Nobody "hacked" you, you just reused the same password
Imagine you do not have to "crack" anything. It is enough to have a list of millions of logins and passwords that leaked from some shop or forum, and to try them one by one on other sites. That is how credential stuffing works, one of the most effective attacks, because it needs no flaw at all.
Why it works
People use the same password in many places. When one service falls and its password database leaks (and leaks happen constantly), the attacker has a ready key to all your accounts where you used that password, including your site's panel and your hosting.
Bots do this automatically, en masse, day and night. They are not "aiming" at you, they simply comb the internet with a ready list.
Symptoms and risk
Unusual logins, password resets you did not request, posts or changes you did not make. If your panel password matches the one from some old forum, you are in the highest-risk group.
What protects you
- A unique password for every account. A password manager does this for you.
- Two-factor login (2FA): even a known password is not enough to get in.
- A login attempt limit: blocks the bots trying password after password.
- Check your email address in a service that reports data leaks.
This one largely depends on you and is cheap to put in place. And the rest (a login limit, 2FA on the panel) we will happily set up as part of our care service. Reach out.