28/12/2023
Dear Laser Hive Customers,
On 18 December, I woke to a security alert from one of my website security programs letting me know that an Administrator had logged into my website at approximately 1 a.m. that morning.
This “Admin” was a hacker and had gained entry to the website through a fake Wordpress security plugin which was uploaded to my website by myself a week earlier when I was fooled in a Phishing attack.
Between the plugin upload and the attack, days later, analysis of my website logs show no other login attempts by the hacker. It looks like the hacker was inside the Wordpress admin area for approximately an hour and page logs show that he/she was mostly interested in finding out what the turnover was from my website. There is no direct evidence that customer information was downloaded by this person, although he did look at one particular customers’ record and I am contacting that person, personally.
When I woke that morning I spent my time identifying the nature of the hack and talking to the Site Providers to get them to delete all trace of the false admin and eliminating any traces of the malware that had given him/her site entry.
The bad news is that while the pages viewed did not show any compromises to customer data, I have to think of the worst possible case and I need to ask you to be vigilant to the fact that your customer email addresses, physical address and phone number could have been leaked from the website records.
Please be reassured that no financial information is ever available from the website as transactions are handled securely offsite by PayPal ( for PayPal transactions) or by Stripe who handle Credit/Debit Card/ApplePay transaction securely.
Some comfort can also come from the fact that the website closed to new orders for the holiday period before the hacker struck.
I have taken the following actions for the future:
1. All Customer data has now been wiped from the data base by me to anonymise past Customer Orders.
2. Previously registered Customers will need to set up a new customer account on the website once I enable that feature again.
3. I have engaged the services of an extra, more proactive, security provider to safeguard further the inherent security of WooCommerce.
A notice is also on the front page of the website repeating the warnings about the website hack and also asking you to watch out for, and report, any suspicious potentially cloned website pages.
Given the possibility of customer contact data from the website having been exposed I ask you all to be extra vigilant. If you suspect that you may have been contacted by someone pretending to be from the Laser Hive then please contact me directly.
This has been a personal shock for me and it will take me a little time before I have the confidence to want to re-launch. For that reason the selling website will not now open for orders on 4 January, but will stay shut to web orders until I have the full confidence to proceed with it.
The wonderful customers that I have are supremely important to me and I am distraught that customer data could have been exposed in this way.
My sincere and humble apologies for any inconvenience this may cause you.
PLEASE NOTE THAT DUE TO THE AMOUNT OF WORK INVOLVED IN NOTIFYING PEOPLE, I WILL NOT BE USING THIS POST TO RESPOND HERE - SO IF YOU NEED TO TALK TO ME THEN PLEASE SEND A DM OR EMAIL. THANK YOU.