Many successful logins at accounts from non -legit countries and IPs
-
Hello guys.
I am running a website with almost 22.000 users at that time. Until a couple of months ago user registration was open because that was the nature of the website.
It’s been a while (almost a year) that Wordfence is logging successful user login attempts for existing users (legit usernames) but from non legit IPs and all sort of countries. All these users are Subscribers so they can’t proceed on doing malicious stuff (i think).
For example yesterday i noticed an IP from a datacenter in Netherlands that Wordfence showed me it had successfully logged in with 5 different usernames. :
All these make me think that perhaps there is is something in my website that can bypass user authentication or their usernames and passwords have been tampered.
Wordfence scan do not show anything of malware
Website is almost updated to the latest versions in core and plugins.
I have disabled XMLRPC.
Can you please provide me with some suggestions on common practices to detect if there is such an issue?
Thank you in advance.
Best
- The topic ‘Many successful logins at accounts from non -legit countries and IPs’ is closed to new replies.