Hack recovery
Hacked? We’ll clean it, close the hole and get you back online
Spam pages in Google, a redirect to somewhere strange, a suspended hosting account or a red browser warning. We remove the malware, find how it got in, close that door and clear the warnings.
Right now
The first hour
Do these four things while we get started. They make the clean-up faster and stop it happening again.
- 01
Don’t delete anything yet
Logs and changed files show how they got in. Without them, it often happens again.
- 02
Change passwords from a clean device
Hosting first, then WordPress admins, SFTP, the database and email.
- 03
Copy the site as it is
Files and database, infected or not. It’s evidence, and a fallback.
- 04
Tell us what you’ve seen
Screenshots, browser warnings, emails from your host. Message us and mark it urgent.
What’s included
Cleaned, closed and cleared
Malware removed by hand
Infected files, injected code, rogue admin users and database spam removed, not just flagged by a scanner.
The entry point found
We trace how they got in (an outdated plugin, a stolen password, an upload form) and close it.
Credentials rotated
Passwords, keys and salts changed, everyone signed out, and access reviewed.
Warnings cleared
Google Safe Browsing and Search Console reviews requested, and blocklists checked.
Hardened afterwards
The same hardening we apply to every site, so the next automated attack finds nothing.
A plain-English incident report
What happened, what was affected, what we fixed, and what to tell customers if anything was exposed.
The steps
From first message to closed
- 01
Contain
Stop the damage and keep the evidence.
- 02
Clean
Remove the malware, files and database.
- 03
Close
Fix the way in and rotate every key.
- 04
Restore
Back online, warnings cleared.
- 05
Watch
Extra checks in the weeks after.
Get help
Tell us what’s happening
Send the details and message us on WhatsApp so we see it straight away. A person on our security team will reply.
- A reply from the people who’ll do the work
- Scope, dates and a fixed price before anything starts
- An NDA before we start, if you want one
- Nothing is tested without written authorization
Urgent? Message us on WhatsApp ↗
How did this happen?
Usually an outdated plugin or theme, a reused password, or another site on the same hosting account. We find out which, because that decides what stops it happening again.
Will I lose my content?
Rarely. We clean in place where we can and restore from a clean backup where we must, then re-apply anything that changed since.
Can’t I just restore a backup?
You can, but the hole is still open, and backups are often infected too. Restoring without fixing the cause usually means being hacked again soon after.
Was customer data taken?
We look for signs of it in the logs and tell you what we find. If personal data may have been exposed, we’ll help you understand your options, but notification decisions sit with you and your advisers.
More security services
The rest of the loop
Manual testing of your website, web app or API, following the OWASP testing guide, with every finding re-tested after it’s fixed.
Read more → WordPress securityAudits, hardening and fixes for WordPress: plugins, users, logins, configuration and the server underneath.
Read more → Vulnerability remediationBring us a pentest report, scan results or a host warning. We fix every finding and re-test it.
Read more → Security operationsMonthly patching, access reviews, log checks and incident response, run by the people who know your site.
Read more →