Public statement
Regarding the www.vortech.net security incident
Date: July 10, 2026
Vortech Consulting recently identified and responded to a compromise of our public website, www.vortech.net.
We are sharing this statement because transparency is especially important in our line of work. Vortech provides security and forensic services to small businesses, and we understand that we must hold ourselves to the same standard of candor that we recommend to our clients.
What Happened
Our public marketing and information website, www.vortech.net, was compromised through exploitation of a vulnerability in a Joomla website extension, SP Page Builder. The vulnerability allowed unauthorized files to be uploaded into web-accessible directories used by the website.
Our investigation found evidence that attackers uploaded and accessed malicious files through this vulnerable component. The activity was limited to the public website environment.
What Was Affected
The affected system was the public www.vortech.net website.
This site is used for marketing, company information, blog content, and general informational pages. It is not used to store client forensic data, client security data, customer portals, payment information, protected health information, regulated client records, or other sensitive client materials.
Based on our investigation to date, we have found no evidence that client data, customer records, payment data, forensic case data, or sensitive business information belonging to others was stored on or compromised from this website.
What We Did
After identifying the issue, we removed the Joomla site from public service and replaced it with a static temporary page. The original Joomla web root has been denied at the web server level, and requests to the former compromised paths are no longer being served by the origin server.
We also placed the site behind enhanced Cloudflare protections while hostile scanning and exploit traffic continued.
We have preserved logs and site artifacts for forensic review and have been reviewing Apache logs, Joomla records, filesystem artifacts, and host-level persistence locations.
Investigation Findings So Far
The investigation identified exploitation of the SP Page Builder upload functionality and malicious files placed under SP Page Builder media paths. We also found one database record indicating an attacker-created SP Page Builder asset path outside the normal iconfont directory.
To date, we have not found evidence of operating-system-level persistence, unexpected shell users, unauthorized SSH access, or compromise of client-sensitive data.
Current Status
The affected Joomla site remains offline and will not be restored directly from the compromised web tree.
We are rebuilding the public website from clean sources and reviewing what components are necessary before any dynamic functionality is reintroduced.
Going Forward
We are taking the following steps:
- Rebuilding the public website from clean sources rather than reusing the compromised application tree.
- Reviewing and reducing third-party website extensions.
- Restricting executable file handling in upload and media directories.
- Maintaining enhanced monitoring for unexpected executable files, upload endpoint activity, and abnormal request volume.
- Rotating relevant administrative and application credentials.
- Continuing to preserve and review forensic evidence related to this incident.
Closing
We regret that this incident occurred. Although the affected site did not contain sensitive client data, the compromise of our public website is serious and unacceptable.
We are disclosing this incident because our clients and community deserve direct and accurate information. If our investigation identifies any material change to the scope or impact described here, we will update this statement accordingly.
For questions, please contact Vortech Consulting through our normal business contact channels.