WP Engine

Solutions
AgencyEnterpriseSmall & Medium BusinessMarketer
How WP Engine supports marketers.Benefits for marketers.Features that help you innovate.
Developer
How WP Engine supports developers.Benefits for developers.Features that help you move faster.
Explore Our Platform
Insights
Thought LeadershipTopics

Read articles, trends, and insights on these topics from leaders in marketing and technology.

Creative AgilityEnterprise PerformanceActionable IntelligenceEcosystem Integration
Resources

Access ebooks, whitepapers, webinars, and other knowledge from our ecosystem of digital experts.
Visit Resource Center.

Delivering a Slam Dunk Experience on WordPressEbook: The Ultimate Guide to WordPress Plugins15 Common WordPress Mistakes Agencies and their Clients Make
Case Studies
About
Our CompanyOur PlatformLatest News

Access the latest news from inside WP Engine.
Visit the Newsroom.

WP Engine Secures Strategic Growth Investment From Silver LakeWP Engine Unveils First WordPress Digital ExperienceWP Engine Expands Global Presence with New Office in Brisbane
Media Center

Get announcements and resources about WP Engine.

Press Releases
Careers at WP Engine
Pricing
Sales Questions?

Contact Sales

Discover why organizations of all types and sizes choose WP Engine — and how it can benefit you.

Chat

1

I'm available right now to answer any of your questions!

Reply

Call

+1-512-201-4819

Contact

Send a message

Compare Plans
Need Support?
Support DocumentationBilling HelpSupport

We offer support 24 hours a day, 7 days a week, 365 days a year. Log in to get expert one-on-one help.

Log in for support

Sales Questions

Contact Sales

Discover why organizations of all types and sizes choose WP Engine — and how it can benefit you.

Chat

1

I'm available right now to answer any of your questions!

Reply

Call

+1-512-201-4819

Contact

Send a message

Sign in
Sign in
Search

Search

Compare Plans
Call Sales +1-512-201-4819
Menu
AgencyEnterpriseSmall & Medium BusinessMarketers
How WP Engine supports marketers.Benefits for marketersFeatures that help you innovate.
Developers
How WP Engine supports developers.Benefits for developers.Features that help you move faster.
Our PlatformPricingResource CenterOur CompanySolution CenterThought LeadershipDocumentationCareers

Update on Recent Security Attacks

Austin Gunter 4.12.2013

Many of you have heard about the recent attacks on WordPress sites. As Sucuri Security has documented, many hosts are experiencing a dramatic increase in brute force attacks on their WordPress customers.

In many regards, being prepared for attacks like this is part of the responsibility that any WordPress hosting takes on in the day to day running of a business. And WP Engine has gone to great lengths to ensure that we are prepared for just such situations as this one. These attacks have been well-documented and intentional. Whoever is behind the attacks is doing a good job, and they’ve gotten attention as a result.

There are a number of bad IP addresses that are currently involved in the attacks (although these may not represent all locations the attacks are originating). One of our WordPress experts has folded Sucuri’s list of the addresses into an .htaccess file that you can run on your own self-hosted account, and that we want to make as widely available as possible. Naturally, WP Engine takes care of this sort of thing so our clients don’t need to upload the .htaccess file.

At this time, WP Engine customers continue to be well-protected. We’re keeping a vigilant eye on the behavior and attack patterns, and will provide updates if things do change. It’s important to always respect a coordinated effort like this. However, at the present moment, our security measures are responding as intended to the attacks and protecting your sites.

Thanks for choosing WP Engine!

More WordPress news from WP Engine

Finely Tuned Consultant – Joel GoodmanUpdate on The Friday Linode Event

Comments

  1. Nirave says

    April 12, 2013 at 6:28 pm

    Great to hear!!

    Reply
  2. Jim Walker says

    April 12, 2013 at 6:31 pm

    Yes, notes on on this posted here as well, http://goo.gl/i0ahb

    Reply
  3. Phil Simon says

    April 12, 2013 at 6:31 pm

    Another reason to love you guys. Like anything else in life, if you want more, you have to pay more.

    Reply
  4. Devin Walker says

    April 12, 2013 at 7:02 pm

    I haven’t noticed any slowdown with my site on WPE… you guys are on top of this ish.

    Reply
  5. Jaki says

    April 12, 2013 at 8:20 pm

    Thanks!!

    Reply
  6. Michael Cabral Poubel Bastos says

    April 12, 2013 at 8:25 pm

    I put together a version that works the same way for Nginx, in case there are any fans in the audience…

    https://gist.github.com/bastosmichael/5376293

    Reply
  7. Rob says

    April 12, 2013 at 10:09 pm

    Awesome. Love not having to worry about this on a Friday. Thanks WPEngine!

    Reply
  8. Debi Block says

    April 13, 2013 at 10:40 am

    And this is exactly why I moved to wpengine. I was a victim of such attacks this week. My old host did their best at mitigating the issue and I commend them. But they were not prepared. Nor do they provide backups or restore points if your site is trashed.

    Reply
  9. Ryan says

    April 13, 2013 at 4:04 pm

    Great job guys! When I read about the attack being so calculated I knew that having a host that was as equally prepared to handle such attacks is a huge plus. Thanks for keeping us informed, too!

    Reply
  10. Eli Israel says

    April 14, 2013 at 11:19 am

    We are considering adding a two-factor authentication mechanism (Duo Security) to our site.

    Would this be a hassle for the WPEngine team? Do you recommend 2FA for some sites? Thanks.

    Reply
  11. Jason says

    April 15, 2013 at 9:38 am

    My site is currently hosted elsewhere and was hit by this attack over a week ago. When I think of how this impacts business, I would much rather be paying $30 a month and still have my site up and running, versus $7 a month and have it non-functional for a week and counting. I can’t even uninstall WordPress because they’ve taken away the ability to access the site. If there is a way to migrate my domain name over to WP Engine, I’m hoping to do so. Then at least I can start over and reload my site from clean copies of my files.

    Reply
  12. Richard Bohn says

    April 16, 2013 at 2:25 pm

    Should we use the Login Lockdown plugin?

    Are there any other security plugins that you WPEngine folks recommend?

    Thanks, Rich Bohn

    Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • Subscribe

    Subscribe to our blog to get great tips for your WordPress site.

  • Favorite Tweets by @wpengine
  • Sign In

    Solutions

    • Agency
    • Enterprise
    • SMB
    • Marketer
    • Developer

    Insights

    • Blog
    • Torque
    • Velocitize

    About

    • Our Company
    • Leadership Team
    • Our Platform
    • Careers
    • Affiliates
    • Contact
    • Legal
    • Newsroom
    • Privacy Policy

    Resources

    • Resource Center
    • Documentation
    • Solution Center
    • Find an Agency

    WP Engine

    504 Lavaca Street, Suite 1000
    Austin, TX 78701

    Sales

    +1-512-201-4819
    [email protected]
    7am–7pm CST

    Billing

    [email protected]

    • Facebook
    • Twitter
    • LinkedIn
    • YouTube
    • Instagram
    • RSS
    © 2013—2026 WPEngine, Inc. All rights reserved.
    WP ENGINE®, VELOCITIZE®, TORQUE®, EVERCACHE®, and the cog logo service marks are owned by WPEngine, Inc.