CloudLinux

Responding to a Compromised Account on a Shared Server

Published / Updated: 13-Sep-2026

When a single account is suspected to be compromised, the response should prioritize containment, evidence retention, and service communication.

Immediate Actions

  • Restrict or suspend the affected account if active abuse is occurring.
  • Preserve relevant logs and timestamps before broad cleanup begins.
  • Reset credentials and review recent file changes for unauthorized additions.
  • Check for scheduled tasks, injected scripts, or malicious mail activity.

After Containment

Identify the entry point and close it before restoring normal operation. Cleanup without root-cause analysis often leads to repeat compromise.

0%