
What is phishing and how does it target website owners?
Phishing is a social engineering attack where someone pretends to be a trusted company or person to trick you into handing over passwords, payment details, or access to your systems. For website owners, phishing usually arrives as a convincing email that looks like it came from your hosting company, domain registrar, WordPress, Google, or a payment provider, and it pushes you to log in through a fake page or open a malicious attachment. Once the attacker has your credentials, they can take over your site, your domain, or your email without ever touching a single vulnerability in your code.
Website owners are attractive targets because a single login often unlocks a lot of value: a hosting control panel, a domain that receives email, an admin account with thousands of customer records, or an ad account with a payment card attached. This article explains how phishing works, the specific scams that target people who run websites, how to spot them, and the practical defenses that make you a much harder target.
What Is Phishing?
Phishing is the practice of sending fraudulent messages that impersonate a legitimate sender in order to steal information or get the recipient to take a harmful action. The name comes from "fishing": the attacker casts out bait and waits for someone to bite.
Unlike a brute-force attack or a plugin exploit, phishing doesn't break any technology. It exploits people. The attacker's goal is to create a believable situation, add some pressure, and get you to act before you think carefully.
Most phishing messages try to get you to do one of these things:
- Enter credentials on a fake login page that looks like your host, registrar, or email provider.
- Approve a payment or transfer to an account the attacker controls.
- Download and open a file that installs malware, such as a password stealer.
- Grant access by adding a new user, approving an OAuth app, or sharing an API key.
- Reply with sensitive information like account numbers, backup codes, or server details.
Common Types of Phishing
Phishing comes in several flavors, and website owners run into most of them:
- Bulk email phishing: Generic messages sent to huge lists, such as "Your mailbox is full" or "Your payment failed."
- Spear phishing: Targeted messages that mention your real domain, your hosting company, or your name to look more legitimate.
- Whaling: Spear phishing aimed at owners, founders, or executives who have authority to approve payments or access.
- Smishing and vishing: Phishing via SMS text messages or voice calls, often posing as a bank, host, or support team.
- Clone phishing: A copy of a real email you've received before, with the link or attachment swapped for a malicious one.
- Business email compromise (BEC): Attackers use a hijacked or look-alike email account to request payments or change bank details.
Why Do Phishers Target Website Owners?
If you run a website, you hold several keys that are worth money to criminals. A successful phish against a site owner can give an attacker:
-
Control of the website: With your hosting or WordPress admin login, they can inject spam, malware, or redirects and use your site's reputation to spread further attacks.
-
Control of the domain: Access to your registrar account lets them change DNS, redirect your email, or even transfer the domain away.
-
Access to customer data: Online stores and membership sites hold names, addresses, and order histories that can be sold or used for more targeted phishing.
-
Access to money: Payment gateways, ad accounts, and invoicing systems can be abused directly.
-
A trusted sending platform: Your domain and email reputation can be used to send phishing to your own customers, which is far more convincing than a random address.
Small business owners are frequently targeted because they tend to manage everything themselves, often from one email inbox, without a dedicated IT or security team to double-check suspicious requests.
Phishing Scams Aimed Specifically at Website Owners
General phishing awareness helps, but the scams aimed at people who run websites have their own recognizable patterns.
Fake Domain Renewal and Expiry Notices
These emails claim your domain is about to expire or be suspended and link to a payment page. Some are outright credential phishing pages that mimic your registrar. Others are "domain slamming" scams from companies that try to trick you into transferring your domain to them at an inflated price.
Your registrar's renewal notices will always be visible inside your actual registrar account, so the safe response is to log in directly rather than clicking the email.
Fake Hosting Suspension or Billing Emails
A classic one: "Your hosting account has been suspended due to a billing issue. Log in within 24 hours to avoid data loss." The link leads to a clone of cPanel, Plesk, or your host's customer portal. Once you enter your password, the attacker has full access to your files, databases, and often your email accounts.
Fake WordPress Security Alerts
Attackers send emails that look like they come from the WordPress security team, claiming a critical vulnerability was found on your site and asking you to install a "patch" plugin. The downloaded plugin is actually a backdoor that creates a hidden administrator account.
Remember that WordPress.org does not send individual site owners emails asking them to install patches manually. Core security fixes arrive through normal updates in Dashboard > Updates, and plugin fixes arrive through the plugin repository.
Fake Plugin or Theme License Notices
If you use premium plugins or themes, you may get messages saying your license has expired or been flagged. The link leads to a fake vendor login page, or the email includes a "renewed" plugin ZIP that contains malware.
Copyright and DMCA Threats
These emails claim you've used a copyrighted image and must remove it or face legal action. The "evidence" is a link to a file download or a shared document page that asks you to log in. This scam works because it creates legal fear and urgency at the same time.
