Table of contents
- When did the wave of website hacks begin?
- Why have website hacks increased?
- Are only Joomla websites being hacked?
- When will website hacking stop?
- What are the possible consequences of a hack?
- What should website owners do now?
- Which websites fre in the highest-risk groups?
- Security measures
- We can do everything for you
Anton Majoroff here. Few people could have failed to notice the increased hacker activity targeting Joomla websites since the spring of 2026. Why have websites suddenly become frequent targets, and how long will this continue? Is Joomla the only platform affected, or are others suffering as well? What should you do to prevent your website from being hacked again? Let’s take a closer look.
When did the wave of website hacks begin?
Starting in April 2026, we began receiving one report after another about hacked Joomla websites. Attackers deleted the website’s file system and uploaded a new WordPress website in its place. In some cases, the consequences were irreversible because no backups were available.
It all began when one or more attackers started carrying out mass attacks by exploiting a vulnerability in the Tassos Framework plugin, which is required for extensions developed by tassos.gr. Some of the most popular extensions using it include:
The developer patched the vulnerability back in February 2026, announced it by email and published a post about it on the company blog. But who cares about any of that? Updates, patches and other unnecessary complications. If the website works, what else could you possibly need? That was how almost everyone thought until the very last moment, and many people still think the same way. As a result, every website running outdated Tassos extensions was caught in the crossfire.
I assume the attackers were so encouraged by their success that they moved on to discovering vulnerabilities in other popular extensions, followed by numerous new hacks. Some of the best-known extensions that proved unsafe for websites included:
- JCE
- SP Page Builder
- Helix3
- Helix Ultimate
- AcyMailing
These are all extremely popular extensions created by developers who have earned the trust of a large number of users over many years. There is little doubt that hackers will eventually get to less popular extensions as well and will inevitably identify and punish websites that use them.
Why have website hacks increased?
The recent rise of neural networks is turning the IT market upside down in many different ways. Artificial intelligence simplifies certain processes to such an extent that some professions and even entire fields of work have almost disappeared. For example, many managers have wondered why they should employ a copywriter when a neural network can generate a high-quality, unique text of almost any length within minutes. Copywriters are probably suffering more than anyone else right now. But this article is not about them. It is about AI as an extremely effective tool that can increase the productivity of certain IT professionals by tens or even hundreds of times. This includes programmers, and hackers are programmers too — who would have thought it, but yes, hackers are malicious programmers. In the past, a hacker could spend an enormous amount of time searching for a vulnerability in the code. Today, a good prompt and a few minutes of waiting may be enough. After that, an automated system can punish every unfortunate website that happens to use the vulnerable extension.
In other words, AI is extremely effective at helping hackers compromise websites built with open-source software, including Joomla websites. Nothing prevents an attacker from downloading popular extensions one after another, scanning them for poorly written code using a specially trained neural network and then creating exploits just as easily.
Can we say that AI itself is the cause of these attacks? I would not say so. The real cause is poor-quality source code. AI merely makes such code easier to discover, and attackers are now taking full advantage of that opportunity.
Are only Joomla websites being hacked?
Of course not. Websites running any open-source CMS are being targeted. This includes all free CMS platforms, such as WordPress, OpenCart, Drupal and many others. In fact, the more popular a CMS is, the more websites running it are hacked. To Joomla’s credit, security patches for the core system are released regularly, and there have not yet been any security flaws in Joomla itself that resulted in widespread mass hacking. The critical problems are found primarily in third-party extensions created by individual developers.
When will website hacking stop?
Many websites have fallen victim to the circumstances, but their sacrifice should not be in vain. Measures taken by developers and website owners will reduce the number of successful attacks, but hackers will never stop trying. Anyone who fails to take steps to secure their website risks losing it.
Developers will have to take the security of their extensions more seriously if they want to avoid reputational damage or even legal liability for security breaches. After all, there is nothing stopping developers from using AI for legitimate purposes to improve the quality of their code. Those who genuinely care about the outcome of their work are already doing so.
Website owners, meanwhile, will have to stop neglecting the condition of their websites, especially when it comes to keeping the software up to date.
What are the possible consequences of a hack?
A website hack can result in serious financial and legal consequences, as well as reputational damage, not to mention a considerable headache. Even if you are lucky enough not to lose the website completely, the consequences can still be critical. For example, the personal data of registered users may be leaked, including payment information.
What should website owners do now?
You should no longer rely on the hope that “it probably won’t happen to me.” Any vulnerable website will be hacked sooner or later. Given the current situation and modern technology, it will probably happen sooner rather than later. To help avoid the consequences of an attack, I will list the main steps that should be taken immediately. First, let us determine which websites are the most vulnerable.
Which websites fre in the highest-risk groups?
Many website owners naively assume that hackers have no interest in their small one-page website and would have no reason to attack it. In reality, every website is at risk. As we know, even the Pentagon’s websites have been hacked. Our task is to assess the risks and reduce them as much as possible. The following websites belong to the main risk groups:
- Websites without a configured backup system.
