Public statement

Regarding the www.vortech.net security incident

Date: July 10, 2026

Vortech Consulting recently identified and responded to a compromise of our public website, www.vortech.net.

We are sharing this statement because transparency is especially important in our line of work. Vortech provides security and forensic services to small businesses, and we understand that we must hold ourselves to the same standard of candor that we recommend to our clients.

What Happened

Our public marketing and information website, www.vortech.net, was compromised through exploitation of a vulnerability in a Joomla website extension, SP Page Builder. The vulnerability allowed unauthorized files to be uploaded into web-accessible directories used by the website.

Our investigation found evidence that attackers uploaded and accessed malicious files through this vulnerable component. The activity was limited to the public website environment.

What Was Affected

The affected system was the public www.vortech.net website.

This site is used for marketing, company information, blog content, and general informational pages. It is not used to store client forensic data, client security data, customer portals, payment information, protected health information, regulated client records, or other sensitive client materials.

Based on our investigation to date, we have found no evidence that client data, customer records, payment data, forensic case data, or sensitive business information belonging to others was stored on or compromised from this website.

What We Did

After identifying the issue, we removed the Joomla site from public service and replaced it with a static temporary page. The original Joomla web root has been denied at the web server level, and requests to the former compromised paths are no longer being served by the origin server.

We also placed the site behind enhanced Cloudflare protections while hostile scanning and exploit traffic continued.

We have preserved logs and site artifacts for forensic review and have been reviewing Apache logs, Joomla records, filesystem artifacts, and host-level persistence locations.

Investigation Findings So Far

The investigation identified exploitation of the SP Page Builder upload functionality and malicious files placed under SP Page Builder media paths. We also found one database record indicating an attacker-created SP Page Builder asset path outside the normal iconfont directory.

To date, we have not found evidence of operating-system-level persistence, unexpected shell users, unauthorized SSH access, or compromise of client-sensitive data.

Current Status

The affected Joomla site remains offline and will not be restored directly from the compromised web tree.

We are rebuilding the public website from clean sources and reviewing what components are necessary before any dynamic functionality is reintroduced.

Going Forward

We are taking the following steps:

Closing

We regret that this incident occurred. Although the affected site did not contain sensitive client data, the compromise of our public website is serious and unacceptable.

We are disclosing this incident because our clients and community deserve direct and accurate information. If our investigation identifies any material change to the scope or impact described here, we will update this statement accordingly.

For questions, please contact Vortech Consulting through our normal business contact channels.