{"id":11913,"date":"2026-07-06T09:56:42","date_gmt":"2026-07-06T07:56:42","guid":{"rendered":"https:\/\/mybox.com\/help\/?post_type=manual_kb&#038;p=11913"},"modified":"2026-07-06T09:56:47","modified_gmt":"2026-07-06T07:56:47","slug":"why-changing-passwords-is-not-enough-after-a-hack","status":"publish","type":"manual_kb","link":"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-changing-passwords-is-not-enough-after-a-hack\/","title":{"rendered":"Why changing passwords is not enough after a hack"},"content":{"rendered":"\n<div class=\"translation-block translation-block-merged\">\n<p class=\"wp-block-paragraph\">Changing passwords is an important step after a website or hosting account has been hacked. It prevents known credentials from being reused, but it does not remove malicious files, backdoors, unauthorized users, or changes already made inside the website.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This article explains why password changes alone are not enough after a hack, what else should be checked, and why cleanup should focus on both access and damage.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 ez-toc-wrap-left counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-changing-passwords-is-not-enough-after-a-hack\/#What_changing_passwords_does\" >What changing passwords does<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-changing-passwords-is-not-enough-after-a-hack\/#What_changing_passwords_does_not_fix\" >What changing passwords does not fix<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-changing-passwords-is-not-enough-after-a-hack\/#Backdoors_can_keep_access_open\" >Backdoors can keep access open<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-changing-passwords-is-not-enough-after-a-hack\/#Unauthorized_users_may_still_exist\" >Unauthorized users may still exist<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-changing-passwords-is-not-enough-after-a-hack\/#Files_may_have_been_changed\" >Files may have been changed<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-changing-passwords-is-not-enough-after-a-hack\/#Database_content_may_also_be_affected\" >Database content may also be affected<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-changing-passwords-is-not-enough-after-a-hack\/#Email_and_reputation_may_be_affected\" >Email and reputation may be affected<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-changing-passwords-is-not-enough-after-a-hack\/#Sessions_and_tokens_may_remain_active\" >Sessions and tokens may remain active<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-changing-passwords-is-not-enough-after-a-hack\/#What_to_do_after_changing_passwords\" >What to do after changing passwords<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-changing-passwords-is-not-enough-after-a-hack\/#Restore_from_backup_carefully\" >Restore from backup carefully<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-changing-passwords-is-not-enough-after-a-hack\/#Find_the_original_entry_point\" >Find the original entry point<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-changing-passwords-is-not-enough-after-a-hack\/#What_is_normal\" >What is normal<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-13\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-changing-passwords-is-not-enough-after-a-hack\/#When_to_contact_support\" >When to contact support<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-14\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-changing-passwords-is-not-enough-after-a-hack\/#Summary\" >Summary<\/a><\/li><\/ul><\/nav><\/div>\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_changing_passwords_does\"><\/span>What changing passwords does<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<\/div>\n\n<div id=\"mybox-4285256387\" class=\"mybox-content mybox-entity-placement\"><div class=\"early-access-banner-inpost\">\r\n  <div class=\"banner-left-inpost\">\r\n    <div class=\"icon-box-inpost\">\r\n      <img decoding=\"async\" src=\"https:\/\/mybox.com\/help\/wp-content\/uploads\/2026\/02\/square-info-icon.svg\" alt=\"Info\">\r\n    <\/div>\r\n    <div class=\"text-box-inpost\">\r\n      <span class=\"label-inpost\"><span class=\"translation-block translation-block-banner-text\">Early access<\/span><\/span>\r\n      <h4><span class=\"translation-block translation-block-banner-text\">Still need help?<\/span><\/h4>\r\n      <p><span class=\"translation-block translation-block-banner-text\">Contact our customer service team.<\/span><\/p>\r\n    <\/div>\r\n  <\/div>\r\n\r\n  <div class=\"banner-right-inpost\">\r\n    <a href=\"https:\/\/panel.mybox.com\/helpdesk2\/v\/list\/\" class=\"banner-button-inpost\"><span class=\"translation-block translation-block-banner-text\">Message us<\/span><\/a>\r\n  <\/div>\r\n<\/div><\/div>\n\n<div class=\"translation-block translation-block-merged\"><p class=\"wp-block-paragraph\">Changing passwords helps block access through credentials that may have been stolen, guessed, reused, or exposed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This usually includes passwords for:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>the hosting control panel<\/li>\n\n\n\n<li>WordPress or another CMS<\/li>\n\n\n\n<li>FTP or SFTP accounts<\/li>\n\n\n\n<li>database users<\/li>\n\n\n\n<li>email accounts<\/li>\n\n\n\n<li>administrator accounts<\/li>\n\n\n\n<li>connected services<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">If the attacker still has the old password, changing it can stop that specific login path.