My host has suspended my site for suspicious activity
An email from the host announces a shutdown for "suspicious activity", with no further detail: in the vast majority of cases, the compromised site has become a tool working for a third party, without the merchant's knowledge.
The most common wording used by hosts
- "Mass unsolicited email detected from your account": the outgoing mail server has been used for spam
- "Abnormal CPU or memory consumption": a script is running continuously on the server, often unrelated to your store
- "Activity detected participating in an attack against a third-party service": the server is sending requests to other sites, generally without their knowledge or yours
- "Malicious content detected in account files": an automated scanner has flagged a file known to be malicious
- "Report received from a third party": another host, an email provider, or a security service has reported activity coming from your IP address
Why the suspension is almost never arbitrary
A shared host runs hundreds, sometimes thousands, of sites on the same physical servers. Abnormal activity on one account, whether mass spam sending, a script consuming disproportionate resources, or outgoing requests to a third-party service, directly threatens the stability of other sites on the same machine and the reputation of the host's IP range with anti-spam services.
That's why the shutdown is almost always automatic and immediate, triggered by an internal monitoring system before a human has looked at the case in detail. The host isn't trying to punish the merchant: it's isolating an account that objectively shows the same signals as a compromised site being used as a relay. On WordPress, this relay usually takes the form of an injected PHP script sending emails through the native mail() or wp_mail() function, or running background tasks via wp-cron.php at an abnormally high frequency.
The entry point that allowed this takeover follows the most common pattern on WordPress and WooCommerce: a plugin or theme that hasn't been updated for a long time, or, more rarely, a flaw in an extension that's actually recent but critical. That's the documented case of CVE-2023-28121 in the WooCommerce Payments plugin, an authentication flaw with a CVSS score of 9.8 affecting versions 4.8.0 to 5.6.1, which allowed an unauthenticated attacker to impersonate any user, including an administrator. The plugin was installed on more than 600,000 sites. The fix, version 5.6.2, was released on 23 March 2023, and Automattic force-installed it on affected sites given the severity of the flaw. Large-scale attacks only began on 14 July 2023, almost four months later, peaking at 1.3 million attempts against 157,000 sites on 16 July 2023 as recorded by Wordfence. Admin access obtained this way gives an attacker everything needed to install the script behind the suspension.
Getting back online properly
-
Ask the host for the exact technical detail
The initial message is often generic. Technical support can usually provide precise logs: IP addresses, files involved, volume and recipients of the detected sends.
-
Identify and remove the responsible script or account
Without that technical detail, getting back online is a guess, and the suspension typically repeats within days.
-
Find the entry point before requesting reactivation
Hosts generally require confirmation that the cause was addressed, not just that the visible symptom disappeared.
-
Regenerate all passwords and API keys
A hosting account, WordPress admin account, or API key that was compromised should be treated as exposed even after the cleanup.
Going further
Describe your need in one minute
A few targeted questions so I can reply with an estimate rather than another questionnaire.