Security notice regarding our website
Between 30 August and 11 September 2026, our WordPress-based website was manipulated through unauthorised access. During that period, visitors may have been shown a fake captcha window. It asked them to copy a given text and paste it into a Windows input window. Anyone who followed that instruction may have installed malware on their own device (the “ClickFix” method).
You are not affected if you only read our pages; simply opening the site does not cause an infection. If you remember such a prompt and followed it: disconnect the device from the network, run a full virus scan, change important passwords from a different device, enable two-factor authentication, and involve your IT support for business devices.
The system held the addresses of our newsletter distribution list: email address, in some cases a name, and the date of subscription. Bank details, payment data and client matter information were not stored there. Whether those addresses were read out cannot be established with certainty. If they were, this may lead to targeted advertising or fraudulent emails, possibly appearing to come from us. We will never ask you for passwords by email.
An external security notification made us aware on 11 September 2026, and we removed the malicious code and reset the website the same day. We then changed all access credentials, two-factor authentication is in place, all updates were installed and protective software was added. The vulnerability has been closed; we have reported the incident to the data protection authority of North Rhine-Westphalia (LDI NRW).
Questions: welcome@boesherzgoebel.de, +49 2159 69649700.