Back to glossary

Defacement

3 min read

Defacement is the unauthorised modification of a website’s content, usually its home page, to carry a message, damage a reputation or simply demonstrate that the site could be broken into.

July 30, 2026
Compartir:

Defacement is the unauthorised, malicious modification of the content of a website.

The point is to change how a page looks or what it says, in order to carry a message, cause reputational damage, or simply prove that the site was vulnerable.

It gets done by a wide range of people, from individuals to groups with political or ideological motives.

What characterises it

The content changes. Images, text, links, or an added message from the attacker. Sometimes it is the whole home page, sometimes a single file that nobody notices for weeks.

The motives vary. Some do it to publish a political, social or ideological message. Others to demonstrate technical ability, or to damage the reputation of the organisation they hit.

The route in is usually mundane. Weak credential handling, software that has not been updated, or a vulnerability in the web application itself. The methods range from brute forcing an administrator password to exploiting a publicly known flaw in the content management system.

Why it matters more than it looks

Reputation. Malicious content on your own site erodes the trust of the people who use it, and it is visible to everybody at once.

Message propagation. Attackers sometimes use a defaced site to spread propaganda or misleading claims, which affects public perception well beyond the organisation itself.

It is a symptom. This is the part that gets missed. If somebody could change the content, they had write access. What else did that access reach? A defacement is the visible end of an intrusion, not the whole of it, and treating it as a cosmetic problem is how the actual compromise gets left in place.

A worked example

A group with political motives targets the website of a government agency. Using a vulnerability in the site’s content management system, they modify the home page.

Instead of the original content, the page now displays political messages and the group’s symbols. Alongside the defacement, they publish a statement setting out their demands.

The immediate effect is reputational, and the more serious question is the one that comes afterwards: an attacker with enough access to rewrite the home page usually had enough access to read the database, plant a web shell, or use the server as a foothold into whatever it can reach.

Where to read more

OWASP, Content Spoofing: detail on the concept, the attack methods and the practices that prevent this kind of incident.

Imperva, Website Defacement: an overview of defacement attacks, with real cases and recommended mitigations.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.