Behind the Scenes: How We're Protecting Your Websites From 30,000+ Daily Attacks

· 3 min read

You Deserve to Know What We’re Doing to Keep Your Sites Online

You may have noticed some sluggishness on your site in mid-December. We want to be upfront about what happened and what we’ve put in place since.

What Happened: When Bots Nearly Broke Our Servers

In mid-December, automated bots started firing off a steady stream of malicious requests against sites on our servers. These weren’t real visitors, they were scanners hunting for security vulnerabilities.

The problem is that each request still costs resources, even a rejected one. The server still has to check WordPress files, query the database, and burn CPU and memory to say no. With dozens of WordPress sites sharing each server, that many bogus requests an hour was enough to eat into the resources legitimate visitors needed, and that’s what caused the load spikes and slowdowns.

The Challenge: Cloudflare Was a Blindspot

Some of our customers use Cloudflare to proxy their traffic. It’s a great tool and we support it. To make that work, Cloudflare’s IP ranges are whitelisted on our servers so their traffic is never blocked. The problem: when attackers routed requests through Cloudflare’s proxy, those requests arrived wearing Cloudflare’s IP address and sailed straight through our firewall unchallenged. The real attacker was hidden behind a trusted face, and our standard IP-based blocking had no way to tell them apart from legitimate visitors.

Our Solution: Multi-Layer Protection

We put four automated layers in place.

1. Real Attacker Identification

We reconfigured our web servers to extract actual visitor IPs from behind Cloudflare and similar proxies, so we can see who’s really knocking.

2. Intelligent IP Blocking

Bad actors are now blocked at the web server level, before they ever consume PHP processing power or touch a database. A blocked attacker gets an immediate connection termination with zero resource cost to the server, and the blocklist keeps growing automatically as new offenders show up.

3. Attack Pattern Recognition

IP blocking alone isn’t enough, because determined attackers rotate addresses. So we added pattern recognition that blocks requests targeting known hacking tools and webshells, suspicious file names no legitimate visitor would ever request, common vulnerability scanners, and known exploit attempts, catching attacks regardless of which IP they come from.

4. Automated Learning

The system actively monitors logs, identifies emerging attack patterns, and updates the blocklists automatically, without us having to manually review every log entry. It learns and adapts as attacks evolve.

The Results: Your Sites Are Protected

Since deploying these protections, our custom WAF now blocks over 30,000 malicious requests every single day, before they ever reach your site. Server load is back to normal, PHP resources are freed up for actual customers, and we haven’t had a repeat of the December slowdowns since.

What This Means for You

Nothing looks different from your end, your site just works. But behind the scenes, there’s now a constant, automated wall between your website and the bots trying to find a way in.

Our Commitment: Continuous Improvement

We’re not treating this as a one-time fix. Ongoing work includes monitoring attack patterns and getting ahead of emerging threats, expanding blocklists as new malicious IPs surface, refining pattern detection as attack methods evolve, and making sure the protection adds negligible latency for real visitors.

Automated attackers constantly probe for weaknesses and they won’t stop. But that’s not your problem to worry about, it’s ours.

Transparency Matters

We could have quietly resolved this and said nothing. We didn’t, because we think you deserve to understand what went wrong, how we fixed it, and how we’re preventing it happening again.

You trust us with your website. That means we owe you speed, security, and availability, and we owe you honesty when something challenges that.

If you have questions about our security measures or want to know more about what we’re doing under the hood, get in touch, we’re happy to walk you through it.

Ready to Get Started?

Affordable NZ web hosting backed by a fanatical local support team. No lock-in, instant setup.