Check Point Research disclosed on August 22 that a global cybercrime operation dubbed "StopAndProtect" hijacked 2,000 WordPress websites running outdated software versions to operate malware distribution, data theft, and ransomware campaigns, according to TechRadar. The investigation found 5,000 infected computers globally supporting the distributed criminal infrastructure, which exploited WordPress sites left unpatched for years.
TL;DR: Check Point Research uncovered a cybercrime ring operating through 2,000 compromised WordPress sites running outdated software, using the domains to distribute malware, steal data, and deploy ransomware across 5,000 infected systems worldwide.
Outdated WordPress Versions Enabled Mass Compromise
Check Point researchers identified one compromised site running a five-year-old WordPress core version containing approximately 40 known vulnerabilities, the investigation revealed. The attackers targeted sites where administrators had not implemented regular update cycles, leaving core WordPress installations and third-party plugins exposed to publicly documented exploits. WordPress currently powers 43% of websites worldwide, making it the dominant content management system and a high-value target for attackers seeking distributed hosting infrastructure.

The StopAndProtect operation initially appeared to focus on ransomware distribution when Check Point first documented the threat earlier in 2026, but researchers later determined the infrastructure supported multiple criminal activities. Attackers left evidence of their operations through screenshots and logs of victims, internal tooling artifacts, and configuration files referencing the hijacked domains.
Attackers Used CAPTCHA Prompts to Deploy Malware
"StopAndProtect shows how attackers can turn thousands of poorly maintained WordPress sites into a distributed criminal infrastructure," said Eli Smadja, a researcher at Check Point, in the company's disclosure. The investigation found attackers deployed fake CAPTCHA verification prompts that instructed visitors to copy, paste, or run commands outside their browsers, a social engineering tactic designed to bypass security software and execute malicious payloads directly on victim systems.
The distributed nature of the infrastructure—spreading malicious operations across 2,000 independent WordPress domains—complicated takedown efforts and allowed the operation to persist even when individual sites were remediated. Agencies managing multiple client WordPress installations face compounding risk exposure when update protocols lag across portfolios, as a single unpatched site can serve as an entry point for lateral movement into agency infrastructure.
Security Recommendations for Agency-Managed WordPress Sites
Check Point issued specific guidance urging organizations to immediately leave websites requesting unusual command execution steps and to maintain updated security software. The research team emphasized that agencies should treat unexpected CAPTCHA prompts requiring terminal commands or copy-paste instructions as high-confidence malware delivery attempts. Sites running WordPress versions more than one major release behind current—particularly installations three to five years outdated—require immediate remediation, the researchers indicated.
The investigation highlighted the compounding vulnerability created when both WordPress core and plugin ecosystems fall behind patch cycles. Agencies operating white-label WordPress development services for multiple clients carry direct business risk when maintenance contracts exclude proactive security updates, as compromised client sites can damage agency reputation and trigger liability claims. Recent WordPress plugin security incidents have shown that attackers launch exploits within hours of vulnerability disclosure, narrowing the safe update window for production sites.
WordPress security protocols increasingly require automated monitoring for outdated software versions, particularly for agencies managing dozens or hundreds of client installations. The 40-vulnerability exposure on a single five-year-old installation documented in the StopAndProtect investigation demonstrates how rapidly technical debt accumulates when update disciplines lapse. Standard agency operations should include quarterly security audits identifying signs of outdated WordPress installations across client portfolios.
What Happens Next
Agency operations teams managing white-label WordPress portfolios should immediately audit client sites for WordPress core versions and plugin patch status, flagging any installation running software more than 12 months behind current release. The StopAndProtect disclosure reinforces that security maintenance cannot remain optional in hosting contracts—compromised client sites expose both the client and the managing agency to reputational and legal risk.
WordPress agencies without dedicated security monitoring infrastructure face a decision point: build internal capacity for continuous vulnerability scanning and patch management, or establish partnerships with specialized security providers. The distributed nature of the StopAndProtect operation—spreading across 2,000 independent domains—demonstrates that single-site fixes no longer suffice when attackers target WordPress at ecosystem scale.
Client education protocols should now include explicit warnings about CAPTCHA prompts requesting command execution or copy-paste operations, particularly for non-technical site administrators who may not recognize social engineering tactics. Agencies can reduce portfolio-wide risk by implementing automated update policies for WordPress core and established plugins, while maintaining manual review processes for major version upgrades that may affect custom theme or plugin compatibility.
