Cyber Attack From A Known Website

By: Ben Fielding | Estimated Reading Time: 3 minutes

What Your Business Can Learn From It


You expect dodgy links in emails or random pop-ups to be risky. But what if the danger comes from a website you trust?

One of our clients recently had a close call. A member of their team went to book a venue for a company event. They had used this venue before and had a great relationship with them. It was a well-known business with a professional website. Everything looked normal at first. The web address was correct. The landing page looked familiar, but something was off. The design seemed broken, like the page had not fully loaded.

Still, they carried on.

They clicked on the booking link and were met with a Captcha request. You know the ones. “Click here to prove you’re human.” It looked normal too. But after clicking “Verify,” a new window popped up with strange instructions.

It told the user to copy a code
Open the Windows Run box (by pressing Windows + R)
Paste the code
And press OK

It all seemed a bit odd. But the instructions looked official. The user nearly followed them.

What they did not realise was that this code would hijack a legitimate Windows process called mshta.exe. In the background, it would try to install malware and gain admin access to their system.

This is where the story could have gone very wrong.
But it didnโ€™t.


How SentinelOne and Nxt Gen IT Saved the Day

Thankfully, our client had SentinelOne Endpoint Detection and Response (EDR) running on all devices. As soon as the malware tried to hijack the process, SentinelOne blocked it.

It killed the process immediately
Prevented any changes to the system
And sent us an instant alert

Our techs jumped on it straight away. We called the user to walk through what had happened, made sure no other steps had been taken, and ran a full check on the device. Everything was clean. No damage was done.

We also contacted the venue. At first, we got a recorded message saying, “We are currently experiencing issues with our website.” That confirmed our suspicions. When we eventually spoke to someone, we explained what we had seen and shared advice on how to secure their site and get help resolving it.


The Bigger Lesson: Trusted Sites Can Be Hacked Too

The most important part of this story is this:

  • It was a legitimate website
  • From a trusted business
  • That had been used before

The attackers had found a weakness in the venueโ€™s website and used it to trick people who trusted it. This is more common than many people think.

Hackers do not always build fake sites. Sometimes, they go after real websites that have poor security or outdated software.


What You Can Do to Protect Your Business

1. Use EDR software like SentinelOne
It stops threats in real time and gives your IT team the visibility to act fast.

2. Train your staff to pause and ask questions
In this case, the user ran a strange command. Encourage your team to stop and check if anything feels off.

3. Keep websites fully patched
If you run a website, make sure it is up to date. That includes
All plugins and modules
Content management systems like WordPress or Joomla
Any third-party code or integrations

Out-of-date software is one of the easiest ways in for hackers.

4. Use security monitoring on your website
Even small businesses can now use tools that alert them when something changes on their site. This helps spot issues before customers do.

5. Regularly test your systems
Penetration testing, vulnerability scans, and patch audits are not just for big companies. They are key for spotting holes before someone else does.


Nxt Steps

This could have been a disaster. But with the right systems in place and a fast response from our team, nothing was lost. No data stolen. No systems infected.

It was a close callโ€”and a reminder that good cyber security is not just about avoiding obvious scams. It is about expecting the unexpected and having tools that step in when people make honest mistakes.

If you are not sure whether your systems could handle something like this.
Or if your website is up to date and secure.
Letโ€™s talk

We will help you spot the gaps before someone else finds them.