An Online Shop Was Fined €20,700 After a Cyberattack
Web Security
· 9 min read
The fourth online shop fined by ANSPDCP in 12 months following a cyberattack. Seven in ten Romanian entrepreneurs admit they took no additional security measures. Would your website survive the same inspection?
On 27 June 2026, Romania's data protection authority ANSPDCP announced the conclusion of an investigation at Homelux SRL — an online shop specialising in furniture and home décor. The company was fined €20,700 following a cyberattack and irregularities regarding the security of users' personal data.
This is not an isolated case. It is the fourth online shop fined by ANSPDCP in the past 12 months following a cyberattack.
In September 2025, PRIMONET RO SRL was fined €20,000 after customers discovered money missing from their cards following a cyberattack. Also in September 2025, Vellea Home SRL received a €5,000 fine after customer personal data was accessed without authorisation. In November 2025, Greencorp SRL was sanctioned with €3,000 following a similar incident.
Why This Is Happening — and Why It Will Happen More Often
More than 70% of companies in Romania are directly exposed to cyberattacks, according to a study by Frames and Infosec Center published on 6 July 2026. In 2024 alone, over 27 million cybersecurity events were recorded at national level.
A barometer conducted between 30 June and 2 July 2026 shows that seven in ten entrepreneurs admit they have not taken additional security measures, 53% rely on IT teams and classic software protection, and 87% of companies have no special protocol for managing cybersecurity incidents.
The DNSC director warned in July 2026 that Romania is under constant pressure from cyberattacks, including from state actors, and the DNSC quarterly bulletin for Q1 2026 shows that Romania remains a constant target, especially in the context of hacktivist attacks and vulnerabilities in the SME sector.
But there is one detail that completely changes the perspective. Most attack attempts are automated: bots that permanently scan the internet, looking for vulnerable WordPress versions, outdated plugins, administration panels, weak passwords, open ports or misconfigured servers. If a domain is visible on the internet, sooner or later it will be scanned, tested and attacked automatically.
You are not being attacked because you are important. You are attacked because you are visible and vulnerable.
Where the Real Vulnerability Lies: WordPress and Its Plugins
According to DNSC, 80% of reported incidents are ransomware attacks, and many incidents are caused by basic issues: misconfigurations or lack of updates.
If your website runs on WordPress — and the probability is high, WordPress powers 43% of all websites on the internet — the attack surface is determined primarily by the installed plugins.
In 2025, 11,334 vulnerabilities were discovered in the WordPress ecosystem, 91% in plugins, and the median time to first attack after a vulnerability is published is 5 hours.
Every unupdated plugin is a door. Every theme abandoned by its developer is a window. Every admin panel with the default password is an open invitation. And the bots never sleep. They scan non-stop.
What ANSPDCP Checks After an Attack — and What They Usually Find
When ANSPDCP investigates a security incident, they are not just looking for evidence of the attack. They are looking for evidence of negligence in prevention.
In the Vellea Home SRL investigation, the authority found a violation of Article 32 of the GDPR — the one that obliges operators to implement adequate technical and organisational measures for data security — and ordered the company to revise its incident response plan, include clear procedures for early detection of threats and automatic alerting mechanisms through periodic system scanning.
Simply put: it is not enough to say you were attacked. You must demonstrate that you took all reasonable measures to prevent the attack. If your website runs on outdated plugins, with an old theme, without periodic scanning and without an incident response plan — you did not take reasonable measures.
Three Scenarios Where You Are Exposed Without Knowing It
The plugin you haven't updated in 6 months
You installed a contact form plugin, an image slider, a newsletter module. It works. You don't touch it. Meanwhile, the developer discovered a critical vulnerability, published a patch, and bots started exploiting old versions the same day. Your unupdated plugin is now an active entry point.
The theme bought 4 years ago from ThemeForest
The theme received updates in its first 2 years. Now the developers have abandoned it or moved on to other projects. You no longer receive security updates. Vulnerabilities discovered subsequently remain open on your website permanently.
The customer personal data database, unencrypted
Customers have left you their name, email address, phone number, possibly their delivery address. All of it sits in a MySQL database with WordPress's default configuration. An attacker who finds a vulnerability in any plugin can extract the entire database in a single query. You will find out you had a breach when customers start calling.
What “Updated” Means Is Not What You Think
There is a common misconception: “I have WordPress updated to the latest version, I am safe.” Updated WordPress core is the minimum, not the sufficient. If you have 15 plugins and 3 of them have uncorrected vulnerabilities — regardless of the WordPress version — you are exposed.
Moreover: some vulnerabilities have no patch available because developers have abandoned the plugin. The only way to be safe is to remove the plugin and find an active alternative — or build the functionality natively, without dependency on a third-party plugin.
The Alternative: What We Offer and Why It Matters for Security
When we migrate a site from WordPress to modern technologies — React, Next.js, headless architectures — we are not just doing a redesign. We are changing the entire security architecture.
- No third-party plugins with their own attack surface — the code running on your site is written specifically for you, not sourced from external dependencies with their own vulnerability history.
- Databases separated from the frontend — an attack on the frontend does not automatically reach customers' personal data.
- Controlled updates, not outsourced — you control what gets updated and when, not a plugin vendor who may abandon the product.
- Security audit included in every project we deliver — not a checkbox in a checklist.
If You Don't Want to Migrate Right Now — What You Can Do Immediately
Not every site needs immediate migration. There are also intermediate steps that significantly reduce risk:
- Take an inventory of active plugins and remove everything you don't use.
- Update WordPress core, all themes and all active plugins to the latest version.
- Enable two-factor authentication for the admin panel.
- Change the default admin URL (/wp-admin) — it is the first thing bots look for.
- Implement periodic automatic scanning with a dedicated tool (Wordfence, Sucuri or similar).
- Make daily backups of the database and make sure you know how to restore it.
These do not eliminate the risk — they reduce it. If the site processes customers' personal data, the acceptable risk level relative to GDPR is significantly lower than what WordPress with unmanaged plugins offers.
What We Do Concretely if You Contact Us
The first step is a free analysis of your current site: which plugins are running, how many active vulnerabilities exist, what the security architecture looks like and what the real level of exposure is.
If there are clear reasons for migration, we present a concrete proposal. If not, we tell you directly what intermediate steps would reduce the risk most without a major investment. We do not build solutions where they are not needed. But we do not leave a real risk situation without naming it.
Let's See How Exposed Your Website Is Right Now
Send us a message on the contact page with your website address. We do a free initial analysis and tell you honestly what we found. No obligations — an honest assessment of the real situation.