Available for projects & agency overflow · Quick reply, from the person who does the work

My host has suspended my site for suspicious activity

An email from the host announces a shutdown for "suspicious activity", with no further detail: in the vast majority of cases, the compromised site has become a tool working for a third party, without the merchant's knowledge.

Describe my issue Send a message

The most common wording used by hosts

  • "Mass unsolicited email detected from your account": the outgoing mail server has been used for spam
  • "Abnormal CPU or memory consumption": a script is running continuously on the server, often unrelated to your store
  • "Activity detected participating in an attack against a third-party service": the server is sending requests to other sites, generally without their knowledge or yours
  • "Malicious content detected in account files": an automated scanner has flagged a file known to be malicious
  • "Report received from a third party": another host, an email provider, or a security service has reported activity coming from your IP address

Why the suspension is almost never arbitrary

A shared host runs hundreds, sometimes thousands, of sites on the same physical servers. Abnormal activity on one account, whether mass spam sending, a script consuming disproportionate resources, or outgoing requests to a third-party service, directly threatens the stability of other sites on the same machine and the reputation of the host's IP range with anti-spam services.

That's why the shutdown is almost always automatic and immediate, triggered by an internal monitoring system before a human has looked at the case in detail. The host isn't trying to punish the merchant: it's isolating an account that objectively shows the same signals as a compromised site being used as a relay. On WordPress, this relay usually takes the form of an injected PHP script sending emails through the native mail() or wp_mail() function, or running background tasks via wp-cron.php at an abnormally high frequency.

The entry point that allowed this takeover follows the most common pattern on WordPress and WooCommerce: a plugin or theme that hasn't been updated for a long time, or, more rarely, a flaw in an extension that's actually recent but critical. That's the documented case of CVE-2023-28121 in the WooCommerce Payments plugin, an authentication flaw with a CVSS score of 9.8 affecting versions 4.8.0 to 5.6.1, which allowed an unauthenticated attacker to impersonate any user, including an administrator. The plugin was installed on more than 600,000 sites. The fix, version 5.6.2, was released on 23 March 2023, and Automattic force-installed it on affected sites given the severity of the flaw. Large-scale attacks only began on 14 July 2023, almost four months later, peaking at 1.3 million attempts against 157,000 sites on 16 July 2023 as recorded by Wordfence. Admin access obtained this way gives an attacker everything needed to install the script behind the suspension.

Getting back online properly

  1. Ask the host for the exact technical detail

    The initial message is often generic. Technical support can usually provide precise logs: IP addresses, files involved, volume and recipients of the detected sends.

  2. Identify and remove the responsible script or account

    Without that technical detail, getting back online is a guess, and the suspension typically repeats within days.

  3. Find the entry point before requesting reactivation

    Hosts generally require confirmation that the cause was addressed, not just that the visible symptom disappeared.

  4. Regenerate all passwords and API keys

    A hosting account, WordPress admin account, or API key that was compromised should be treated as exposed even after the cleanup.

Going further

Describe your need in one minute

A few targeted questions so I can reply with an estimate rather than another questionnaire.

symptomes
depuis-quand
sauvegarde
acces-admin (facultatif)
Please provide an email or a phone number so I can get back to you.

Please provide an email or a phone number so I can get back to you.

Frequently asked questions

Will I lose my domain name or my files?
Generally no. A suspension for suspicious activity cuts access or certain services, but the domain name and files remain the account's property, unless hosting itself is unpaid separately.
Can the host reactivate me without me cleaning up the site first?
Some will temporarily on request, but the suspension usually returns quickly if the cause wasn't addressed: it's the same automatic behaviour that triggered it the first time.
How do I know if my IP address has been blacklisted?
Several free online tools check whether an IP address appears on the main anti-spam blacklists. It's worth checking after cleanup, before asking for mail sending to be restored.
Is this necessarily related to a payment extension?
No, that's just a documented example. The most common cause remains an outdated plugin or theme, whatever its function, left without updates for a long period.
What if the host refuses to reactivate the account?
Ask for a detailed written report of the situation before switching hosts: that report is the basis for the diagnosis and avoids carrying the unresolved problem over to the new host.