Card skimmer removed in 9 hours, root cause closed in 6 days
A multi-store WooCommerce group was silently exfiltrating checkout fields through a modified mu-plugins loader. Their scanner reported the estate as clean for eleven weeks.
We traced entry to a licence-check callback in a nulled premium theme, contained the same day, rebuilt the affected hosts from known-good images, and rewrote their deployment so that no writable path is ever executable again.