Cybercrime Crew Leaves Its Own Server Wide Open, Exposing 1.4 Million Website Target List
A misconfigured server ran unprotected for three weeks, handing researchers a rare look inside a mass WordPress hacking operation now tracked as WP-SHELLSTORM.

Key points
- A cybercrime group left its own command server exposed on the public internet for three weeks, revealing tools, logs and target lists.
- The exposed files named more than 1.4 million websites the group was probing, most of them running WordPress.
- Researchers are tracking the operation as WP-SHELLSTORM, named for the backdoor web shells planted on thousands of compromised sites.
- Successful break-ins numbered in the thousands, a serious figure but a small fraction of the full target list.
- WordPress site owners should audit administrator accounts and update or remove outdated plug-ins immediately.
A gang that spends its days breaking into other people's websites forgot to lock its own front door.
For about three weeks, one of the group's servers sat on the open internet with no password protection. Anyone who found the address could read the contents. Security researchers did, and what they found was the full backstage of a mass website-hacking operation: the group's tools, daily activity logs, and a target list of more than 1.4 million websites.
Most targets ran WordPress, the publishing software that powers a large share of the world's blogs and small-business pages. The operation is now tracked as WP-SHELLSTORM, a name that points to what the attackers plant on sites they compromise: a web shell, a small hidden program that lets them return and control the server whenever they like.
How did the hackers get in?
They scanned for WordPress sites running weak or outdated plug-ins and themes, the third-party add-ons that site owners install and then neglect to update. WordPress itself wasn't the flaw. Once inside, the group created a hidden administrator account and dropped a backdoor file. From there they could post spam, redirect visitors to scam pages, or sell access to other criminals.
The leaked logs, first reported by The Hacker News, showed the crew testing thousands of sites an hour and logging which ones yielded access. That kind of volume is only possible because the attack is almost entirely automated. We first covered the web-shell technique being applied against WordPress installations on 5 June 2026, when CVE-2026-8732 let attackers create administrator accounts without any credentials at all.
A target list of 1.4 million sites doesn't mean 1.4 million sites were broken into. It's closer to a cold-call list. Confirmed intrusions ran into the thousands, still a damaging number.
Should you worry?
If you run a WordPress site, or pay someone to run one, check two things this week.
First, log in and review the administrator account list. An account you don't recognise should be removed immediately, and every password changed.
Second, update WordPress, your active plug-ins and your active themes to their latest versions. Abandoned plug-ins should be deleted outright, not just switched off, because inactive code still sits on the server.
Ask your hosting provider whether they offer a file scan for known backdoors. Many do at no extra cost.
Ordinary visitors to a hacked site aren't usually in direct danger, but they may be pushed toward fake shopping pages or malware downloads. A familiar site that suddenly redirects somewhere unfamiliar is worth treating as compromised.
The practical lesson here is one that applies to attackers as much as defenders: operational security is hard to maintain under the pressure of running what amounts to an industrial software operation. This group's slip handed researchers more insight into mass WordPress exploitation than most structured investigations produce. Watch whether law enforcement acts on it, because the target lists are specific enough to be useful in court.



