Yesterday morning started like many others. Chris Horlacher opened his browser to check equibitlawsuit.com and was immediately confronted with an aggressive Cloudflare verification page demanding he run a PowerShell command. He recognized it instantly as the ClickFix phishing attack that security researchers have been warning about.

What followed was a full-day emotional rollercoaster of detection, containment, and a live confrontation with whoever is trying to silence this site.
The Attack Unfolds
By mid-morning, the site began throwing fatal errors. WordPress sent an automated email warning that the Performance Optimizer plugin had caused a critical error. This was a plugin Horlacher had never installed himself.
With help from his developer, the team traced the issue. Hosting.com’s security system had already detected and quarantined a malicious file inside the plugin. The plugin had been compromised, or possibly was never legitimate to begin with.
We immediately disabled and removed the infected plugin. Wordfence Premium was installed and a full scan was run.
Catching the Intruder Live
While the team was still in the middle of securing the site, Wordfence started firing alerts:
A user named “Waseem” — the same username as the Fiverr developer who had worked on the site redesign a month earlier — had just logged into the WordPress dashboard with full Administrator privileges.

The logins came from two different countries: Bangladesh (IP 103.189.218.76) and Virginia, USA (IP 209.50.175.145).

Server access logs later revealed the intruders’ actions:
- The Bangladesh IP successfully logged in and attempted to upload new plugins.
- The Virginia IP used command-line tools (Wget) to navigate the dashboard, access WooCommerce reports, create posts, and probe for sensitive areas.
Tellingly, the intruders made no attempt to modify the Bitcoin and Monero donation addresses on the ‘Take Action‘ page, which would have been a typical move for a hacker. Their motivations were not for personal financial gain.
This was a coordinated attempt to take full control of the site and attack you, the readers.
This happened while Horlacher was away from his desk. Upon returning around 4 PM, he immediately began locking down the site. The compromised “Waseem” account was deleted at 12:34 PM, roughly 23 minutes after the second detected login. No further attempts from that account have been logged.
Horlacher reached out to the real Waseem on Fiverr. He immediately denied any involvement.
In other words, someone had stolen credentials and was actively trying to regain control of equibitlawsuit.com in real time, while the team watched the alerts come in.
Implications
This was not an opportunistic hack. The attacker had specific knowledge of a valid administrator username (“Waseem”) and its password. This points to either:
- Prior compromise of the developer’s systems, or
- Insider access / credential leakage during the previous site work.
This is consistent with the broader pattern of targeted, persistent attacks documented in the Factum, and published on this website.
Current Status
The malicious plugin has been completely removed. The site is stable, and monitoring has been strengthened significantly. Equibit Group Ltd. continues to work with Hosting.com to investigate the full scope of the intrusion.
The Bigger Picture
This was not a random hack. The timing, the use of a previously legitimate contractor’s username, and the immediate attempt to regain access after the initial infection was neutralized all point to a deliberate, coordinated effort to compromise the public record of the Equibit lawsuit.
They are not just attacking Horlacher personally anymore — they are coming for the documentation itself.
But here’s what they don’t seem to understand: every attack makes the public record stronger. Every log, every alert, every suspicious login is now part of the evidence.
We will not be silenced.
The documentation continues.
Full lawsuit materials and timeline: equibitlawsuit.com
