Skip to content
UK web hosting, domain names, email, website security and online services.

Respond to a compromised reseller customer account Print

  • account, security, malware, reseller
  • 0

Contain one customer without exposing other accounts, rotate credentials and remove the vulnerability before returning the site to service.

Applies to: Reseller migrations, security and support

Migrations, security incidents and account termination can affect customer data. Use written change records, maintain independent backups and confirm authority before destructive actions.

Before you start

  • Sign in with the reseller account rather than a customer SiteWorx login.
  • Identify the affected SiteWorx account, package and domain.
  • Record the current package, DNS and account settings before making a production change.

Work through these checks

  1. Identify the affected SiteWorx account and suspend only that account when immediate abuse or visitor harm requires containment.
  2. Preserve logs and suspicious files and notify Tudor Internet promptly when platform abuse, phishing or malware is involved.
  3. Change the customer’s SiteWorx, FTP, mailbox, database and application credentials through separate secure channels.
  4. Remove unknown users, scheduled tasks, forwarders and persistence and replace compromised software with clean supported releases.
  5. Patch the entry point and review other customer accounts for reused credentials or the same vulnerable package.
  6. Unsuspend only after testing and confirming abuse has stopped.
  7. Give the customer a factual incident summary and required follow-up without disclosing another tenant’s information.

Common problems

SymptomLikely causeWhat to do
A package or SiteWorx account cannot be created.Overselling is disabled and the requested allocation exceeds the reseller plan or a package field is invalid.Compare allocated and available capacity, reduce the package or upgrade the reseller service before retrying.
A customer issue cannot be resolved from SiteWorx.The fault is platform-level, network-level or requires provider permissions.Collect the account, domain, timestamp, exact error and checks completed, then escalate from the reseller account without sharing customer passwords.

When to contact Tudor Internet

Open a ticket through the Customer Portal when the checks above do not resolve the issue, when an action is unavailable for your service, or when continuing could risk data loss or service interruption. Include the following so the request can be investigated efficiently:

  • The reseller service and affected SiteWorx account
  • The package name and current resource use
  • The exact action attempted and error returned
  • Whether the issue affects one or multiple customer accounts
Do not send passwords, private keys, full payment-card details, one-time authentication codes or unredacted identity documents in an ordinary support reply.

Related articles

Last reviewed: 2026-07-18.


Was this answer helpful?

« Back