Invasion Investigation · Part 8
The last article was about decisions with a price tag. This one is about the decisions that involve other people — and they work differently, because some of them aren’t yours to make on cost grounds at all.
They’re also the ones owners get wrong most often, in both directions: staying silent when they had an obligation to speak, and announcing things publicly before they knew whether they were true.
The obligations come first, because some of them have deadlines. After them come the last three decisions with a price tag — how much investigation you are actually buying, when to stop, and whether to stay where you are — because each one turns on what the conversations below tell you.
One item comes before all the others.
If data belonging to other people may have been exposed, talk to an attorney
Notification duties vary by state and by data type. Getting it wrong is expensive in both directions — failing to notify when you should have, and notifying badly when you didn’t need to.
We are not lawyers and this is not legal advice. Have the conversation early, before you’ve announced anything and before you’ve destroyed anything. This is the one item on this page where “it costs too much time” is not a reason.
Tell your host, and tell them early
If you’re on shared hosting — and most small businesses are — your compromise is not only yours.
You’re one account among dozens or hundreds on the same physical server, sharing a filesystem. A compromised account is a foothold inside that machine, and the tooling that turns up in these compromises is built to take advantage of it.
From the case file. Two of the tools recovered here had cross-account capability built in. One carried a module that creates symbolic links to other customers’ configuration files so they can be read through the web. The other advertised a bypass for the restriction that’s supposed to stop a script reading outside its own account.
Whether either was ever used against the neighbours is unknown and probably unknowable. The capability sat there for months, which is the part that matters when you’re deciding whether to pick up the phone.
There’s more to it than file access. Spam sent or served from one account gets the server’s IP address blacklisted, and every site on it inherits that — their email stops arriving, their reputation takes the hit, and none of them will ever know why.
And it runs both ways. If a neighbour is compromised and nobody told the host, that’s a live threat to you, sitting on the same disk. The reason to care about this isn’t only courtesy.
Your host is the only party who can actually check. You can see your account. They can see the machine — whether the same files appear elsewhere, whether the same addresses are hitting other accounts, whether it started somewhere other than with you. That’s not information you can obtain at any price.
Two practical points on how to do it.
Take your capture first. A host’s response can be abrupt — a scan, a quarantine, files deleted, an account suspended without much notice. That’s their job, and it can destroy evidence you haven’t collected yet. Snapshot, then call. It’s a delay of an hour, not a week.
And ask for specific things, because a generic report gets a generic response — which, in this case, meant files being emptied with no investigation of how they arrived and nobody prompted to change a password.
Ask them to: preserve and extend your log retention immediately; check whether other accounts on the machine show the same indicators; tell you what they change, rather than just changing it; and confirm whether anything was found above your account, where you can’t look.
If the sites aren’t all yours
Worth its own note, because many people reading this manage websites for other people — and many others are the client wondering what their web person owes them.
That wasn’t the situation in this case; every affected domain belonged to the same owner, which is the only reason the whole thing can be published in this much detail. But if a compromised site belongs to someone else, the notification decision arrives long before you have answers, and delaying it until you’re certain is how a technical problem becomes a relationship problem.
The defensible version: tell them early, tell them what you don’t yet know, and tell them what you’re doing about it. “I don’t know yet” delivered on day one costs far less than a complete explanation delivered on day thirty.
Do you tell people?
Separate two things that get confused, because they carry different obligations.
Content was tampered with — your site displayed things you didn’t publish. A reputation problem.
Data was taken — records belonging to people were reachable by someone who shouldn’t have had them. A legal question, and the one that involves the attorney.
Then be honest about proof, because this is where people mislead themselves in both directions.
From the case file. Complete site backups — database included — were sitting in the hosting account during the window the intruders had full file access, and their tooling read files directly off disk.
Opportunity: established. Whether anything was taken: unknown, and probably unknowable — because reading a file with their own tools leaves no log entry at all.
“Nothing appears to have been taken” is not reassurance when the method leaves no trace. Absence of evidence here is genuinely absent, not exculpatory.
Take that to your attorney — not a conclusion, but the actual state of what you know and can’t know. It’s a far more useful conversation than either “we were hacked” or “nothing happened.”
Do you report it?
Yes — and here’s the honest version of what to expect.
File it. Ten minutes. Expect nothing back.
For a small business hit by commodity spam, the loss doesn’t clear any prosecutorial threshold, the operator is offshore, and the infrastructure is rented and disposable. An abuse report to the provider whose address is in your logs may get a server shut down — helping the next victim more than you. A federal report contributes to a pattern nobody will discuss with you.
Neither returns your rankings, your time, or your money.
And it’s worth understanding why, because it isn’t indifference — it’s arithmetic. Look at what they chose not to do. No defacement, no deletion, no ransom. The damage was calibrated to stay below the level where anyone’s response becomes economical. Dozens of domains at mildly annoying each is a business. One destroyed site with a furious owner is a liability.
