Responding to a Compromised Account on a Shared Server
When a single account is suspected to be compromised, the response should prioritize containment, evidence retention, and service communication.
Immediate Actions
- Restrict or suspend the affected account if active abuse is occurring.
- Preserve relevant logs and timestamps before broad cleanup begins.
- Reset credentials and review recent file changes for unauthorized additions.
- Check for scheduled tasks, injected scripts, or malicious mail activity.
After Containment
Identify the entry point and close it before restoring normal operation. Cleanup without root-cause analysis often leads to repeat compromise.