Skip to main content

Digital Dialogue

Founder, CEO
Date: 08 October 2026
Follow Us

What Happens When an Attacker Gets Past MFA?

Multi-factor authentication (MFA) is one of the most effective ways to protect business accounts. But what happens when an attacker manages to get past it?

Imagine an employee receives an email that appears to come from a trusted service. They click the link, enter their username and password, and are asked for their usual authentication code.

Everything looks familiar. Unfortunately, the website is fake, and the attacker may now have enough information to access the account.

One layer of security has been bypassed. What happens next?

MFA is important, but it is not complete protection

Multi-factor authentication adds an essential layer of protection to business systems, email accounts, website administration panels and online services.

Even when passwords are stolen, MFA can prevent unauthorised access. However, attackers increasingly use phishing, fraudulent login pages and social engineering to trick users into completing authentication requests.

Some attacks can even capture authenticated sessions, allowing criminals to gain access without needing to enter another MFA code.

This does not mean businesses should stop using MFA. Quite the opposite. It means MFA should form part of a broader security strategy rather than being treated as the final line of defence.

Website security requires multiple layers of protection

At Cartmell & Cartmell Communications, we have worked with business websites, hosting environments and content management systems since 2002.

Our experience with WordPress, Joomla and website hosting has shown us that security cannot depend on a single password, plugin or security application.

A secure website requires ongoing attention to software updates, server configuration, access controls, backups and suspicious activity.

For example, even when a website administrator uses MFA, an outdated plugin or vulnerable website extension could provide attackers with another way into the website.

Protecting the login page is important, but protecting the entire website environment is equally important.

What happens when an attacker gains access?

Consider a situation where an attacker successfully obtains the login details of a website administrator or business email account.

Once access is gained, the attacker may attempt to:

  • Change administrator passwords or create additional user accounts.
  • Install malicious WordPress plugins or Joomla extensions.
  • Modify website files or inject malicious scripts.
  • Redirect visitors to fraudulent websites.
  • Access sensitive customer or business information.
  • Use compromised email accounts to distribute phishing messages.
  • Exploit the hosting environment to attack other websites.

The extent of the damage depends on the permissions available to the compromised account and the security controls already in place.

This is why restricting administrator access, monitoring website activity and maintaining reliable backups are essential.

How Cartmell helps protect WordPress and Joomla websites

Our approach to website security focuses on prevention, ongoing maintenance and recovery.

We provide practical website management and hosting services designed to reduce common vulnerabilities and help businesses maintain a secure online presence.

1. WordPress and Joomla security updates

Outdated website software remains a common security risk.

Our website maintenance services include updating WordPress and Joomla core software, themes, templates, plugins and extensions.

Keeping these components updated helps address known vulnerabilities that attackers may exploit.

We also recognise that updates need to be managed carefully to avoid compatibility issues and unnecessary website downtime.

2. Website security configuration

We use established security tools and appropriate configuration settings to strengthen WordPress and Joomla websites.

Depending on the website and hosting environment, this may include:

  • Akeeba Admin Tools Professional configuration.
  • Administrator access restrictions and login protection.
  • File and directory permission checks.
  • Security header configuration.
  • Protection against common automated attacks.
  • Reviewing suspicious files and website activity.

These measures help reduce the number of opportunities available to attackers.

3. Cloudflare and malicious traffic protection

Not every attack starts with a stolen password.

Websites are regularly targeted by automated bots, malicious requests, login attempts and vulnerability scanners.

Where appropriate, we configure Cloudflare security features to help filter unwanted traffic before it reaches the hosting server.

This can include web application firewall rules, bot protection and restrictions on commonly abused endpoints such as WordPress XML-RPC.

Filtering malicious traffic can also help reduce unnecessary server load and improve website availability.

4. Website backups and recovery

No security solution can guarantee that a website will never be compromised.

That is why reliable backups form an important part of website management.

