If you’ve visited this website at any point over the last year and wondered why we’d suddenly abandoned stories about life, travel and Afghanistan in favour of becoming enthusiastic promoters of online casinos…
We hadn’t.
Apparently, we’d been hacked.
And not just slightly hacked.
While I’ve been merrily getting on with life, somebody else had been merrily getting on with my website. They created new administrator accounts, installed malicious software, hid files in places I didn’t know existed and — most impressively — published more than 2,000 spam posts, largely advertising casinos and gambling sites.
Some of them weren’t even in English.
For a while, Himalayan Adventures had apparently diversified into the European online gambling market without consulting management.
How did I not notice 2,000 casino posts?
An excellent question.
I hadn’t been updating the blog much recently, so I wasn’t looking at the website very often. The spam posts were also backdated, buried amongst years of legitimate posts, and apparently designed more for search engines than for the approximately 50 actual human beings who occasionally wander over here to see what we’re doing.
There had been clues.
Pratiksha had mentioned some time ago that clicking things on the website occasionally produced strange pop-ups. I couldn’t reproduce it, so I assumed it was something at her end.
It wasn’t.
Sorry, Pratiksha.
Eventually WordPress stopped working properly altogether, and when I finally started digging, I discovered that the website I’d been neglecting had developed an entire secret life.
There were unfamiliar administrator accounts with reassuring-looking names. There were plugins I’d never installed. There were thousands of posts I’d never written.
One rogue administrator was called bot, which at least had the decency not to make much effort with its disguise.
Another was called admin2backup, complete with a wordpress.org email address, which looked just plausible enough to make you wonder whether you ought to delete it.
I did.
It came back.
That was the point at which this stopped being website housekeeping and became an episode of The X-Files.
Things got worse before they got better
I started removing the obvious rubbish: rogue users, malicious plugins and approximately two millennia’s worth of casino spam.
Then I ran the malware scanner supplied with my hosting account.
It found a lot.
Malicious files. Backdoors. Hidden plugins. Compromised theme files. Files designed to recreate other malicious files when they were removed.
This wasn’t somebody simply guessing my WordPress password and posting a few dodgy adverts. The site had been thoroughly compromised.
At this point I decided that my qualifications as a graphic designer were perhaps insufficient for conducting a full forensic investigation of a hacked web server.
So I called in people who actually knew what they were doing.
Enter FixRunner
I found a company called FixRunner who offered to clean the website properly for a fee.
They went through the WordPress installation, removed malicious files and backdoors, replaced the WordPress core files, cleaned malicious code from the theme and investigated the database.
They found, amongst other things, a hidden malicious plugin and three backdoor files, one of which could potentially allow someone to log into the website as an administrator without a password.
Which was comforting.
Unfortunately, there was one small problem.
They needed access to the database.
And nobody could get into it.
I could log into cPanel perfectly well. But clicking phpMyAdmin — the tool used to access the database — produced an access-denied error.
FixRunner got exactly the same error.
Thus began my lengthy correspondence with HostGator support.
Welcome to HostGator
Over the next day or so, I tried accessing phpMyAdmin using:
Chrome.
Safari.
Firefox.
My Mac.
My phone.
Wi-Fi.
Mobile data.
A UK VPN.
An Amsterdam VPN.
A Seattle VPN.
And eventually an entirely separate physical computer in the UK.
HostGator suggested the problem might be my Nepalese IP address.
It wasn’t.
Passwords were synchronised. Processes were cleared. Tickets were escalated. Screenshots were sent. More screenshots were sent. At one point I had what amounted to four identical screenshots of futility.
HostGator could access phpMyAdmin.
I couldn’t.
FixRunner couldn’t.
Then, almost by accident, we discovered something rather wonderful.
If I logged directly into cPanel with my perfectly valid cPanel username and password and clicked phpMyAdmin:
Access denied.
But if I logged into HostGator’s customer portal, clicked their cPanel button, arrived at what appeared to be exactly the same cPanel and then clicked exactly the same phpMyAdmin button:
It worked.
Twenty-seven hours of troubleshooting distilled into:
Have you tried coming in through the other door?
FixRunner suggested I create a delegated HostGator account for them. I did. They got in. The investigation continued.
And, as of this week, the site is finally clean.
Ironically, after everything was finished, I changed my cPanel password, logged in directly again and tried phpMyAdmin.
It now works.
I have no idea why.
I have decided not to ask.
So… are we safe now?
As safe as any public website can reasonably be.
FixRunner removed the malicious files and backdoors, investigated the database, removed the remaining unauthorised administrators and ran a final security scan. I’ve also run separate scans and checked the site myself from outside my WordPress account.
Everything is currently clean.
I’ve changed passwords, removed temporary access and tightened up the security. I’ll also be keeping a considerably closer eye on things from now on.
There remains one slightly awkward administrative task.
My WordPress Trash currently contains 2,019 posts.
I’m leaving them there for a little while longer, just in case I’ve accidentally thrown away something legitimate amongst:
BEST ONLINE CASINO BONUS 2026!!!
Eventually, though, the casino empire will be permanently destroyed.
And an apology
There’s a serious bit to all this.
If you’ve visited this website over the past year and encountered strange posts, unexpected redirects, pop-up advertising, gambling content, dubious material, or anything else that concerned or embarrassed you, I’m genuinely sorry.
None of it was posted by us.
We don’t know exactly what every visitor may have encountered while the site was compromised, and that’s uncomfortable. What we do know is that the malicious content has now been removed and the site has been professionally cleaned.
For the handful of you who regularly read our updates and wondered why we’d apparently stopped writing about our lives and started recommending Dutch casinos:
Thank you for sticking around.
Normal service has resumed.
Whatever normal service was.
P.S. If this post suddenly starts recommending an exciting new online poker platform with a 300% welcome bonus, please let me know.
I’ll be in cPanel.
Probably trying to open phpMyAdmin.

I’m so pleased to see you are back! I visited the site and could see it had been hacked, so tried to check with a friend in Didcot if they’d heard from you, but I didn’t hear back from them. Hope you’re both ok, and your families – especially after the awful floods in Nepal. Greetings and well wishes from Lichfield 🙂
Gosh! That sounds like hours of hard work and frustration. Ephesians 6:12 ‘For our struggle is not against flesh and blood, but against the rulers, against the authorities, against the powers of this dark world and against the spiritual forces of evil in the heavenly realms.’ comes to mind.
Sending love to you both
What an awful experience for you both – we are so bcc sorry. The whole techy area is too much for this oldie!
Love from us both.