-facing, whether that's a website, a firewall, or a piece of on-premises software. Attackers don't need a targeted reason to go after a Perth small business; they need an unpatched, internet-facing system, and automated scanning finds those at scale regardless of who owns them. It's the same logic behind the ASD Essential Eight's emphasis on patching known vulnerabilities within a defined window, just applied to a part of the business, the public website, that often falls outside a company's usual IT support conversation because "someone built it once" and it's rarely thought about again.

If your website was built by a freelancer or agency that's no longer around to maintain it, that's a genuine gap worth closing, not a reason to leave it as-is and hope.

Get it checked

If you're not sure what your website is built on, who last updated it, or whether it's carrying any of the plugins named in this alert, that's a reasonable thing to have looked at properly rather than guess about. Our IT security solutions cover exactly this kind of exposure, alongside the rest of your systems, and our managed IT support keeps software patched proactively so a campaign like this one is a non-event rather than a scramble. Get in touch or call (08) 9325 1196. We've helped Perth businesses stay a step ahead of exactly this kind of threat since 1997.

Xander
Written by
Xander
Web Developer & IT Technician · 2+ years in IT

Xander builds fast, SEO-friendly websites and handles hands-on IT and computer-repair work — from Next.js builds and local search optimisation through to hardware fixes, OS reinstalls and helpdesk support. He covers the full stack, from the rack to the browser.

Meet the IT Support Perth team →
Xander
14 August 2026
5 min read
Cybersecurity
Website Security
IT Support
Perth Business

Stay Updated with IT Insights

Get the latest cybersecurity tips and technology insights delivered to your inbox

Related Articles

A Fake Invoice Nearly Gets Paid at a Perth Accounting Firm: How We Respond

A representative walkthrough of how we respond when a Perth accounting firm spots a business email compromise (fake-invoice) scam — stop the payment, trace the intrusion, and close the hole for good. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

A Phishing Link at a Perth Medical Practice Becomes an Account Takeover

A representative walkthrough of how we respond when a staff member at a Perth medical practice is phished and their Microsoft 365 account is taken over — contain, assess breach exposure, and harden patient data. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

A Perth Business's Server Dies — and the Backup Hadn't Run in Weeks

A representative walkthrough of how we recover a Perth business after a server failure — and what we do when the backup everyone trusted had silently stopped running. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Need Expert IT Support?

Get personalized advice from our Perth IT experts. Free consultation available.

Related Content

Continue Reading

Explore more insights and expert advice on IT support, cybersecurity, and digital transformation

Your Messages Are "Encrypted" — But the FBI Just Read Them Anyway. Here's What Every Perth Business Needs to Know.
CyberSecurity
ITSupportPerth

Your Messages Are "Encrypted" — But the FBI Just Read Them Anyway. Here's What Every Perth Business Needs to Know.

Most small business owners believe end-to-end encryption means their messages are completely private. A recent FBI case proves that assumption is dangerously incomplete.

5 min read
4/15/2026
What’s new in SMB1001:2026?
SMB1001
SMB10012026

What’s new in SMB1001:2026?

SMB1001:2026 updates for Perth SMBs: Mandatory DMARC from Silver tier, 5 maturity levels, Essential Eight alignment. Get certified, cut insurance costs, win tenders—start your roadmap today!

5 min read
2/25/2026
A Fake Invoice Nearly Gets Paid at a Perth Accounting Firm: How We Respond
Cybersecurity
Business Email Compromise

A Fake Invoice Nearly Gets Paid at a Perth Accounting Firm: How We Respond

A representative walkthrough of how we respond when a Perth accounting firm spots a business email compromise (fake-invoice) scam — stop the payment, trace the intrusion, and close the hole for good. From Computer Mechanics, Perth IT specialists since 1997.

5 min read
8/14/2026
Call us