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_changing_passwords_does_not_fix\"><\/span>What changing passwords does not fix<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A password change does not undo actions that already happened.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If an attacker uploaded malicious files, created a hidden administrator account, modified website code, changed redirects, installed a backdoor, or added spam pages, those changes remain after the password is updated.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The website may still be compromised even if the attacker can no longer log in using the same password.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Backdoors_can_keep_access_open\"><\/span>Backdoors can keep access open<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A backdoor is a hidden method that allows someone to regain access later.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Backdoors can be added to website files, plugins, themes, uploads folders, cron jobs, or configuration files. Some are designed to look like normal files, which makes them harder to notice.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If a backdoor remains in place, the attacker may not need the old password anymore. They may be able to return through the hidden access point.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Unauthorized_users_may_still_exist\"><\/span>Unauthorized users may still exist<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">After a hack, attackers may create new user accounts inside the website or application.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example, in WordPress, a new administrator user may be added quietly. If that user is not removed, the attacker may still have access even after the original passwords are changed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">All administrator and privileged accounts should be reviewed carefully.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Files_may_have_been_changed\"><\/span>Files may have been changed<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A compromised website may contain modified files, injected code, spam content, or malicious scripts.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Common signs include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>unknown PHP files<\/li>\n\n\n\n<li>unfamiliar files in upload folders<\/li>\n\n\n\n<li>modified plugin or theme files<\/li>\n\n\n\n<li>redirects to suspicious websites<\/li>\n\n\n\n<li>spam pages indexed by search engines<\/li>\n\n\n\n<li>unexpected pop-ups<\/li>\n\n\n\n<li>changed <code>.htaccess<\/code> rules<\/li>\n\n\n\n<li>unfamiliar cron jobs<\/li>\n\n\n\n<li>files with unusual names or recent modification dates<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Changing passwords does not remove these files.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Database_content_may_also_be_affected\"><\/span>Database content may also be affected<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Some compromises affect the database, not only website files.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Malicious code, spam links, injected scripts, fake users, changed settings, or unauthorized redirects may be stored in database tables. This is common in CMS platforms such as WordPress, where much of the website content and configuration is stored in the database.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A complete cleanup should include both files and database content.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Email_and_reputation_may_be_affected\"><\/span>Email and reputation may be affected<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If a hacked website was used to send spam or host malicious content, the domain or server reputation may be affected.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Changing passwords does not automatically remove blacklist entries, stop outgoing spam caused by malicious scripts, or repair email reputation. The source of the abuse must be removed first.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">After cleanup, email authentication, mail queues, logs, and blacklist status may need to be reviewed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Sessions_and_tokens_may_remain_active\"><\/span>Sessions and tokens may remain active<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Some applications keep users logged in through sessions, cookies, or access tokens.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If an attacker already has an active session, changing the password may not always end that session immediately, depending on the application. Connected API keys, application passwords, and integration tokens may also remain valid.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">After a compromise, active sessions should be invalidated where possible, and unused keys or tokens should be removed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_to_do_after_changing_passwords\"><\/span>What to do after changing passwords<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Password changes should be part of a larger recovery process.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">After a hack, check the following:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Change all relevant passwords.<\/li>\n\n\n\n<li>Review administrator and privileged users.<\/li>\n\n\n\n<li>Scan website files for malware.<\/li>\n\n\n\n<li>Check recently modified files.<\/li>\n\n\n\n<li>Review plugins, themes, and CMS core files.<\/li>\n\n\n\n<li>Remove unused plugins, themes, and accounts.<\/li>\n\n\n\n<li>Check <code>.htaccess<\/code>, redirects, and cron jobs.