62px
62px
Work with an existing website · After a hack

Website hacked — we clean it, close the entry point and remove penalties

Redirects to third-party pages, Google warnings, hosting blocked for spam. We start recovery by finding the entry point, not by deleting files: otherwise everything will come back in a week. Recovery €690, typical timeframe 1-3 days.

Write in the form below
€690
Recovery
turnkey
1-3d
Typical time
to return to operation
30d
Monitoring
after cleaning
0
Blind edits:
entry point first
Does this look like your case?

What a hacked website looks like

Symptoms vary, but the cause is usually the same: an outdated plugin, a stolen password, or a vulnerability in third-party code. The sooner you act, the less damage to search and email.

Redirects to third-party websites

From a phone or from search results the site leads to a casino or pharmacy, while from your computer it opens normally — this is how it hides from the owner.

Warning in search

Google flags "This site may harm your computer" or drops pages from search results. Sanctions are lifted by submitting a request after cleanup.

Hosting blocked for spam

A mailing was sent from your server, the domain ended up on blocklists, and emails to clients stopped being delivered.

Unknown users in the admin panel

Accounts with administrator rights appeared that nobody created, or access to your account was lost.

Suspicious files and injected code

PHP files with random names in the site root, an unknown script in the header, and injected links in the database.

The site has become slow

Server load has increased sharply: someone else's code is mining, sending spam, or distributing third-party files at your expense.

How we restore

Restoration step by step: first the entry point, then cleanup

01

Isolation and snapshot

We take a copy of the infected site — it will be needed for investigation. If necessary, we put up a temporary page to avoid accumulating penalties.

02

Finding the entry point

We review access logs, file modification dates, known plugin vulnerabilities, and environment versions. Until we understand how the attacker got in, cleanup is pointless.

03

Cleanup and closing the hole

We remove malicious code from files and the database, update vulnerable components, and change all credentials: hosting, admin panel, database, FTP, email.

04

Removing penalties and monitoring

We submit a reconsideration request in Google Search Console and remove the domain from blocklists. We keep file change monitoring for 30 days.

Price for the work

How much does recovery after a hack cost

We quote after an initial inspection. If the site has been infected for a long time and there is no clean copy, we will say so directly: rebuilding is cheaper.

Work
Price from
Timeline
When this is your case
Initial inspection
€190
up to 4 hours
you need to understand the scope: what is infected and how they got in
Recovery after a hack
€690
1–3 days
cleanup, vulnerability patching, access change, Google request
Security audit without hacking
€290
1–3 days
nothing has happened yet, but you want to know the weak points
Restore from backup + patch the hole
€490
1 day
there is a known clean copy and the cause is identified
Domain removal from blocklists
€190
1–5 days
email not delivered, domain in spam lists after a mailing
Monitoring after recovery
€49/mo
ongoing
file monitoring, updates, off-server backups

We work with WordPress, Bitrix, Joomla, Laravel and custom PHP. Recovery includes a report: how they got in and what was done to prevent it from happening again.

What you will keep

What you get besides a clean website

Report with the entry point

How exactly they got in, what they managed to do, what was closed. Without this, you cannot be sure they will not return.

Clean copy

Verified backup of files and database after cleaning, stored outside the site server.

New access list

All passwords changed and provided to you: hosting, admin panel, database, FTP, email, repository.

Hygiene checklist

What to update, who to remove excess permissions from, where to enable two-factor authentication.

Honest boundary

When cleaning is not worth it

Sometimes restoration costs more than rebuilding, and we say this before invoicing:

  • Infection lasts for months — no clean copies remain, thousands of files have been modified, and the engine has not been updated for a long time. Checking every file is more expensive than rebuilding on the current version.
  • Engine is no longer supported — old Joomla, Drupal 7, custom code on PHP 5: there is nothing to patch the hole with, the next hack is a matter of weeks.
  • No hosting access — without server access you can neither view logs nor change passwords. First we regain control.
  • The site will have to be redone anyway — if a new version is planned in the coming months, it is more reasonable to invest the budget in it and temporarily close the current site.

In such cases we will show two invoices side by side — cleanup and a new version — and tell you what we would choose ourselves.

FAQ · After a hack

Frequently asked questions about recovery after a hack

Can you just restore from a backup?
It is possible, but not enough: a backup will restore the files, but not the vulnerability through which they got in. The infection will repeat within a few days. That is why we restore from a copy only together with closing the cause.
How long will it take?
The typical timeframe is one to three days: inspection and locating the entry point, cleanup, changing access credentials, submitting a request to Google. If the site is large or the infection is old, we will tell you after the initial inspection.
What should be done right now?
Change the hosting and admin passwords, make a copy of the site as is (it is needed for the investigation), and do not delete suspicious files — they are used to locate the entry point. If the site is sending mail, ask the hosting provider to temporarily block email sending.
Google has already flagged the site. Is this permanent?
No. After cleanup, we submit a review request in Search Console; the warning is usually removed within a few days. Rankings do not return immediately — the shorter the flagged period, the faster they recover.
How did they get in at all?
Most often through an outdated plugin or theme, less often through a stolen password or a vulnerability in third-party code. We provide the exact answer in the report: without it, we cannot guarantee that they will not return.
Emails to clients are not being delivered — is this related?
Yes, if mail was being sent from the server, the domain was added to blocklists. Domain removal is a separate task at €190: we clean the reputation, configure SPF, DKIM and DMARC, and submit requests to the lists.
What should be done to prevent it from happening again?
Updates, off-server backups, minimum user permissions, two-factor authentication. If there is no one to monitor this, website maintenance from €49 per month covers it, and file monitoring is included.
We use WordPress — is it attacked more often?
It is not the core that gets hacked, but outdated plugins: WordPress simply has more of them than others. The core itself is secure with timely updates — we wrote about working with it on the WordPress development page.
Contact

Describe what is happening with the website

We need the website address, when you noticed the problem, and what you have already done. We reply within 60 minutes during working hours (GMT+3).

Recovery €690 — with a report on the entry point

Cleaning without finding the cause is a delay, not a solution

Send the site address and symptoms. We will come back with an assessment of the scope, timeline and fixed price for the work.

Write to Telegram