I am a web developer and we have no one specialising in the wellbeing of the server or the network currently at our office. Usually I can sort many of the issues that arise with my basic knowledge but currently, we have some strange things happening and I have no idea what is going on so I'm looking for some advice from someone a lot more knowledgeable than me to shed some light if possible.
We have an ecloud server hosted by UK Fast (Linux server) and it holds a VPS server and lots of client sites. Yesterday, the server randomly went down and when we realised, we called them up and they said someone had SSH'd in and run the command sudo rm TSG-server.pub
which essentially removed our whole server. UK fast managed to get us an IP of where the user who did this was accessing it from but 1. I don't know how this helps at all and 2. they could have been using a VPN anyway.
The weird thing is that they had a login attempt ad it was successful... So whoever it was, knew the password or got it from somewhere. The only place we have our password is on LastPass and no one else knows it. So we restored the backup and got everything back, changed the password and called it a day.
So cut to this morning and it happened again... except this time they didn't leave any trace of who it was because they made sure they deleted the logs as well...
How could they possibly be doing this and how can we stop this? I don't even know where to begin...
Does anyone have any idea of how this might be happening, please.