<\/li>\n\n\n\n<li>Review database content for injected code or spam.<\/li>\n\n\n\n<li>Update the CMS, plugins, themes, and extensions.<\/li>\n\n\n\n<li>Check file permissions.<\/li>\n\n\n\n<li>Remove unknown FTP, SFTP, database, and email accounts.<\/li>\n\n\n\n<li>Review access logs if available.<\/li>\n\n\n\n<li>Clear website, server, and CDN cache.<\/li>\n\n\n\n<li>Reissue or remove exposed API keys and tokens.<\/li>\n\n\n\n<li>Monitor the website after cleanup.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">The exact steps depend on the application and the type of compromise.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Restore_from_backup_carefully\"><\/span>Restore from backup carefully<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Restoring a backup can help, but it should be done carefully.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A backup is useful only if it was created before the compromise happened. If the backup already contains malicious files or hidden users, restoring it may bring the problem back.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">After restoring a backup, the website should still be updated, scanned, and reviewed for the original vulnerability.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Find_the_original_entry_point\"><\/span>Find the original entry point<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A hacked website should be cleaned, but the original cause should also be investigated.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Common entry points include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>weak or reused passwords<\/li>\n\n\n\n<li>outdated CMS versions<\/li>\n\n\n\n<li>outdated plugins or themes<\/li>\n\n\n\n<li>vulnerable extensions<\/li>\n\n\n\n<li>insecure file permissions<\/li>\n\n\n\n<li>exposed admin areas<\/li>\n\n\n\n<li>compromised devices<\/li>\n\n\n\n<li>unsafe uploaded files<\/li>\n\n\n\n<li>leaked API keys<\/li>\n\n\n\n<li>abandoned test installations<\/li>\n\n\n\n<li>old backups left inside public folders<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">If the entry point remains open, the website may be hacked again even after cleanup.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_is_normal\"><\/span>What is normal<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">It is normal to start with password changes after a hack. This is one of the first containment steps.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It is not enough to stop there. A website can remain compromised through files, database entries, hidden users, active sessions, vulnerable plugins, or exposed tokens.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A clean recovery means both blocking access and removing what was changed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"When_to_contact_support\"><\/span>When to contact support<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Contact support if you suspect a hosting account, website, or mailbox was compromised and you are not sure what was affected.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Include the following details:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>the affected domain or website<\/li>\n\n\n\n<li>when the issue was first noticed<\/li>\n\n\n\n<li>what symptoms were seen<\/li>\n\n\n\n<li>whether passwords were already changed<\/li>\n\n\n\n<li>whether unknown users or files were found<\/li>\n\n\n\n<li>whether the website sends spam or redirects visitors<\/li>\n\n\n\n<li>whether a backup restore was attempted<\/li>\n\n\n\n<li>any security scan results or warning messages<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">This information helps support review the account more effectively and identify whether the issue is related to files, mail, DNS, access, or hosting configuration.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Summary\"><\/span>Summary<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Changing passwords after a hack is necessary, but it only protects against one access path. It does not remove malicious files, backdoors, hidden users, injected database content, active sessions, or exposed tokens.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A proper recovery should include password changes, malware cleanup, user review, updates, log review, and investigation of the original entry point. This reduces the risk of the same website being compromised again.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n<\/div>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"template":"","format":"standard","manualknowledgebasecat":[10],"manual_kb_tag":[],"class_list":["post-11913","manual_kb","type-manual_kb","status-publish","format-standard","hentry","manualknowledgebasecat-safety"],"_links":{"self":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/11913","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb"}],"about":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/types\/manual_kb"}],"author":[{"embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":1,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/11913\/revisions"}],"predecessor-version":[{"id":11914,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/11913\/revisions\/11914"}],"wp:attachment":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/media?parent=11913"}],"wp:term":[{"taxonomy":"manualknowledgebasecat","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manualknowledgebasecat?post=11913"},{"taxonomy":"manual_kb_tag","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb_tag?post=11913"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}