RM sends our SEO report to a hacker

#337618
  • Congratulations on your great tool and work; it’s been very useful.
    BTW I am the owner of the email accounts [redacted] and [redacted], our subsidiary organisation, which is used in the screenshot below.

    I today noticed an issue where RankMath (free version) was sending the monthly SEO reports to a previous Owner on our Google Search Console account. The problem is that this email ( [redacted] ) is associated with a hacker who inserted themselves as an Owner on our Search console back in November 2021. I found out today because the reports are sending through our plugin, from my email address. While we got the attack under control in early December, I just found that two SEO reports were sent to the hacker email in early January and early February.
    It seems to me that RM did not itself update the list of “members”/users to send the email reports to, and it must be using the ones from Search Console, as this email was never a user on our website.
    I just disconnected from Google and then set up the connection again, hoping that RM will now use the latest list of Owners to send email to.
    I hope you can fix this for RM to update the users to send reports to regularly, especially for the free plugin, where you cannot update that list.
    Let me know if you have any questions, and I can send you more detail.

Viewing 7 replies - 1 through 7 (of 7 total)
  • Hello,

    Thank you for contacting us and sorry for any inconvenience that might have been caused due to that.

    The SEO reports are sent to the email where the website is connected and if the reports are going to that email it means that the user you mentioned has your website connected to their account.

    The only way this can happen is if said user got access to the backend of your website and connected the website to their account.

    ​​​​​​​We don’t send the reports from information about the owners on Google Search Console.

    Hope this helps clarify your doubts.

    Don’t hesitate to get in touch if you have any other questions.

    Wow, thank you Miguel.
    That is concerning – wouold you be able to point out where the data is stored that RankMath sends the email to?
    They are not the Administrator, nor are they a user. Where would that email address come from?I am also very sure that they didn’t have access to the hosting.
    Thank you for clarifying,

    Stefan

    Hello,

    The data that gets included in the SEO Report comes directly from your database and the reports you see on your website inside the Analytics module.

    If you add the website URL in the sensitive data section we can let you know precisely if the website still continues to activate using that account and we can help you get the website disconnected from that account.

    Looking forward to hearing back from you.

    I love this auto-reply 🙂

    Hello,

    I have updated the sensitive data as requested. Can you please check further?

    Thank you.

    Prabhat
    Rank Math agency

    Hello,

    We checked and the website is connected to the account with the email ID: rafi********5**@g********.

    Could you confirm if this is the desired account?

    If not, please follow this guide to reconnect the website to the desired account:
    https://rankmath.com/kb/website-not-shown-in-account/

    Looking forward to hearing back from you.

    Thank you.

    Hi,

    Thank you; I was able to disconnect the incorrect acccount, and then connect to the correct account.

    I will get in touch again if the next report does not come to my own email address.

    Have a good day,

    Stefan 🙂

    Hello,

    We are super happy that your concern has been addressed.

    If you do have another issue in the future, please feel free to create a new forum topic, and it will be our pleasure to assist you again.

    Thank you.

Viewing 7 replies - 1 through 7 (of 7 total)

You must be logged in to reply to this ticket.