The internet box for my client, a dental practice, started showing pills last Tuesday. I called Hetzner where we rent the website space. They say my nephew who set this up did bad security. But my nephew used their one-click install in 2021 and we never touched it since. HETZNER SUPPORT says "outdated plugins" and closed the ticket. I need to prove it was not us for the client meeting. Has anyone gotten forensics from a host that admits fault? I have screenshots of their install page still offering WordPress 5.8 — https://www.hetzner.com/cloud.
Client's WordPress hacked, host blames me
Your nephew probably clicked something. RTFM
---
Signature: have you tried not being hacked?
seedbox, NAS, tape, and three offsite