Aggregate the harm across thousands of victims and it’s enormous. Present it one victim at a time — the only way it’s ever presented — and it never clears the bar.
Ten minutes is a fair price for a lottery ticket. Just don’t build a recovery plan around anyone arriving.
Stay with your host, or move?
Once you’ve told them, their response answers a question you’re going to have to decide anyway.
This one gets framed as technical. It isn’t.
Moving costs hours now — certain, immediate, and yours. Staying costs risk later — uncertain, deferred, and easy to discount. Human beings are extremely bad at that trade, and the bias runs one way: we underpay for deferred risk every time.
So make the deferred cost concrete before you decide. Not “are they a good host” — “what did they do, what did it cost, and what stops it happening again?”
From the case file. When the host’s scanner found the malicious files a month after they were written, it emptied them and left a note saying the danger had been removed. It never investigated how they arrived, and nobody was prompted to rotate the credential. The payload was gone; the access was untouched. The operator walked back in eleven months later through the same door.
Later, a redirect rule created on the hosting side produced a loop that broke the site — and it lived in account settings rather than any file, so it couldn’t be found by examining the website.
That’s the honest ledger. What it’s worth depends on the hours a migration costs you and what those hours would otherwise earn — which is a number only you have.
And there’s a cheaper option than either. Most of what went wrong above is configuration, not hosting. Turning off PHP where it doesn’t belong, extending log retention, auditing what’s enabled by default — those are support tickets, not a migration. Fix the specific failures first, and you’ll know within a month whether the relationship is salvageable.
How much investigation are you buying?
Nobody tells you this is a purchase, so people discover it halfway through, having spent the budget on the wrong question.
There are two jobs here and they cost very differently.
“Is it clean now, and is the door shut?” Bounded. Answerable. What most businesses actually need.
“What exactly happened, when, and to whom?” A different order of work — and on multi-domain shared hosting with expired logs it may be partly unanswerable at any price.
From the case file. One site, logs intact, caught early: days of work. This case — five domains, mixed technology, seventeen months, logs long gone: months of work, three document revisions, six logged corrections. And the entry point is still labelled inferred.
Choosing the cheaper question deliberately is a perfectly good decision. Discovering halfway through that you were never going to get the expensive one is what wastes money. Ask which you’re buying before the work starts.
When do you stop?
Investigations don’t end. They stop being worth continuing, which is different, and nobody tells you when you’ve arrived.
Stop when the next answer wouldn’t change anything you’d do.
That’s the whole test. If knowing precisely which of two mechanisms let them in produces identical remediation either way, the answer has no operational value left — you’re now buying it for peace of mind rather than for the site.
Which is legitimate, and worth naming as a separate purchase.
From the case file. The document behind this series exists for two reasons: the findings feed the work, and the owner wanted the thing to stop turning over at 2am. Both are good reasons. Confusing the second for the first is how people spend three more months on a question that stopped mattering in week two.
And if you’re going to spend the hours anyway
Here’s the one piece of advice in this article that actually recovers value rather than limiting loss.
You will probably overspend on this. Almost everyone does — the instinct to understand what happened to your own property is strong, and it doesn’t switch off when the site comes back up.
So if the hours are going to be spent regardless: make them produce something transferable.
Write it down as you go. Keep the evidence. Turn what you learned into documentation, a process, an article, a way of working — something that exists after the site is clean and that would have value even if this had never happened.
That’s the difference between a cost and an investment, and it’s decided entirely by whether you took notes.
From the case file. Eight months of investigation produced a clean site — which a rebuild would also have produced, in a fraction of the time. It also produced a documented case file, a set of techniques, and this series.
The site was the smaller half of what those hours bought.
What you can do yourself, and what you can’t
You can make every call on this page, and nobody can make them for you. Picking up the phone to your host costs nothing but the hour it takes to snapshot first. Filing the report costs ten minutes. Telling a client “I don’t know yet” on day one is free, and it’s the version that holds up.
What can be delegated is the information underneath those calls — what was reachable, what was actually found, what’s proven versus inferred, and what the host should be asked to check on the machine you can’t see. Good information makes these conversations shorter and cheaper. It doesn’t have them for you.
And the one thing that genuinely needs a professional who isn’t us: the legal question, before you tell anybody anything.
Back: Should You Rebuild Your Website After a Hack?
Every one of these conversations goes better when you can say what happened rather than what you think happened. Establishing that before you have to explain it is worth doing first.
Start a Recovery ReviewPaid assessment · scope agreed up front
Next: Spam Link Tactics → — how a few pages became thousands, why the damage outlives the cleanup, and the removal mistake that makes it permanent.
Hub: Invasion Investigation Blog Series
ProVAE builds and recovers websites in Douglas, Georgia, serving South Georgia.