- Websites using extensions with known vulnerabilities.
- Websites using pirated versions of extensions.
- Websites with a large number of third-party extensions.
- Websites running Joomla 4 or an earlier version.
- Websites without additional security measures.
These groups are not mutually exclusive. The more groups your website belongs to, the greater the risk of it being hacked.
Websites without backups
Without backups, even an attempted update can break the entire website without any possibility of restoring it quickly. If the website is hacked, you may as well consider it lost.
Backups should therefore be created:
- automatically using server or hosting tools,
- regularly in remote storage using Akeeba Backup Pro,
- before every Joomla CMS or extension update.
Each of these options can prevent headaches caused not only by hacking, but also by website failures following updates.
Websites using vulnerable extensions
We are specifically referring to known vulnerabilities in the following Joomla extensions:
- JCE
- SP Page Builder
- Helix3
- Helix Ultimate
- AcyMailing
- Quix
- RSFiles
- Balbooa Forms
If your website uses any of these extensions and you have not updated anything for a long time, it has most likely already been affected. If you are lucky and there are no visible signs of hacker activity — although this does not guarantee that the website has not been compromised — you should update at least these extensions immediately. However, if the website has already been hacked, updating extensions on an infected website will not solve the problem. If there is no backup created before the attack, you can try to clean the website, but depending on the severity of the infection, this may be extremely difficult or even impossible.
Websites using pirated extensions
Commercial Joomla extensions offered free of charge on any resource other than the official developer’s website are highly likely to contain malicious code. The advice here is simple:
- choose a free extension from the developer’s official website rather than a paid extension downloaded free of charge from a public website;
- if you are unsure whether a paid extension will suit your needs, check whether the developer offers a refund policy;
- when you purchase an extension from its developer, you contribute to its continued development.
Websites with a large number of extensions
A website may run Joomla 5 or 6, but that does not guarantee its security if its extensions are not updated. The more third-party Joomla extensions a website uses, the greater the risk of it being hacked. If one extension does not contain a major security flaw, another one may. Keeping third-party extensions up to date therefore reduces the risks considerably.
Websites Running Joomla 4 or Earlier
Joomla 4 has not received any updates since 2025. Joomla 3, which still powers the majority of websites, is an entirely separate risk group. Websites running these versions often carry megabytes of unnecessary code in the form of third-party extensions that even their own developers may have forgotten about. Hackers, however, may remember them, find a security hole and exploit it.
Websites without additional security measures
If a website runs the latest version of Joomla, its extensions are updated promptly and a backup system is configured, the risk of hacking is already minimal. Nevertheless, some risks remain:
- If a hacker deliberately decides to target your particular website, they will examine it from every possible angle and may find a weak point.
- A hacker may discover a vulnerability in a third-party extension and exploit it before a security patch becomes available.
- In addition to specific CMS and extension vulnerabilities, there are many other attack methods, including password guessing.
Security measures
Security measures for a website can be broadly divided into essential and additional measures.
Essential measures
These measures should ideally have been implemented on existing websites yesterday, and they should never be forgotten when creating new websites:
- Regular automated backups, including backups stored in remote file storage.
- Running the website on a current Joomla version that continues to receive security updates. At the time of writing, these are Joomla 5 and Joomla 6.
- Keeping the number of third-party extensions to a minimum and completely uninstalling unused extensions.
- Regular and timely updates of all third-party extensions in use.
Additional measures
If some malicious individual decides to target your website specifically, additional measures may save the day:
- Two-factor authentication for access to the administration panel.
- Hiding the administration login page from attackers by adding a GET parameter to its URL.
- Generating the server configuration files .htaccess and nginx.conf with additional security rules for the website’s files and directories.
- Using a Web Application Firewall to prevent SQL injections, malicious file uploads, cross-site scripting and similar attacks.
- Periodic automated scanning of the website files and the entire server for malicious code.
What is required to implement these measures?
- A professional approach: it is important to understand what needs to be done and in which order.
- Time for updates and for testing the website’s functionality after those updates.
- Financial investment in commercial extensions.
We can do everything for you
If everything listed above seems too complicated, if you simply do not want to spend your time on it or if you would like to save money on expensive extensions, we are ready to help:
- update your website to the latest Joomla version together with all extensions used on it;
- audit the installed extensions and then remove those that are not being used;
- configure website backups, including backups to remote storage;
- install licensed versions of popular extensions on your website;
- protect your website from hacking by implementing additional security measures;
- take your website under our wing by regularly updating the CMS and all extensions, including commercial ones.
Terms used:
AcyMailing, Akeeba Backup, Extension, CMS, SQL, XSS, Authentication, Backup, Balbooa Forms, Convert Forms, Engage Box, Google Structured Data, Helix Ultimate, JCE, SP Page Builder