Fake Google Search Console or SEO Warnings
Messages claiming "Your site has been removed from Google" or "Critical indexing error" push you to log in with your Google account on a fake page. Real Search Console notifications are always visible inside Search Console itself.
Contact Form and Support Ticket Phishing
Attackers submit your own contact form with a message like "Your site is showing an error on this page, see screenshot," with a link to a malicious file. Because it arrives through your own form, it feels like a genuine visitor report.
Payment Gateway and Marketplace Alerts
Store owners get fake messages from Stripe, PayPal, or marketplace platforms saying a payout is on hold or an account needs verification. The goal is to capture your login and redirect payouts to a new bank account.
How to Spot a Phishing Email
No single sign proves an email is a phish, but a few patterns show up again and again. Train yourself to slow down whenever you notice any of these:
-
Urgency or threats: "Within 24 hours," "final notice," "your account will be deleted." Legitimate companies rarely demand immediate action through an email link.
-
Mismatched sender addresses: The display name says "Your Host Support" but the actual address is from a random or misspelled domain. Always check the full address, not just the name.
-
Look-alike domains: Watch for swapped characters, extra words, or different top-level domains, such as
yourhost-billing.comorwordpress-security.net. -
Links that don't match: Hover over (or long-press on mobile) a link to preview the real URL before clicking. If the text says one thing and the destination is another, stop.
-
Unexpected attachments: ZIP files, HTML attachments, Office documents asking you to "enable content," and PDF files with embedded login buttons are all common delivery methods.
-
Requests that bypass normal process: Asking you to change bank details, share a password, or install a plugin manually is a red flag, especially when it arrives by email.
-
Generic greetings or odd tone: "Dear customer" or strange phrasing can be a clue, though modern phishing is often well written, so don't rely on spelling mistakes alone.
Check Email Authentication Results
Most email clients let you view the original message headers. Look for the Authentication-Results line, which reports whether the message passed SPF, DKIM, and DMARC checks:
Authentication-Results: mx.example.com;
dkim=pass header.d=yourhost.com;
spf=pass smtp.mailfrom=yourhost.com;
dmarc=pass header.from=yourhost.com
A pass for the genuine company's domain is a good sign, though not a guarantee. A fail, or a pass for a completely different domain, strongly suggests the message isn't what it claims to be.
How to Protect Yourself From Phishing
The best defense combines good habits with technical controls, so that even if you do click something by mistake, the damage is limited.
Use a Password Manager
A password manager such as Bitwarden, 1Password, or the one built into your browser only autofills credentials on the exact domain they were saved for. If you land on yourhost-login.com instead of your real host, the manager won't offer to fill anything in. That silence is a powerful warning sign.
It also means you can use a unique, strong password for every service, so one stolen password doesn't unlock everything else.
Turn On Two-Factor Authentication Everywhere
Enable two-factor authentication on your hosting account, domain registrar, email, WordPress admin, payment providers, and any analytics or ad accounts. Two-factor authentication makes a stolen password far less useful on its own.
Be aware that code-based two-factor authentication (SMS or authenticator apps) can still be phished in real time by sophisticated attackers who relay your code instantly. Where available, prefer passkeys or hardware security keys, which are bound to the real website and can't be used on a fake domain.
Go Directly to the Source
Make a personal rule: never log in through a link in an email. Instead:
- Type the URL of your host, registrar, or bank into the address bar yourself.
- Use bookmarks you created for these services.
- Check for alerts inside the real dashboard.
If there's a genuine problem, you'll see it there.
Verify Requests Through a Second Channel
If an email asks you to pay an invoice, change bank details, or grant access, confirm it with the sender through a channel you already trust, such as a phone number from their official website or an existing chat thread. Never use contact details provided in the suspicious message itself.
Protect Your Domain With Registrar Lock
Most registrars offer a transfer lock (sometimes called registrar lock or client transfer prohibited status). Keep it enabled so your domain can't be moved to another registrar without an extra step. Some registrars also offer an additional registry lock for high-value domains.
Publish SPF, DKIM, and DMARC Records
These DNS records don't stop you from receiving phishing, but they make it much harder for criminals to send phishing emails that impersonate your domain to your customers. A basic DMARC record looks like this:
_dmarc.example.com. IN TXT "v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@example.com"
Start with p=none to monitor reports, confirm all your legitimate senders pass, and then move to p=quarantine or p=reject once you're confident.
Keep Your Devices and Browser Updated
Many phishing attacks try to deliver malware rather than steal a password directly. An updated operating system, browser, and email client, plus built-in protections like Microsoft Defender or macOS XProtect, block a large share of these payloads.
Protecting Your WordPress Site From the Fallout
Even careful people get caught occasionally, so it helps to limit what a single stolen login can do on your WordPress site.
-
Use separate accounts for separate jobs: Don't use your administrator account for daily writing. Create an Editor or Author account for content work and keep the admin account for maintenance.
-
Limit the number of administrators: Review Users > All Users regularly and remove admin accounts that aren't needed.
