New Findings + Breach Response Plan
Everything below surfaced while delivering the paid Get Current package. It falls OUTSIDE that scope. You choose your level of breach-response support โ three explained tiers. We recommend T2 (Scope) โ the FIPA notification floor and the tier your attorney needs answered. T3 is available as an upgrade for full protection + monitoring. T1 is contain-only, below our recommendation.
Phase 1 โ Emergency Ads Fixโ DELIVEREDDUE NOW
โ ๏ธ Already performed 2026-07-15 โ awaiting your approval to bill
- Emergency closure of a public database exposure (1.09 GB dump publicly downloadable since 2022-12-01)
- 45-month forensic sweep across access logs โ confirmed 24 downloads by 17 distinct IPs, ~31.6 GB exfiltrated
- Evidence preservation + hash verification + chain of custody
- Internal incident report + 6-page client-facing notice (delivery-ready)
- Targeted pre-flip backup (database + code), verified + secured
- Security lockdown Phase 1 deployed (mu-plugin allow-list, 37 sessions destroyed, function-tested)
- Admin inventory + credential remediation (15 admins audited, weak accounts flagged)
Delivered under emergency โ market crisis-response for this scope typically $2,000โ$3,500. Billed at flat $1,200 (with $200 goodwill credit if you approve T2 or T3 within 7 days = effective $1,000).
โ Emergency work delivered ยท awaiting billing approval
Job 2 โ A Real Search Engine for Your Readers
Choose your level of breach-response support. T2 is our recommendation -- meets the FIPA notification floor. T3 adds full protection + monitoring ($3,610 net after credit). Prices firm 30 days.
- โ ๏ธ Below our recommendation โ contains the incident but does not answer whose data was exposed
- Close 2 remaining publicly-readable files (218 MB error logs)
- Full web-root audit for other stray dumps and migration artifacts
- Forced password reset across all user accounts
- Rotate credentials for connected services (SMTP, mailing list, integrations)
- Set backup encryption passphrase (stops future cleartext copies to any destination)
- Written completion report
- Lockdown Phase 1 already delivered โ counts against this tier (see prepaid credit)
- ๐ฏ RECOMMENDED โ FIPA notification floor. This is what your attorney needs answered.
- Everything in T1, plus:
- Offline enumeration of the exfiltrated database โ which tables, which users, how many individuals, categories of PII, whether live credentials were captured
- Affected-party report โ a document your attorney or insurer can act on
- Post-compromise persistence check โ unexpected admin accounts, unknown plugins, modified core files, evidence anyone USED the exfiltrated credentials
- Attribution pass on the 17 source IPs
- Prepaid credit applied: PM admin inventory (~$340 value) doubles as T2 persistence check
- ๐ฏ Upgrade โ full protection + monitoring. Contains + scopes + makes the next incident detectable.
- Everything in T1 + T2, plus:
- Client-owned encrypted backup destination โ account created and owned by Michael, revocable app key; migrate off third-party Dropbox
- Verified restore test (currently untested โ no complete UpdraftPlus set has ever existed)
- Backup retention remediation (`/backup` volume 100% full, silently failing since Feb 2026)
- External uptime + file-integrity monitoring โ catches the next stray artifact and the next silent outage
- Redirect WordPress admin notifications to Michael (currently routed to `lorenzo@`, never received)
FIPA notification note
Florida's FIPA notification timeline runs from the date a breach is DETERMINED, which appears to be 2026-07-15. Tier 2 enumeration is the minimum that tells you whether and whom you must notify. Delay lands on your legal exposure.
