Why Your Site Gets Attacked Even Though “Nobody Needs It”
Back to Blog

Why Your Site Gets Attacked Even Though “Nobody Needs It”

The objection

Sooner or later every client conversation about security arrives at the same sentence: “We’re a small company. Who would bother hacking us?”

It’s a fair question, built on a sensible mental model of crime. An attacker picks a target, sizes it up, decides whether it’s worth the effort. Under that model a local business website genuinely isn’t worth anyone’s time. The trouble is that the model describes bank robbery, and mass attacks on websites work nothing like bank robbery.

Nobody picked you

The vast majority of attacks on WordPress sites involve no human choosing anything at all. Fleets of bots scan the reachable internet around the clock, throwing lists of known vulnerabilities and common passwords at every site that answers. Yours gets attacked for the same reason it gets indexed: it exists and it responds to HTTP requests.

WordPress makes this profitable at scale because it runs over 43% of the web. Write one exploit for one popular plugin and you’ve made a key that fits millions of doors, at which point the rational move is to try every door on the planet. Checking is free. Whether a given door belongs to a bank or a bakery is information the bot doesn’t collect.

The checking got fast, too. The median gap between a critical flaw going public and mass exploitation is now down to about five hours. Only fully automated pipelines move that fast, which is its own confirmation that no human is reviewing the target list.

What they actually take

The other half of the misunderstanding is about the prize. “We don’t store anything valuable” assumes the attacker wants what’s on the site. Sometimes that’s true, but a compromised website is worth money in ways that have nothing to do with its contents.

Your server is, first of all, a computer someone else now controls for free. It sends spam. It mines cryptocurrency badly but profitably. It hosts phishing kits and attacks other sites, and there are criminal marketplaces where exactly this capacity is rented out by the hour, subsidized by your hosting bill.

Your visitors are traffic. Redirect operations monetize an audience by routing real people toward scam stores and fake login pages, quite often while showing you and Google an untouched site, as we described in the Parrot TDS case.

Your domain has a reputation, and reputation can be spent. Years of legitimate email and decent rankings mean a phishing page hosted on your domain slips past filters that would flag a week-old one instantly.

And sometimes the site is just a foothold. Somewhere to stash tools, a position to pivot toward a more interesting neighbor on the same server, a place to wait.

Look at what all four have in common: none of them cares whether your company matters. They care that the site has a CPU, some visitors, a domain with history and a valid certificate. Every site has those, which is why every site is on the list.

The mindset shift

Once you stop picturing a burglar and start picturing weather — constant, indiscriminate, uninterested in you personally — the useful question changes. “Are we worth attacking?” has no answer you can act on. “How long would we stay open if a plugin we run went public tomorrow?” does, and it’s measurable: hours until an update lands, whether anything filters traffic before it reaches PHP, how far back a clean backup goes. Company size isn’t on it. What the first day costs when those answers are bad we’ve described in detail, hour by hour, in a separate post.

So, who would bother hacking you? Nobody in particular, and that’s the point. The scanning happens whether or not anyone has ever thought about your company.

Author: Valentyn
Share this post
Book a call
Contacts

    Tell us about your project — we'll get back to you within 24 hours.

    replies within 24h

    Thank you!
    Thanks for your email — we will get back to you shortly.