How it actually happens
A hole is found in a popular add-on or website system. Within days, robots are checking every reachable site for it. Sites still running the old version get broken into mechanically: spam pages injected, visitors redirected, or the server quietly put to work for someone else. The owner usually finds out from a customer, a browser warning, or a Google "this site may be hacked" label, weeks later.
Why updates get skipped
Because updates occasionally break things, and nobody wants to be the person who broke the website. So updates wait "until there's time", which means never, which means the site drifts into the vulnerable zone. The honest answer is not updating braver. It is updating with a safety net: a backup that has been restore-tested taken first, risky changes tried somewhere safe before the live site, and someone watching afterwards.
The update policy worth demanding
- Security patches applied on a weekly cycle; urgent ones faster.
- A restore-tested backup exists before every update run, every time.
- Risky updates tried on a copy before they touch the live site.
- After every run, someone confirms the site still loads and the forms still deliver.
- Everything written down, so "is that up to date?" has an answer on paper.
If a site has been neglected too long to update safely, that is a rescue, not a maintenance task, and pretending otherwise is how updates get a bad name.