AI still can’t unhack your site

AI gave you a family of tools to use. It’s not a replacement for a professional.

Last week, I unhacked a website that was actively being wiped as I arrived. Completely wiped. They had gotten complacent and they knew it, and so they thought, lets use AI to bring us up to speed. Sounds great!

Through an unfortunate chain of events, they suddenly needed me. I dropped the book I was reading and ran to my desk to see that when I logged in, files were disappearing in real time. They hadn’t made a backup in too long, and their backup tool had just been deleted.

What had changed? They’d added an AI tool to optimize their site, but that AI tool conflicted with their security software, so they’d deactivated the security without realizing – they had allowed AI to make a management decision–a critical one–whether to be secure. The AI tools they had installed were well meaning. But those opened up his site to vulnerability and now they had a bad actor giving himself root access and deleting everything on the site. Right in front of their eyes, the website vanished. The client was hyperventilating. He almost cried. He was talking about how all of his work was down the drain. (Don’t worry… minutes later, because I’d recognized where the vulnerability was, the damage was contained and the database was back.)

I removed the offending connection and access before it could do any more damage, helped him restore his site, then added a large amount of security. Otherwise there’d be no site today. He only ended up being offline for less than twenty minutes. Our call, including the decompression phase of the call where we just calmed him down, was less than an hour.

The tools that the hacker used? Built with AI. About midway through this process, the client used an AI security tool built into his hosting provider to review his site and found nothing wrong. Hard to find anything wrong with an empty website, I guess.

Everyone out there who values their security needs a good security plugin and a good security consultant who knows how to be smarter than an AI. You need to know when AI is helpful and when you’re about to break everything.

An experienced web professional actually matters.

If you want me to help you with a security review, please get in touch about scheduling. Existing clients go to the front of the list. Again, I’ve got 25 years experience and I’m actually interested in and passionate about what I do. I love helping clients. Also, everything I ever say to you has zero AI involved. I’m real, and I know how to use the available tools the RIGHT ways.

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.