# My host has suspended my site for suspicious activity

> An email from the host announces a shutdown for "suspicious activity", with no further detail: in the vast majority of cases, the compromised site has become a tool working for a third party, without the merchant's knowledge.

- Source canonique : [https://allaux.fr/en/securite/hebergeur-a-suspendu-mon-site](https://allaux.fr/en/securite/hebergeur-a-suspendu-mon-site)
- Langue : EN
- Dernière mise à jour : 2026-09-30

## Direct answer

> Reply to the host and ask for the exact trigger: the path of the file detected, the log excerpt, or the timestamp of the offending send. It is the fastest starting point, and it costs nothing. Do not request immediate reactivation before dealing with the cause — an unchanged account goes back offline, often the same day.

## The most common wording used by hosts

- "Mass unsolicited email detected from your account": the outgoing mail server has been used for spam
- "Abnormal CPU or memory consumption": a script is running continuously on the server, often unrelated to your store
- "Activity detected participating in an attack against a third-party service": the server is sending requests to other sites, generally without their knowledge or yours
- "Malicious content detected in account files": an automated scanner has flagged a file known to be malicious
- "Report received from a third party": another host, an email provider, or a security service has reported activity coming from your IP address

## Why the suspension is almost never arbitrary

A shared host runs hundreds, sometimes thousands, of sites on the same physical servers. Abnormal activity on one account, whether mass spam sending, a script consuming disproportionate resources, or outgoing requests to a third-party service, directly threatens the stability of other sites on the same machine and the reputation of the host's IP range with anti-spam services.

That's why the shutdown is almost always automatic and immediate, triggered by an internal monitoring system before a human has looked at the case in detail. The host isn't trying to punish the merchant: it's isolating an account that objectively shows the same signals as a compromised site being used as a relay. On WordPress, this relay usually takes the form of an injected PHP script sending emails through the native mail() or wp_mail() function, or running background tasks via wp-cron.php at an abnormally high frequency.

The entry point that allowed this takeover follows the most common pattern on WordPress and WooCommerce: a plugin or theme that hasn't been updated for a long time, or, more rarely, a flaw in an extension that's actually recent but critical. That's the documented case of CVE-2023-28121 in the WooCommerce Payments plugin, an authentication flaw with a CVSS score of 9.8 affecting versions 4.8.0 to 5.6.1, which allowed an unauthenticated attacker to impersonate any user, including an administrator. The plugin was installed on more than 600,000 sites. The fix, version 5.6.2, was released on 23 March 2023, and Automattic force-installed it on affected sites given the severity of the flaw. Large-scale attacks only began on 14 July 2023, almost four months later, peaking at 1.3 million attempts against 157,000 sites on 16 July 2023 as recorded by Wordfence. Admin access obtained this way gives an attacker everything needed to install the script behind the suspension.

## A suspension generally doesn't erase anything

> The host blocks access or cuts certain services (mail sending, script execution), but generally keeps the files and database intact. It's an emergency stop, not an account deletion.

## Getting back online properly

1. **Ask the host for the exact technical detail** — The initial message is often generic. Technical support can usually provide precise logs: IP addresses, files involved, volume and recipients of the detected sends.
2. **Identify and remove the responsible script or account** — Without that technical detail, getting back online is a guess, and the suspension typically repeats within days.
3. **Find the entry point before requesting reactivation** — Hosts generally require confirmation that the cause was addressed, not just that the visible symptom disappeared.
4. **Regenerate all passwords and API keys** — A hosting account, WordPress admin account, or API key that was compromised should be treated as exposed even after the cleanup.

## Going further

- **My site is sending emails I never wrote** — The most common symptom preceding a suspension for spam. ([/securite/mon-site-envoie-des-emails-que-je-n-ai-pas-ecrits](/securite/mon-site-envoie-des-emails-que-je-n-ai-pas-ecrits))
- **What to do in the first two hours** — The exact order of priorities once the doubt is confirmed. ([/securite/que-faire-dans-les-deux-heures](/securite/que-faire-dans-les-deux-heures))
- **Hacked WordPress site** — The reference page for an already-identified WordPress hack. ([/wordpress-woocommerce/site-pirate](/wordpress-woocommerce/site-pirate))

## FAQ

### Will I lose my domain name or my files?

Generally no. A suspension for suspicious activity cuts access or certain services, but the domain name and files remain the account's property, unless hosting itself is unpaid separately.

### Can the host reactivate me without me cleaning up the site first?

Some will temporarily on request, but the suspension usually returns quickly if the cause wasn't addressed: it's the same automatic behaviour that triggered it the first time.

### How do I know if my IP address has been blacklisted?

Several free online tools check whether an IP address appears on the main anti-spam blacklists. It's worth checking after cleanup, before asking for mail sending to be restored.

### Is this necessarily related to a payment extension?

No, that's just a documented example. The most common cause remains an outdated plugin or theme, whatever its function, left without updates for a long period.

### What if the host refuses to reactivate the account?

Ask for a detailed written report of the situation before switching hosts: that report is the basis for the diagnosis and avoids carrying the unresolved problem over to the new host.