Our maintenance services include backup solutions using tools such as Akeeba Backup Professional, with external backup storage where configured.

Backups provide an important recovery option if website files are damaged, deleted or compromised.

However, a backup is only useful when it is available, uncompromised and can be successfully restored.

5. Website monitoring and maintenance

Website security is not a once-off installation.

Software changes, new vulnerabilities are discovered and attackers continually adapt their methods.

Our ongoing WordPress and Joomla maintenance services help businesses stay on top of updates, website availability, security checks and maintenance requirements.

Where included in the service, we provide website monitoring and regular maintenance reporting.

Why website security should not depend on one plugin

Installing a security plugin is a sensible step, but it does not automatically make a website secure.

A security plugin cannot compensate for every weakness in outdated software, poor passwords, excessive administrator permissions or an incorrectly configured hosting environment.

Likewise, a secure hosting server cannot protect a website from every vulnerability introduced by third-party plugins or extensions.

Effective website security requires several controls working together.

For businesses using WordPress or Joomla, this means combining regular maintenance, security configuration, controlled access, backups and monitoring.

Don't overlook the people managing your website

Technology is only part of the security picture.

Website administrators, employees and external developers often have access to important business systems.

Phishing emails and fraudulent login pages can appear convincing, even to experienced users.

Rather than relying entirely on employees to recognise every threat, businesses should limit the damage that compromised credentials could cause.

Practical steps include:

  • Enabling MFA wherever supported.
  • Using unique passwords and a reputable password manager.
  • Providing individual administrator accounts rather than sharing logins.
  • Removing access when employees or developers no longer require it.
  • Limiting user permissions to what is necessary.
  • Reviewing website administrator accounts regularly.
  • Training employees to recognise suspicious login requests.

What should you do if your website is compromised?

If you suspect that someone has gained unauthorised access to your WordPress or Joomla website, acting quickly can help limit further damage.

Important first steps include:

  1. Restrict suspicious access and preserve relevant logs or evidence.
  2. Change compromised passwords from a trusted device and revoke affected sessions.
  3. Review administrator accounts and remove unauthorised users.
  4. Investigate suspicious website files, plugins and extensions.
  5. Check whether website or customer information may have been exposed.
  6. Identify and address the vulnerability before restoring normal access.
  7. Restore from a verified clean backup when necessary.
  8. Review the incident and improve security controls to reduce the risk of recurrence.

Depending on the nature of the incident, businesses may also need to notify affected customers or comply with applicable data protection requirements.

The real question is what happens when security fails

Instead of asking only whether your business has MFA enabled, consider these questions:

  • When were your WordPress or Joomla plugins last updated?
  • Are unused plugins, extensions and administrator accounts removed?
  • Is your website protected against common automated attacks?
  • Do you have reliable backups stored separately from your website?
  • Would you know if your website suddenly became unavailable?
  • Who is responsible for investigating suspicious website activity?
  • How quickly could your website be recovered following an attack?

These questions help identify gaps that are often overlooked when businesses rely on individual security products.

Website security is an ongoing responsibility

At Cartmell & Cartmell Communications, we believe website security should be practical, proactive and part of everyday website management.

Whether your business operates a small WordPress website, a WooCommerce online shop or a more complex Joomla platform, regular maintenance and layered protection can significantly reduce your exposure to common threats.

Our services cover WordPress and Joomla website maintenance, security configuration, hosting, backups, troubleshooting and ongoing website management.

The objective is not to promise that an attack will never happen. It is to reduce the likelihood of an incident and improve your ability to respond and recover when something goes wrong.

Need help securing your WordPress or Joomla website?

Cartmell & Cartmell Communications provides website maintenance, hosting and technical support for businesses across South Africa.

Whether you need assistance securing an existing website, managing software updates or recovering from a website security incident, we can help you assess the next steps.

Contact Cartmell & Cartmell Communications to discuss your website security and maintenance requirements.