-
Watch for new admin accounts: A security plugin such as Wordfence, Solid Security, or an activity log plugin like WP Activity Log can alert you when a new administrator is created or a user's role changes.
-
Get notified of logins: Many security plugins can email you when an administrator logs in from a new device or location.
-
Keep off-site backups: If an attacker does get in, a recent clean backup stored outside your hosting account makes recovery far easier.
If you want a simple safety net without a plugin, you can add a small custom plugin that emails you whenever a new administrator is created:
<?php
/**
* Plugin Name: Sajjad New Admin Alert
* Description: Emails the site owner when a new administrator account is created.
*/
add_action( 'user_register', 'sajjad_alert_new_admin', 10, 1 );
add_action( 'set_user_role', 'sajjad_alert_role_change', 10, 3 );
function sajjad_alert_new_admin( $user_id ) {
$user = get_userdata( $user_id );
if ( $user && in_array( 'administrator', (array) $user->roles, true ) ) {
sajjad_send_admin_alert( $user );
}
}
function sajjad_alert_role_change( $user_id, $role, $old_roles ) {
if ( 'administrator' === $role && ! in_array( 'administrator', (array) $old_roles, true ) ) {
sajjad_send_admin_alert( get_userdata( $user_id ) );
}
}
function sajjad_send_admin_alert( $user ) {
if ( ! $user ) {
return;
}
$subject = sprintf( '[%s] New administrator: %s', wp_specialchars_decode( get_bloginfo( 'name' ) ), $user->user_login );
$message = sprintf(
"A user was given the Administrator role.\n\nUsername: %s\nEmail: %s\nTime: %s\n\nIf you did not do this, investigate immediately.",
$user->user_login,
$user->user_email,
current_time( 'mysql' )
);
wp_mail( get_option( 'admin_email' ), $subject, $message );
}
Save this as wp-content/mu-plugins/sajjad-new-admin-alert.php (create the mu-plugins folder if it doesn't exist). Must-use plugins load automatically and can't be deactivated from the dashboard, which makes them a good home for small security helpers.
What to Do If You Clicked a Phishing Link
Clicking a link isn't always a disaster, but entering credentials or opening an attachment needs a fast response. Work through these steps:
-
Change the password immediately: Go directly to the real service (not through the email) and change the password for the account you entered. If you reused that password anywhere else, change it there too.
-
Sign out other sessions: Most hosts, registrars, and email providers let you log out all active sessions. In WordPress, go to Users > Profile and click Log Out Everywhere Else.
-
Check and reset two-factor settings: Make sure the attacker hasn't added their own authenticator device, recovery email, or phone number.
-
Review account activity: Look for new users, changed DNS records, forwarding rules in your email, new API keys, or changed payout details.
-
Scan your device: If you opened an attachment, run a full malware scan and consider changing passwords from a different, clean device.
-
Check your website: Look for unfamiliar admin users, unknown plugins, or modified files. If you find signs of compromise, follow a proper hacked-site recovery process.
-
Tell the provider: Report the phishing email to the company being impersonated. Many hosts and registrars have an abuse or security address and will help secure your account.
-
Warn your team or customers if needed: If the attacker could have used your email or site to contact others, a short, honest notice helps prevent a second wave of victims.
FAQ: Phishing and Website Owners
Phishing is when a criminal pretends to be a trusted company or person, usually by email or text, to trick you into giving away passwords, money, or access to your accounts.
Website owners control valuable assets like hosting accounts, domains, customer data, and payment systems. One stolen login can let an attacker take over the site, redirect email, or use the site to attack others.
No. WordPress.org does not email individual site owners asking them to download and install patch plugins. Security updates arrive through Dashboard > Updates and the official plugin repository.
It greatly reduces the risk, because a stolen password alone isn't enough. However, real-time phishing kits can relay SMS or app codes, so passkeys and hardware security keys offer the strongest protection.
A password manager only autofills your login on the exact domain it was saved for. If it doesn't offer to fill in your password, you may be on a look-alike phishing site.
Not always, but you should never act on it through the email link. Log in to your registrar directly to check your domain's real expiry date and renewal status.
Go directly to the real service and change your password, then sign out all other sessions, check your two-factor settings, and review recent account activity for changes.
Conclusion
Phishing works because it targets people rather than software, and website owners are especially valuable targets because a single login can unlock a hosting account, a domain, a store, or a customer list. The scams aimed at site owners, from fake hosting suspensions to bogus WordPress security patches and DMCA threats, all rely on urgency and a convincing disguise.
The good news is that a few habits make a huge difference. Never log in through email links, use a password manager and unique passwords, turn on two-factor authentication (ideally passkeys), verify unusual requests through a second channel, and limit what any single account can do on your site. Combine those with a quick response plan for the day you do click something, and phishing becomes a nuisance rather than a disaster.


